Hello everyone, the latest release of the Devo Platform is now live! Release 8.11.1 introduces Alert Page presets! Now you can save your Alert page filters, create new ones, set them as default on a per-user level, and mange your presets! In addition, this release introduces a few enhancements to the devo.audit.alert.triggered table. Alert Operations have been added to this table so you can now track when every alert has been triggered among other details. Additionally we have enhanced the tracking of alert priority change with the alert priority name, giving you additional context when auditing your alerts. Learn more about this release below! Geo AvailabilityRegion Status GovCloud Released CA Released US Released EU Released APAC Released Table of ContentsNew Features Introducing Alert Presets Improvements New Audited Operation field added Improved Priority Change recording New FeaturesIntroducing Alert PresetsWith this release, you will now be able to sav
Geo AvailabilityRegion Status GovCloudReleased CAReleased USReleased EUReleased APACReleased Hello everyone, the latest release of the Devo Platform is now live! Release 8.11.0 delivers a wide range of improvements to Data Search that are sure you enhance the key core experience of the Devo Platform! Data Search has been re-imagined from a collection of single components to a unified architecture, delivering speed and freedom of action. With this improvement we have been able to remove Column Limits, deliver improvements to column reorganization, table navigation as well as improved data visibility and control. In addition, we have delivered improvements to Alerts with the new ExtraData search filter. Learn more about this release below! Table of ContentsNew Features Data Search reimagined Enhancements Removed Column Limits New feedback added for query with no results Improvement to Drag & Drop Column Order Improved Table Navigation New action added to view wrappe
The Devo Parser is one of the secret spices of our unique Hyperstream technology. The Parsers organize raw events stored in tags in different columns and display them in the corresponding tables. This method completely bypasses data indexing and contributes to Devo’s amazing search speeds. Every data source is unique, so we have a great catalog of existing parsers. Our teams review parser performance, build new parsers and update parsers on a regular basis. This article covers all the updated and new parsers available this month. If you require a new parser, please open a support ticket through the support portal located here. You can also visit the new Resources Portal, a single page for all your customer resources! Table of ContentsNew Parsers dmp.egnyte Updated Parsers proxy.zscaler cloud.azure box.all.win firewall.cisco adn.f5 endpoint.vmware mail.fortinet box.unix network.meraki firewall.fortinet firewall.sophos box.vmware auth.cisco mail.proofpoint New Parsersdmp.e
Every month, the integrations team work on new and updated collectors for you, and I collect them all in this Catalog Update. This post contains new and updated collector information as well as links to their respective pages in our Documentation portal. Be advised that some pages in Documentation may not be available at the time of posting but will be added as soon as they are available. To request new collectors or an update to an existing collector, please open a support ticket through the Support Portal. You can also visit the new Resources Portal, a single page for all your customer resources! Table of ContentsNew Collectors Symantec Collector v1.0.0 Trellix DLP v1.0.0 Updated Collectors Github Collector v3.0.0 VMware Carbon Black Cloud EPP Collector v1.4.1 Office365 Management API Collector v2.3.2 Azure Collector v2.2.0 AWS SQS Collector v1.5.2 Wiz Collector v1.7.0 Duo Collector v2.0.0 Rapid7 InsightVM Collector v1.7.0 Lark Collector v1.1.0 Crowdstrike API Resources
The Devo team has released the latest version of Devo SOAR! This release include 2 new integrations and a host of new actions and bug fixes. SOAR Automation is a key feature of Devo Intelligent SIEM, allowing you to automate a large number of daily tasks and give you back essential time to perform key investigations and hunts. First time with Devo SOAR? We have tutorials on the community to help you get started as well as the rich Devo SOAR Documentation portal. Devo SOAR also has a guided playbook builder to interactively create a no-code automation! Geo AvailabilityRegion Status CA Released US Released EU Released APAC Released Table of ContentsNew Integrations Enhancements New IntegrationsCISCO Ironport with 1 actionBeyond Trust with 3 actions EnhancementsWeb API now supports multipart/form-data in the bodyAbsolute new action: Get a Wipe Request.Case Management new action behavior: Create case action now has title field as required.Anomali new action parameter:
Hello everyone, the latest release of the Devo Platform is now live! Release 8.10.43 brings some core improvements for Scheduled Reports, Autoparser and new functionality for Multitenant domains. The great Autoparser now reports when it encounters inconsistencies in the data being processed. Scheduled reports are now aligned with the RFC Standard for emails changing the way the reports are sent. Multitenant domains can now see and define my.app and my.upload tables created in their child domains. Lastly we have a collection of bug fixes in direct response to customer feedback. Learn more in this product update and don’t forget to subscribe! Geo AvailabilityRegion Status GovCloud Released CA Released US Released EU Released APAC Released Table of ContentsNew Features Multitenant root domains can create my.app & my.upload table definitions in the finder. Updated Feature Autoparser on tables with inconsistent data Scheduled reports are sent to each recipient i
The Integration team prepared and released a new Activeboard to help users monitor and be informed on the status of their collectors along with any warnings or errors that may be occurring. We have also released a companion Alert Pack that works in conjunction with the Activeboard to provide full visibility around your Collectors. This combination will give you visibility into Collector uptime, warning errors, general activity and message types. You also see all credential errors as well as API limits and server errors. This is a must have Activeboard that provides full visibility into the health of your Data Ingestion.Table of ContentsCollector Monitoring Activeboard Collector Alert Pack What does it look like? Go Check it out on Devo Exchange Devo Collector Monitoring Activeboard Devo Collector Alert Pack Collector Monitoring ActiveboardHaving good supervision in data flow is key in Devo. It’s important to give customers good insights, alerts and security use cases, but insight i
We're thrilled to announce the latest updates and additions to our alerting system with Release 29. This release introduces a large collection of updates to 24 Alert Packs covering all manner of MITRE Tactics and Techniques. Additionally we have updated Detections for Linux, Windows, Network and authentication. Below you will find links to exchange for all the alert packs in your respecting geo’s.To access Updated Detections, open the Security Operations app inside Devo and navigate to the Content Manager. Here, you can search for the detection name, and manage your alerts. To update or install new alerts visit Devo Exchange. Table of ContentsUpdated Alert Packs Linux_Log-Based_Threat_Detection_Suite Windows_Log_Threat_Detection_Suite Authentication_Log_Threat_Detection_Suite Abuse_Elevation_Control_Mechanism_(MITRE_Att&ck_Technique:_T1548) Boot_or_Logon_Initialization_Scripts_(MITRE_Att&ck_Technique:_T1037) Account_Manipulation_(MITRE_Att&ck_Technique:_T1098) Comman
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
Sorry, we're still checking this file's contents to make sure it's safe to download. Please try again in a few minutes.
Sorry, our virus scanner detected that this file isn't safe to download.