Skip to main content

Devo Parser Catalog Update for October

Related products:Devo Integrations
  • November 24, 2025
  • 0 replies
  • 19 views
juan.delrio
Admin
Forum|alt.badge.img+3

The Devo Parser is one of the secret spices of our unique Hyperstream technology. The Parsers organize raw events stored in tags in different columns and display them in the corresponding tables. This method completely bypasses data indexing and contributes to Devo's amazing search speeds. Every data source is unique, so we have a great catalog of existing parsers. Our teams review parser performance, build new parsers and update parsers on a regular basis. This article covers all the updated and new parsers available this month. If you require a new parser, please open a support ticket through the support portal located here. You can also visit the new Resources Portal, a single page for all your customer resources!

 

 

Table of Contents

 

Updated Parsers

box.win

  • Improvements
    • Parsed and added the CallerProcessId field:
      • box.win_nxlog.security
      • box.win_nxlog
    • Updated mapping of logonProc field:
      • box.all.win

edr.eset

  • Added
    • Added new parser:
      • edr.eset.connect.detections
      • edr.eset.connect.incidents
      • edr.eset.connect.permissions
      • edr.eset.connect.role_assignments

firewall.paloalto

  • Improvements
    • Updated the parsing logic to support additional fields and multiple time formats:
      • firewall.paloalto.system

waf.owasp

  • Added
    • Added new parser:
      • waf.owasp.modsecurity.log

network.juniper

  • Added
    • Added new parser:
      • network.juniper.junos