<?xml version="1.0" encoding="utf-8"?><?xml-stylesheet type="text/xsl" href="rss.xsl"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel>
        <title>Sumo Logic Cloud SOAR Release Notes</title>
        <link>https://help.sumologic.com/release-notes-csoar/</link>
        <description>New and enhanced Cloud SOAR features, bug fixes, changes to the application, and more.</description>
        <lastBuildDate>Fri, 03 Jan 2025 00:00:00 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <language>en</language>
        <copyright>Copyright © 2025 Sumo Logic</copyright>
        <item>
            <title><![CDATA[January 03, 2025 - Application Update]]></title>
            <link>https://help.sumologic.com/release-notes-csoar/2025/01/03/application-update/</link>
            <guid>https://help.sumologic.com/release-notes-csoar/2025/01/03/application-update/</guid>
            <pubDate>Fri, 03 Jan 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Changes and Enhancements]]></description>
            <content:encoded><![CDATA[<a href="https://help.sumologic.com/release-notes-csoar/rss.xml"><img src="https://help.sumologic.com/img/release-notes/rss-orange2.png" alt="icon" width="50"></a>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="changes-and-enhancements">Changes and Enhancements<a href="https://help.sumologic.com/release-notes-csoar/2025/01/03/application-update/#changes-and-enhancements" class="hash-link" aria-label="Direct link to Changes and Enhancements" title="Direct link to Changes and Enhancements">​</a></h3>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="platform">Platform<a href="https://help.sumologic.com/release-notes-csoar/2025/01/03/application-update/#platform" class="hash-link" aria-label="Direct link to Platform" title="Direct link to Platform">​</a></h4>
<ul>
<li>Playbooks:<!-- -->
<ul>
<li>Performance optimisations on Incidents page.</li>
<li>Faster onboarding and provisioning for new Cloud SOAR and Automation service customers.</li>
<li>Display Integration Name and Cartesian product in node details popup.</li>
</ul>
</li>
</ul>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="bug-fixes">Bug Fixes<a href="https://help.sumologic.com/release-notes-csoar/2025/01/03/application-update/#bug-fixes" class="hash-link" aria-label="Direct link to Bug Fixes" title="Direct link to Bug Fixes">​</a></h3>
<ul>
<li>Playbooks:<!-- -->
<ul>
<li>Added validations for required fields in playbook nodes.</li>
<li>Updated error messages for required fields.</li>
</ul>
</li>
<li>Integrations:<!-- -->
<ul>
<li>Fixed an issue with API authorization in the Sumo Logic Log Analytics integration.</li>
<li>Fixed the issue of action details not persisting on failure while testing an action.</li>
</ul>
</li>
<li>Incidents:<!-- -->
<ul>
<li>Fixed an issue where the Incident Owner field appeared empty in the incident close audit log.</li>
</ul>
</li>
</ul>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[January 03, 2025 - Content Release]]></title>
            <link>https://help.sumologic.com/release-notes-csoar/2025/01/03/content/</link>
            <guid>https://help.sumologic.com/release-notes-csoar/2025/01/03/content/</guid>
            <pubDate>Fri, 03 Jan 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[This release introduces new integrations, new playbooks, and several updates.]]></description>
            <content:encoded><![CDATA[<a href="https://help.sumologic.com/release-notes-csoar/rss.xml"><img src="https://help.sumologic.com/img/release-notes/rss-orange2.png" alt="icon" width="50"></a>
<p>This release introduces new integrations, new playbooks, and several updates.</p>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="integrations">Integrations<a href="https://help.sumologic.com/release-notes-csoar/2025/01/03/content/#integrations" class="hash-link" aria-label="Direct link to Integrations" title="Direct link to Integrations">​</a></h3>
<ul>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/azure-ad/">Azure AD</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/google-chat/">Google Chat</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/sumo-logic-log-analytics/">Sumo Logic Log Analytics</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/sumo-logic-notifications-by-microsoft/">Sumo Logic Notifications By Microsoft</a></li>
</ul>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[2024 Archive]]></title>
            <link>https://help.sumologic.com/release-notes-csoar/2024/12/31/</link>
            <guid>https://help.sumologic.com/release-notes-csoar/2024/12/31/</guid>
            <pubDate>Tue, 31 Dec 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[This is an archive of 2024 Cloud SOAR release notes. To view the full archive, click here.]]></description>
            <content:encoded><![CDATA[<a href="https://help.sumologic.com/release-notes-csoar/rss.xml"><img src="https://help.sumologic.com/img/release-notes/rss-orange2.png" alt="icon" width="50"></a>
<p>This is an archive of 2024 Cloud SOAR release notes. To view the full archive, <a href="https://help.sumologic.com/release-notes-csoar/archive/">click here</a>.</p>
<hr>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="december-31-2024---application-update">December 31, 2024 - Application Update<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#december-31-2024---application-update" class="hash-link" aria-label="Direct link to December 31, 2024 - Application Update" title="Direct link to December 31, 2024 - Application Update">​</a></h3>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="sumo-logic-on-premises-soar-solution-end-of-life">Sumo Logic On-Premises SOAR Solution End-of-Life<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#sumo-logic-on-premises-soar-solution-end-of-life" class="hash-link" aria-label="Direct link to Sumo Logic On-Premises SOAR Solution End-of-Life" title="Direct link to Sumo Logic On-Premises SOAR Solution End-of-Life">​</a></h4>
<p>Effective today, <strong>December 31, 2024</strong>, Sumo Logic’s on-premises SOAR solution has reached end-of-life and is obsolete. Beginning today, it no longer receives applicable support entitled by active support contracts or by applicable warranty terms and conditions.</p>
<p>We <a href="https://help.sumologic.com/release-notes-csoar/2023/12/31/#november-1-2023---application-update">previously announced</a> that as of November 15, 2023, Sumo Logic's on-premises SOAR solution no longer received updates, and Sumo Logic Engineering no longer developed, repaired, maintained, or tested the software as of that date.</p>
<p>To upgrade to Sumo Logic’s <a href="https://help.sumologic.com/docs/cloud-soar/" target="_blank" rel="noopener noreferrer">Cloud SOAR</a> offering, reach out to your Sumo Logic representative.</p>
<hr>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="november-20-2024---content-release">November 20, 2024 - Content Release<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#november-20-2024---content-release" class="hash-link" aria-label="Direct link to November 20, 2024 - Content Release" title="Direct link to November 20, 2024 - Content Release">​</a></h3>
<p>This release introduces new integrations, new playbooks, and several updates.</p>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="integrations">Integrations<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#integrations" class="hash-link" aria-label="Direct link to Integrations" title="Direct link to Integrations">​</a></h4>
<ul>
<li>[New] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/google-chat/">Google Chat</a></li>
<li>[New] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/malwarebytes-oneview/">Malwarebytes Oneview</a></li>
<li>[New] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/silent-push/">Silent Push</a></li>
<li>[New] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/sumo-logic-automation-tools/">Sumo Logic Automation Tools</a></li>
<li>[New] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/virustotal-v3/">VirusTotal V3</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/apivoid/">APIVoid</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/atlassian-jira-v2/">Atlassian Jira V2</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/atlassian-opsgenie/">Atlassian Opsgenie</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/aws-ec2/">AWS EC2</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/aws-eks/">AWS EKS</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/azure-ad/">Azure AD</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/cloudflare/">Cloudflare</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/connectwise-manage/">ConnectWise Manage</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/cortex-xdr/">Cortex XDR</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/crowdstrike-falcon/">CrowdStrike Falcon</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/freshservice/">Freshservice</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/gmail/">Gmail</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/http-tools/">HTTP Tools</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/ibm-x-force-exchange/">IBM X-Force Exchange</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/microsoft-ews/">Microsoft EWS</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/microsoft-onedrive/">Microsoft OneDrive</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/microsoft-sentinel/">Microsoft Sentinel</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/netskope-v2/">Netskope V2</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/slack/">Slack</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/sumo-logic-cloud-siem/">Sumo Logic Cloud SIEM</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/sumo-logic-notifications-by-gmail/">Sumo Logic Notifications by Gmail</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/urlscan.io/">URLScan.io</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/virustotal/">VirusTotal</a></li>
</ul>
<hr>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="november-15-2024---application-update">November 15, 2024 - Application Update<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#november-15-2024---application-update" class="hash-link" aria-label="Direct link to November 15, 2024 - Application Update" title="Direct link to November 15, 2024 - Application Update">​</a></h3>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="changes-and-enhancements">Changes and Enhancements<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#changes-and-enhancements" class="hash-link" aria-label="Direct link to Changes and Enhancements" title="Direct link to Changes and Enhancements">​</a></h4>
<h5 class="anchor anchorWithStickyNavbar_LWe7" id="platform">Platform<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#platform" class="hash-link" aria-label="Direct link to Platform" title="Direct link to Platform">​</a></h5>
<ul>
<li>Playbooks<!-- -->
<ul>
<li>Improvement - Disabled Cartesian Product flag on all new nodes by default.</li>
</ul>
</li>
</ul>
<h5 class="anchor anchorWithStickyNavbar_LWe7" id="automation-bridge">Automation Bridge<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#automation-bridge" class="hash-link" aria-label="Direct link to Automation Bridge" title="Direct link to Automation Bridge">​</a></h5>
<p>We are happy to announce a beta version of the <a href="https://help.sumologic.com/docs/platform-services/automation-service/automation-service-bridge/">Automation Bridge</a> that includes the following:</p>
<ul>
<li>Support for new CentOS version<!-- -->
<ul>
<li>The CentOS docker image version has been upgraded from CentOS 7 to CentOS 8.</li>
</ul>
</li>
<li>Security fixes</li>
</ul>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="bug-fixes">Bug Fixes<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#bug-fixes" class="hash-link" aria-label="Direct link to Bug Fixes" title="Direct link to Bug Fixes">​</a></h4>
<ul>
<li>Playbooks<!-- -->
<ul>
<li>Fixed Playbook nodes rendering issue on Safari browser.</li>
<li>Fixed issue related to use of underscore within playbooks input fields.</li>
<li>Fixed issue with using authorizer value from playbook input variables in user choice node.</li>
</ul>
</li>
<li>Integrations<!-- -->
<ul>
<li>Resolved an issue where the 'Close Insight' trigger action was not functioning as expected.</li>
</ul>
</li>
<li>Incidents<!-- -->
<ul>
<li>Improved Incident templates page load time.</li>
<li>Fixed issues while trying to update Incident templates.</li>
</ul>
</li>
</ul>
<hr>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="july-17-2024---application-update">July 17, 2024 - Application Update<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#july-17-2024---application-update" class="hash-link" aria-label="Direct link to July 17, 2024 - Application Update" title="Direct link to July 17, 2024 - Application Update">​</a></h3>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="changes-and-enhancements-1">Changes and Enhancements<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#changes-and-enhancements-1" class="hash-link" aria-label="Direct link to Changes and Enhancements" title="Direct link to Changes and Enhancements">​</a></h4>
<ul>
<li>Automation Audit: Logs now contain information about action and section detail (for playbooks, rules, observables, triage, incidents, and so on).</li>
<li>Playbooks: Added option “Split By” for Filter node.</li>
</ul>
<h5 class="anchor anchorWithStickyNavbar_LWe7" id="cloud-soar">Cloud SOAR<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#cloud-soar" class="hash-link" aria-label="Direct link to Cloud SOAR" title="Direct link to Cloud SOAR">​</a></h5>
<ul>
<li>Playbooks:<!-- -->
<ul>
<li>Added option to hide trigger action modal.</li>
<li>Added option to remove additional information from the Slack message in User Choice node.</li>
</ul>
</li>
</ul>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="bug-fixes-1">Bug fixes<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#bug-fixes-1" class="hash-link" aria-label="Direct link to Bug fixes" title="Direct link to Bug fixes">​</a></h4>
<ul>
<li>Playbooks:<!-- -->
<ul>
<li>Fixed send mail action error with Unicode characters.</li>
<li>Fixed export.</li>
</ul>
</li>
</ul>
<hr>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="june-5-2024---content-release">June 5, 2024 - Content Release<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#june-5-2024---content-release" class="hash-link" aria-label="Direct link to June 5, 2024 - Content Release" title="Direct link to June 5, 2024 - Content Release">​</a></h3>
<p>This release introduces new integrations, new playbooks, and several updates.</p>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="integrations-1">Integrations<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#integrations-1" class="hash-link" aria-label="Direct link to Integrations" title="Direct link to Integrations">​</a></h4>
<ul>
<li>[New] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/aws-waf/">AWS WAF</a></li>
<li>[New] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/aws-eks/">AWS EKS</a></li>
<li>[New] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/cyberint/">Cyberint</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/okta/">Okta</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/lacework/">Lacework</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/microsoft-ews-daemon/">Microsoft EWS Daemon</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/greynoise/">GreyNoise</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/chronicle/">Chronicle</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/atlassian-jira-v2/">Atlassian Jira V2</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/abuseipdb/">AbuseIPDB</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/palo-alto-networks-ngfw/">Palo Alto Networks NGFW</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/palo-alto-networks-panorama-v2/">Palo Alto Networks Panorama V2</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/servicenow-v2/">ServiceNow V2</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/incident-tools/">Incident Tools</a></li>
</ul>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="playbooks">Playbooks<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#playbooks" class="hash-link" aria-label="Direct link to Playbooks" title="Direct link to Playbooks">​</a></h4>
<ul>
<li>[New] 541 - Management of AWS EKS Insights</li>
<li>[New] 542 - Resolution of AWS EKS Insights</li>
<li>[New] 543 - Alert and Vulnerability detection with Sysdig Secure</li>
<li>[New] 544 - Vulnerability Alert processing with Sysdig Secure</li>
<li>[New] 545 - Resolution of Sysdig Alerts</li>
<li>[New] 546 - Resolution of Sysdig Alerts - AWS EKS and AWS Nodes</li>
</ul>
<hr>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="june-5-2024---application-update">June 5, 2024 - Application Update<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#june-5-2024---application-update" class="hash-link" aria-label="Direct link to June 5, 2024 - Application Update" title="Direct link to June 5, 2024 - Application Update">​</a></h3>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="changes-and-enhancements-2">Changes and Enhancements<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#changes-and-enhancements-2" class="hash-link" aria-label="Direct link to Changes and Enhancements" title="Direct link to Changes and Enhancements">​</a></h4>
<h5 class="anchor anchorWithStickyNavbar_LWe7" id="cloud-soar-1">Cloud SOAR<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#cloud-soar-1" class="hash-link" aria-label="Direct link to Cloud SOAR" title="Direct link to Cloud SOAR">​</a></h5>
<ul>
<li>Incident list: Restored all bulk operations for select all option.</li>
</ul>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="bug-fixes-2">Bug fixes<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#bug-fixes-2" class="hash-link" aria-label="Direct link to Bug fixes" title="Direct link to Bug fixes">​</a></h4>
<ul>
<li>Playbooks:<!-- -->
<ul>
<li>Fixed start node configuration issue.</li>
<li>Fixed Input values not displayed correctly in Condition node.</li>
<li>Fixed issue related to send email action when cc field is not populated.</li>
<li>Fixed issue related to "Playbooks suddenly failing because of missing parameters".</li>
<li>Fixed issue with unsupported special characters.</li>
</ul>
</li>
<li>Integrations:<!-- -->
<ul>
<li>Fixed issue related to Internal Integration and output edit.</li>
<li>Fixed issue related to Join and unique operator.</li>
</ul>
</li>
<li>Entities: Fixed table loading issue.</li>
<li>Fixed issue related to trigger action, when APIs are involved.</li>
</ul>
<h5 class="anchor anchorWithStickyNavbar_LWe7" id="cloud-soar-2">Cloud SOAR<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#cloud-soar-2" class="hash-link" aria-label="Direct link to Cloud SOAR" title="Direct link to Cloud SOAR">​</a></h5>
<ul>
<li>SecOps: Fixed issue when filtering cards with large number of Incidents or Triage events.</li>
<li>Incidents:<!-- -->
<ul>
<li>Fixed closing note permission.</li>
<li>Fixed issue with old SOAR Incidents not loading.</li>
<li>Fixed issue related to mandatory Incident closing note.</li>
</ul>
</li>
<li>Fixed issue with Trigger action Incident Close.</li>
</ul>
<hr>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="april-23-2024---application-update">April 23, 2024 - Application Update<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#april-23-2024---application-update" class="hash-link" aria-label="Direct link to April 23, 2024 - Application Update" title="Direct link to April 23, 2024 - Application Update">​</a></h3>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="changes-and-enhancements-3">Changes and Enhancements<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#changes-and-enhancements-3" class="hash-link" aria-label="Direct link to Changes and Enhancements" title="Direct link to Changes and Enhancements">​</a></h4>
<ul>
<li>Integrations: Basic Tools added CC in Send Mail Action.</li>
</ul>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="bug-fixes-3">Bug fixes<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#bug-fixes-3" class="hash-link" aria-label="Direct link to Bug fixes" title="Direct link to Bug fixes">​</a></h4>
<ul>
<li>Integrations:<!-- -->
<ul>
<li>Fixed resource testing.</li>
<li>Fixed internal integration update process.</li>
<li>Fixed output fields containing a value of numerical "0" logged blanks instead of the actual number.</li>
</ul>
</li>
<li>Playbooks:<!-- -->
<ul>
<li>Fixed playbook condition logic with AND, OR operators.</li>
<li>Fixed textarea and regex parsing when HTML tags are enabled.</li>
<li>Fixed issue related to multiple playbook revisions and user choice execution.</li>
</ul>
</li>
</ul>
<h5 class="anchor anchorWithStickyNavbar_LWe7" id="cloud-soar-3">Cloud SOAR<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#cloud-soar-3" class="hash-link" aria-label="Direct link to Cloud SOAR" title="Direct link to Cloud SOAR">​</a></h5>
<ul>
<li>Incident: Fixed issue with war room large content loading.</li>
<li>API documentation updated.</li>
</ul>
<hr>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="april-18-2024---content-release">April 18, 2024 - Content Release<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#april-18-2024---content-release" class="hash-link" aria-label="Direct link to April 18, 2024 - Content Release" title="Direct link to April 18, 2024 - Content Release">​</a></h3>
<p>This release introduces two new integrations and several updates to integrations and related playbooks.</p>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="integrations-2">Integrations<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#integrations-2" class="hash-link" aria-label="Direct link to Integrations" title="Direct link to Integrations">​</a></h4>
<ul>
<li>[New] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/atlassian-opsgenie/">Atlassian Opsgenie</a></li>
<li>[New] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/druva/">Druva</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/atlassian-jira/">Atlassian Jira</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/basic-tools/">Basic Tools</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/microsoft-ews-daemon/">Microsoft EWS Daemon</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/servicenow-v2/">ServiceNow V2</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/slack/">Slack</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/sumo-logic-cloud-siem/">Sumo Logic Cloud SIEM</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/sumo-logic-cloud-siem-internal/">Sumo Logic Cloud SIEM Internal</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/sumo-logic-log-analytics/">Sumo Logic Log Analytics</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/sumo-logic-log-analytics-internal/">Sumo Logic Log Analytics Internal</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/virustotal/">VirusTotal</a></li>
</ul>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="playbooks-1">Playbooks<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#playbooks-1" class="hash-link" aria-label="Direct link to Playbooks" title="Direct link to Playbooks">​</a></h4>
<ul>
<li>[Updated] 501 - Send Insight AWS SNS Notification</li>
<li>[Updated] 502 - Send Insight Email Notification</li>
<li>[Updated] 503 - Enrich Entity with CrowdStrike Falcon Intelligence</li>
<li>[Updated] 504 - Enrich Entity with DomainTools</li>
<li>[Updated] 505 - Enrich IP with Geolocation from MaxMind</li>
<li>[Updated] 506 - Recommend Insight Response</li>
<li>[Updated] 507 - Create PagerDuty Incident for Insight</li>
<li>[Updated] 508 - Enrich Entity with PowerShell GreyNoise</li>
<li>[Updated] 509 - Enrich Entity with PowerShell SentinelOne</li>
<li>[Updated] 510 - Enrich Entity with PowerShell User Query</li>
<li>[Updated] 511 - Enrich Entity with PowerShell CrowdStrike</li>
<li>[Updated] 512 - Enrich Entity with PowerShell CarbonBlack</li>
<li>[Updated] 513 - Enrich Entity with PowerShell Whois</li>
<li>[Updated] 514 - Enrich Entity with PowerShell nslookup</li>
<li>[Updated] 515 - Enrich Entity with Recorded Future</li>
<li>[Updated] 516 - Enrich Hash with SentinelOne</li>
<li>[Updated] 517 - Create ServiceNow Ticket for Insight</li>
<li>[Updated] 518 - Update ServiceNow Ticket for Insight</li>
<li>[Updated] 519 - Send Insight Slack Notification</li>
<li>[Updated] 520 - Enrich Entity with Log Search</li>
<li>[Updated] 521 - Update Match List</li>
<li>[Updated] 522 - Create Jira Issue for Insight</li>
<li>[Updated] 523 - Update Jira Issue for Insight</li>
<li>[Updated] 524 - Enrich IP Address with GreyNoise</li>
<li>[Updated] 525 - Enrich Entity with Jamf</li>
<li>[Updated] 526 - Send Insight Teams Notification</li>
<li>[Updated] 527 - Enrich Entity with VirusTotal</li>
<li>[Updated] 528 - Create ZenDesk Ticket for Insight</li>
<li>[Updated] 529 - Update ZenDesk Ticket for Insight</li>
<li>[Updated] 530 - Get Mitre Mitigations for Insight</li>
<li>[Updated] 531 - Example Insight full Enrichment</li>
<li>[Updated] 532 - Example Entity full Enrichment</li>
<li>[Updated] 533 - Example Involved Entities full Enrichment</li>
<li>[Updated] 534 - Enrich Entity with AlienVault OTX</li>
<li>[Updated] 535 - Application Latency Playbook</li>
<li>[Updated] 536 - Unresolved Alert Notification</li>
<li>[Updated] 537 - Amazon GuardDuty BruteForce finding</li>
<li>[Updated] 538 - Admin Privileges Granted</li>
<li>[Updated] 539 - Amazon GuardDuty InstanceCredentialExfiltration finding</li>
<li>[Updated] 540 - EC2 instance accessed from malicious IP</li>
</ul>
<hr>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="april-9-2024---application-update">April 9, 2024 - Application Update<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#april-9-2024---application-update" class="hash-link" aria-label="Direct link to April 9, 2024 - Application Update" title="Direct link to April 9, 2024 - Application Update">​</a></h3>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="changes-and-enhancements-4">Changes and Enhancements<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#changes-and-enhancements-4" class="hash-link" aria-label="Direct link to Changes and Enhancements" title="Direct link to Changes and Enhancements">​</a></h4>
<ul>
<li>Text area editor: HTML mode is disabled by default.</li>
<li>Automation: In playbook list view now results are loaded after the user opens each action card.</li>
</ul>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="bug-fixes-4">Bug fixes<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#bug-fixes-4" class="hash-link" aria-label="Direct link to Bug fixes" title="Direct link to Bug fixes">​</a></h4>
<ul>
<li>App Central: Now when an integration is updated, user custom YAML output is automatically handled by the system and merged during the update process.</li>
<li>Automation: Users can now contact Sumo support asking from which public IPs automations will be generated.</li>
<li>Playbooks:<!-- -->
<ul>
<li>Fixed playbook saving action that caused playbooks to be empty.</li>
<li>Fixed issue related to multiple manual action execution in the same playbook.</li>
<li>Fixed import issue.</li>
</ul>
</li>
</ul>
<h5 class="anchor anchorWithStickyNavbar_LWe7" id="cloud-soar-4">Cloud SOAR<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#cloud-soar-4" class="hash-link" aria-label="Direct link to Cloud SOAR" title="Direct link to Cloud SOAR">​</a></h5>
<ul>
<li>Entities: Fixed issue when creating new entity of type FILE.</li>
<li>Rules: Now it is not possible to create two rules with the same name.</li>
<li>Incidents: Fixed issue related to incident privileges.</li>
</ul>
<hr>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="march-26-2024---application-update">March 26, 2024 - Application Update<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#march-26-2024---application-update" class="hash-link" aria-label="Direct link to March 26, 2024 - Application Update" title="Direct link to March 26, 2024 - Application Update">​</a></h3>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="bug-fixes-5">Bug fixes<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#bug-fixes-5" class="hash-link" aria-label="Direct link to Bug fixes" title="Direct link to Bug fixes">​</a></h4>
<ul>
<li>Playbooks:<!-- -->
<ul>
<li>Fixed execution with cartesian product disabled.</li>
<li>Fixed condition node not working as expected when evaluating value <code>0 == any string</code>.</li>
</ul>
</li>
<li>Fixed date-time format settings.</li>
</ul>
<h5 class="anchor anchorWithStickyNavbar_LWe7" id="cloud-soar-5">Cloud SOAR<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#cloud-soar-5" class="hash-link" aria-label="Direct link to Cloud SOAR" title="Direct link to Cloud SOAR">​</a></h5>
<ul>
<li>Triage: Fixed playbook graph view errors.</li>
<li>Incidents:<!-- -->
<ul>
<li>Fixed incidents navigation button disabled when inside an incident.</li>
<li>Fixed modal to add user as investigator that returned an error.</li>
<li>Fixed fields with '0' value displayed as empty in GUI.</li>
<li>Fixed issue related to 'Prohibit duplicate naming' that was not enforced properly in case of incidents created from automation rule.</li>
<li>Fixed duplicate incidents issue when created from webhooks (LAP scheduled search).</li>
<li>Fixed incidents list with empty rows.</li>
</ul>
</li>
</ul>
<hr>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="march-21-2024---content-release">March 21, 2024 - Content Release<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#march-21-2024---content-release" class="hash-link" aria-label="Direct link to March 21, 2024 - Content Release" title="Direct link to March 21, 2024 - Content Release">​</a></h3>
<p>This release introduces three new integrations, as well as several updates.</p>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="integrations-3">Integrations<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#integrations-3" class="hash-link" aria-label="Direct link to Integrations" title="Direct link to Integrations">​</a></h4>
<ul>
<li>[New] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/aws-private-certificate-authority/">AWS Private Certificate Authority</a></li>
<li>[New] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/criminal-ip/">Criminal IP</a></li>
<li>[New] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/datto-rmm/">Datto RMM</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/cyberark-pam/">CyberArk PAM</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/joe-sandbox/">Joe Sandbox</a><sup>*</sup></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/malwarebytes-nebula/">Malwarebytes Nebula</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/onelogin/">OneLogin</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/smtp-v3/">SMTP V3</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/zendesk/">Zendesk</a></li>
<li>[Updated] <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/zscaler/">Zscaler</a></li>
</ul>
<p><sup>*</sup> These integrations have been migrated and are now available in this release.</p>
<hr>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="march-12-2024---content-release">March 12, 2024 - Content Release<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#march-12-2024---content-release" class="hash-link" aria-label="Direct link to March 12, 2024 - Content Release" title="Direct link to March 12, 2024 - Content Release">​</a></h3>
<p>Our Cloud SOAR <a href="https://help.sumologic.com/release-notes-csoar/#march-12-2024---application-update">application update</a> features an important upgrade to Python 3.12 for our Lambda functions. This enhancement is part of our ongoing commitment to security, performance, and the latest technological standards.</p>
<p>The Python upgrade impacts a total of 38 integrations. These integrations will require updates to ensure compatibility with the new Python version.</p>
<p>Please be aware that with this update, the output from certain actions may no longer be displayed as expected if they were customized in your current setup. This is an important consideration for your workflows, and we recommend reviewing any customizations you have in place.</p>
<p>To facilitate a smooth transition, we have prepared a straightforward guide to assist you in updating your integrations. This guide outlines the steps you need to take to ensure your integrations work seamlessly with Python 3.12. <a href="https://help.sumologic.com/files/updating-app-central-integrations.pdf" target="_blank">Click here for the "Updating App Central Integrations" guide</a>.</p>
<p>Below is the full list of integrations that will be affected by the Python upgrade. Please review this list to determine which integrations in your environment will require attention.</p>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="integrations-4">Integrations<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#integrations-4" class="hash-link" aria-label="Direct link to Integrations" title="Direct link to Integrations">​</a></h4>
<ul>
<li>[Updated] AWS Security Hub</li>
<li>[Updated] AlienVault USM Anywhere</li>
<li>[Updated] Arbor</li>
<li>[Updated] Arcsight ESM</li>
<li>[Updated] Chronicle</li>
<li>[Updated] Coralogix - Send Logs</li>
<li>[Updated] Cortex XDR</li>
<li>[Updated] CrowdStrike Falcon</li>
<li>[Updated] CrowdStrike Falcon Intelligence</li>
<li>[Updated] CylanceProtect</li>
<li>[Updated] DarkOwl</li>
<li>[Updated] Darktrace</li>
<li>[Updated] Devo</li>
<li>[Updated] Elastic Security</li>
<li>[Updated] FortiAnalyzer</li>
<li>[Updated] IMAP</li>
<li>[Updated] Incident Tools</li>
<li>[Updated] KnowBe4 PhishER</li>
<li>[Updated] LogRhythm</li>
<li>[Updated] MISP</li>
<li>[Updated] Microsoft 365 Defender</li>
<li>[Updated] Microsoft EWS</li>
<li>[Updated] Microsoft EWS Daemon</li>
<li>[Updated] Microsoft Teams</li>
<li>[Updated] Mimecast</li>
<li>[Updated] Netskope</li>
<li>[Updated] ProtectOnce</li>
<li>[Updated] RSA NetWitness</li>
<li>[Updated] Recorded Future</li>
<li>[Updated] SentinelOne</li>
<li>[Updated] Sophos Central V3</li>
<li>[Updated] Sumo Logic</li>
<li>[Updated] Sumo Logic CSE</li>
<li>[Updated] Sumo Logic Notifications</li>
<li>[Updated] VMware Carbon Black Cloud Endpoint Standard V2</li>
<li>[Updated] VMware Carbon Black Cloud Platform</li>
<li>[Updated] VirusTotal</li>
<li>[Updated] WithSecure Elements</li>
</ul>
<p>We strongly encourage all users to review the provided documentation and prepare for the upcoming changes. Our support team is available to assist with any questions or concerns regarding this release.</p>
<hr>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="march-12-2024---application-update">March 12, 2024 - Application Update<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#march-12-2024---application-update" class="hash-link" aria-label="Direct link to March 12, 2024 - Application Update" title="Direct link to March 12, 2024 - Application Update">​</a></h3>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="changes-and-enhancements-5">Changes and Enhancements<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#changes-and-enhancements-5" class="hash-link" aria-label="Direct link to Changes and Enhancements" title="Direct link to Changes and Enhancements">​</a></h4>
<ul>
<li>Python version updated. If you experience any issues, refer to our <a href="https://help.sumologic.com/release-notes-csoar/#march-12-2024---content-release">content release note</a>.</li>
</ul>
<h5 class="anchor anchorWithStickyNavbar_LWe7" id="cloud-soar-6">Cloud SOAR<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#cloud-soar-6" class="hash-link" aria-label="Direct link to Cloud SOAR" title="Direct link to Cloud SOAR">​</a></h5>
<ul>
<li>Playbooks: Test feature now permits you to use internal Incident ID.</li>
</ul>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="bug-fixes-6">Bug fixes<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#bug-fixes-6" class="hash-link" aria-label="Direct link to Bug fixes" title="Direct link to Bug fixes">​</a></h4>
<ul>
<li>Playbooks:<!-- -->
<ul>
<li>Fixed test playbook broken functionality.</li>
<li>Fixed scheduled actions issue.</li>
</ul>
</li>
<li>Integrations: Fixed Docker Image build issue that resulted in an internal error.</li>
</ul>
<h5 class="anchor anchorWithStickyNavbar_LWe7" id="cloud-soar-7">Cloud SOAR<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#cloud-soar-7" class="hash-link" aria-label="Direct link to Cloud SOAR" title="Direct link to Cloud SOAR">​</a></h5>
<ul>
<li>Incidents: Fixed column reordering causing the table to disappear.</li>
<li>Triage: Fixed possibility to execute the same playbook more than two times.</li>
</ul>
<hr>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="february-27-2024---content-release">February 27, 2024 - Content Release<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#february-27-2024---content-release" class="hash-link" aria-label="Direct link to February 27, 2024 - Content Release" title="Direct link to February 27, 2024 - Content Release">​</a></h3>
<p>This release contains several updates, including the introduction of new actions and the resolution of some issues.</p>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="integrations-5">Integrations<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#integrations-5" class="hash-link" aria-label="Direct link to Integrations" title="Direct link to Integrations">​</a></h4>
<ul>
<li>[Updated] Lacework<!-- -->
<ul>
<li>New actions<!-- -->
<ul>
<li>Get Alert Details</li>
<li>Search Alerts</li>
</ul>
</li>
<li>Fixed endpoint in Close Alert action</li>
</ul>
</li>
<li>[Updated] Darktrace<!-- -->
<ul>
<li>Resolved bug related to integration resource</li>
</ul>
</li>
<li>[Updated] IP Quality Score<!-- -->
<ul>
<li>New actions<!-- -->
<ul>
<li>Email Reputation</li>
<li>URL Reputation</li>
</ul>
</li>
<li>Renamed action from "Get Credit Usage API" to "Get Credit Usage"</li>
<li>Refined labels and hints</li>
<li>Extended output mapping with examples</li>
</ul>
</li>
<li>[Updated] OneTrust<!-- -->
<ul>
<li>New action: Create Organization</li>
</ul>
</li>
<li>[Updated] Sumo Logic CSE<!-- -->
<ul>
<li>Fixed issue in the "Add Comment To Insight" action where line breaks in the "Insight Comment" field were removed upon submission</li>
</ul>
</li>
<li>[Updated] AWS IAM<!-- -->
<ul>
<li>New action: Get Access Key Last Used</li>
<li>Fixed bug in some actions</li>
</ul>
</li>
<li>[Updated] Incident Tools<!-- -->
<ul>
<li>Fixed Typo</li>
</ul>
</li>
<li>[Updated] Atlassian Jira<!-- -->
<ul>
<li>Enhanced "Create Issue" and "Update Issue" actions to support Jira custom fields</li>
</ul>
</li>
<li>[Updated] Screenshot Machine<!-- -->
<ul>
<li>Screenshot Webpage Action: Updated with new Cloud SOAR API</li>
</ul>
</li>
<li>[Updated] Chronicle<!-- -->
<ul>
<li>New actions:<!-- -->
<ul>
<li>Get Event</li>
<li>Get Events</li>
<li>Get Log</li>
<li>List Alerts</li>
<li>UDM Search</li>
</ul>
</li>
<li>Fixed a bug related to the PageSize field in the List Alerts action</li>
<li>Updated Alerts Daemon Chronicle<!-- -->
<ul>
<li>Fixed a bug related to Last execution time</li>
<li>Updated Output mappings</li>
</ul>
</li>
</ul>
</li>
<li>[Updated] Zscaler<!-- -->
<ul>
<li>Fixed an issue that prevented some actions from being executed</li>
</ul>
</li>
<li>[Updated] Mail Tools<!-- -->
<ul>
<li>Updated Analyze MSG EML action with new Cloud SOAR API</li>
</ul>
</li>
<li>[Updated] Recorded Future<!-- -->
<ul>
<li>Refactored Recorded Future Alerts Daemon</li>
<li>Refactored Vulnerability Search Daemon</li>
<li>Enabled Incident Artifacts feature flag for Get Alert Details action</li>
</ul>
</li>
<li>[Updated] GreyNoise<!-- -->
<ul>
<li>New action: Context IP Lookup Community</li>
<li>Other minor fixes</li>
</ul>
</li>
</ul>
<hr>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="february-19-2024---application-update">February 19, 2024 - Application Update<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#february-19-2024---application-update" class="hash-link" aria-label="Direct link to February 19, 2024 - Application Update" title="Direct link to February 19, 2024 - Application Update">​</a></h3>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="changes-and-enhancements-6">Changes and Enhancements<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#changes-and-enhancements-6" class="hash-link" aria-label="Direct link to Changes and Enhancements" title="Direct link to Changes and Enhancements">​</a></h4>
<ul>
<li>Playbooks:<!-- -->
<ul>
<li>Enabled <a href="https://help.sumologic.com/docs/platform-services/automation-service/automation-service-playbooks/#test-a-playbook">playbook testing</a>. With this improvement it is now possible to test a playbook configuration before publishing it, using Insight, Incident or custom JSON as input.</li>
<li>Action configuration: Integration fields configuration now suggests default values, if present.</li>
<li>UserChoice, answer by Email: Fixed Authorizer usage from previous nodes.</li>
</ul>
</li>
<li>AppCentral: Within the Integrations section, each integration card now contains a hyperlink to the related public documentation page <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/">Integrations in App Central</a>.</li>
<li>Integrations: It is now possible to send custom commands when an integration docker image is created. This feature is available for Not Certified integration only.</li>
</ul>
<h5 class="anchor anchorWithStickyNavbar_LWe7" id="cloud-soar-8">Cloud SOAR<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#cloud-soar-8" class="hash-link" aria-label="Direct link to Cloud SOAR" title="Direct link to Cloud SOAR">​</a></h5>
<ul>
<li>Enabled a new reporting feature for case management and dashboards.</li>
</ul>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="bug-fixes-7">Bug fixes<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#bug-fixes-7" class="hash-link" aria-label="Direct link to Bug fixes" title="Direct link to Bug fixes">​</a></h4>
<ul>
<li>Integrations:<!-- -->
<ul>
<li>Fixed Resource test issue.</li>
</ul>
</li>
<li>AppCentral: Fixed playbook preview when maximized view is used.</li>
</ul>
<h5 class="anchor anchorWithStickyNavbar_LWe7" id="cloud-soar-9">Cloud SOAR<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#cloud-soar-9" class="hash-link" aria-label="Direct link to Cloud SOAR" title="Direct link to Cloud SOAR">​</a></h5>
<ul>
<li>Rules: Fixed scheduled execution.</li>
<li>Tasks: Fixed creation if a required field is dismissed.</li>
<li>Incidents: Fixed full screen view buttons for widgets.</li>
<li>Notes: Fixed CSV export.</li>
</ul>
<hr>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="february-6-2024---application-update">February 6, 2024 - Application Update<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#february-6-2024---application-update" class="hash-link" aria-label="Direct link to February 6, 2024 - Application Update" title="Direct link to February 6, 2024 - Application Update">​</a></h3>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="new-documentation-for-the-cloud-soar-saas-version">New Documentation for the Cloud SOAR SaaS version​<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#new-documentation-for-the-cloud-soar-saas-version" class="hash-link" aria-label="Direct link to New Documentation for the Cloud SOAR SaaS version​" title="Direct link to New Documentation for the Cloud SOAR SaaS version​">​</a></h4>
<p>We are excited to announce the following new documentation for features in our Cloud SOAR SaaS version:</p>
<ul>
<li>Features:<!-- -->
<ul>
<li><a href="https://help.sumologic.com/docs/cloud-soar/incidents-triage/#create-a-dashboard">Dashboards</a></li>
<li><a href="https://help.sumologic.com/docs/cloud-soar/incidents-triage/#create-widgets">Create widgets for dashboards</a></li>
<li>Directly manage User Choice actions within the playbooks from your <a href="https://help.sumologic.com/docs/cloud-soar/automation/#configure-slack-for-cloud-soar">Slack workspace</a>.</li>
</ul>
</li>
<li>Open Integration Framework:<!-- -->
<ul>
<li><a href="https://help.sumologic.com/docs/platform-services/automation-service/automation-service-integrations/#create-a-new-integration">Integration Builder</a> allows you to build integrations without needing to provide code</li>
<li>Integrations, and related action execution, can be done <a href="https://help.sumologic.com/docs/platform-services/automation-service/automation-service-integrations/#cloud-or-bridge-execution">in the cloud or through the Bridge</a>. Only certified integrations can be executed in the cloud.</li>
<li>Certified integrations allow you to customize JSON and table output schema</li>
<li>Actions configuration during playbook design is rearranged for easier use</li>
</ul>
</li>
<li>Architecture:<!-- -->
<ul>
<li>Fully-functional in the Cloud (the Bridge is only required for custom integrations)</li>
<li>User and profile management is in Sumo Logic core platform instead of Cloud SOAR</li>
<li>Automatic scalability based on server load</li>
<li><a href="https://help.sumologic.com/docs/api/cloud-soar/">Cloud SOAR APIs</a> are standardized to use the same infrastructure as APIs in the Sumo Logic core platform</li>
</ul>
</li>
</ul>
<hr>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="january-30-2024---application-update">January 30, 2024 - Application Update<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#january-30-2024---application-update" class="hash-link" aria-label="Direct link to January 30, 2024 - Application Update" title="Direct link to January 30, 2024 - Application Update">​</a></h3>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="changes-and-enhancements-7">Changes and Enhancements<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#changes-and-enhancements-7" class="hash-link" aria-label="Direct link to Changes and Enhancements" title="Direct link to Changes and Enhancements">​</a></h4>
<ul>
<li>Added public help document for supported integrations. See <a href="https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/">Integrations in App Central</a>.</li>
<li>Integrations: Added possibility to rename an integration keeping original reference in YAML.</li>
<li>Playbooks:<!-- -->
<ul>
<li>List view set as default. View changes are saved in user preferences.</li>
<li>Deprecated Nested attribute.</li>
<li>Added possibility to dynamically reference a resource in actions.</li>
</ul>
</li>
<li>Automation now tracks failed actions executions.</li>
</ul>
<h5 class="anchor anchorWithStickyNavbar_LWe7" id="cloud-soar-10">Cloud SOAR<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#cloud-soar-10" class="hash-link" aria-label="Direct link to Cloud SOAR" title="Direct link to Cloud SOAR">​</a></h5>
<ul>
<li>Playbooks: Fixed insight execution for nested playbooks with more than 2 nesting levels.</li>
<li>Rules: Added ability to change the Daemon Name or Integration Resource within an existing automation rule.</li>
</ul>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="bug-fixes-8">Bug fixes<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#bug-fixes-8" class="hash-link" aria-label="Direct link to Bug fixes" title="Direct link to Bug fixes">​</a></h4>
<ul>
<li>Email encoding a character to UTF8 for literal string fixed.</li>
<li>Playbooks:<!-- -->
<ul>
<li>Unable to use variable fields with quotes in text area fixed.</li>
<li>Fixed playbook inputs not visible in TextArea placeholder.</li>
<li>Resolved scheduled action execution issue with playbook status.</li>
</ul>
</li>
</ul>
<h5 class="anchor anchorWithStickyNavbar_LWe7" id="cloud-soar-11">Cloud SOAR<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#cloud-soar-11" class="hash-link" aria-label="Direct link to Cloud SOAR" title="Direct link to Cloud SOAR">​</a></h5>
<ul>
<li>Incidents:<!-- -->
<ul>
<li>Fixed war room export for updated tasks.</li>
<li>Fixed possibility to copy table contents in Notes description field.</li>
<li>Incident creation: Fixed infinite spinner in Automation tab.</li>
</ul>
</li>
</ul>
<hr>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="january-25-2024---content-release">January 25, 2024 - Content Release<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#january-25-2024---content-release" class="hash-link" aria-label="Direct link to January 25, 2024 - Content Release" title="Direct link to January 25, 2024 - Content Release">​</a></h3>
<p>This release introduces new integrations, as well as new Playbooks related to Cloud Infrastructure Security for AWS.</p>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="integrations-6">Integrations<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#integrations-6" class="hash-link" aria-label="Direct link to Integrations" title="Direct link to Integrations">​</a></h4>
<ul>
<li>[New] Axonius</li>
<li>[New] OneTrust</li>
<li>[New] AWS Network Firewall</li>
<li>[Updated] Azure AD<!-- -->
<ul>
<li>Added New Action: Get Member Groups</li>
</ul>
</li>
<li>[Updated] AWS IAM<!-- -->
<ul>
<li>Added New Action: Update Access Key</li>
</ul>
</li>
<li>[Updated] Slack<!-- -->
<ul>
<li>Updated action: Ask Question</li>
</ul>
</li>
<li>[Updated] AWS EC2<!-- -->
<ul>
<li>Updated action: Stop Instance</li>
</ul>
</li>
<li>[Updated] Atlassian Jira<sup>*</sup>
<ul>
<li>Several changes have been made. This update introduces BREAKING CHANGES: both the Output Mapping and Input fields have been revised and updated. This version is specific to Jira Server and Data Center.</li>
</ul>
</li>
</ul>
<p><sup>*</sup> These integrations have been migrated and are now available in this release.</p>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="playbooks-2">Playbooks<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#playbooks-2" class="hash-link" aria-label="Direct link to Playbooks" title="Direct link to Playbooks">​</a></h4>
<ul>
<li>[New] 540 - EC2 instance accessed from malicious IP</li>
<li>[New] 539 - Amazon GuardDuty InstanceCredentialExfiltration finding</li>
<li>[New] 538 - Admin Privileges Granted</li>
<li>[New] 537 - Amazon GuardDuty BruteForce finding</li>
</ul>
<hr>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="january-8-2024---content-release">January 8, 2024 - Content Release<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#january-8-2024---content-release" class="hash-link" aria-label="Direct link to January 8, 2024 - Content Release" title="Direct link to January 8, 2024 - Content Release">​</a></h3>
<p>This release introduces two new integrations, <strong>ipdata</strong> and <strong>Google Alert Center</strong>, as well as several updates.</p>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="integrations-7">Integrations<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#integrations-7" class="hash-link" aria-label="Direct link to Integrations" title="Direct link to Integrations">​</a></h4>
<ul>
<li>[New] ipdata</li>
<li>[New] Google Alert Center</li>
<li>[Updated] PowerShell Tools<!-- -->
<ul>
<li>Updated the integration to address hostname resolution in Docker</li>
</ul>
</li>
<li>[Updated] Panda EDR<!-- -->
<ul>
<li>Fixed Token Issue</li>
</ul>
</li>
<li>[Updated] IPinfo<!-- -->
<ul>
<li>Enabled Incident Artifacts for IP Address field</li>
</ul>
</li>
<li>[Updated] CSE Tools<!-- -->
<ul>
<li>Extended output mapping for Get Signal action</li>
</ul>
</li>
<li>[Updated] Sumo Logic<!-- -->
<ul>
<li>Updated Search Sumo Logic Action</li>
</ul>
</li>
<li>[Updated] Have I Been Pwned<!-- -->
<ul>
<li>Added new action: Get Latest Breach</li>
</ul>
</li>
<li>[Updated] Sumo Logic CSE<!-- -->
<ul>
<li>Added new Action: Create Insight From Signals</li>
<li>Updated Add Enrichment Insight, Add Enrichment Entity, and Add Enrichment Signal actions</li>
</ul>
</li>
<li>[Updated] Incident Tools<!-- -->
<ul>
<li>Added new action: Get Incident</li>
</ul>
</li>
<li>[Updated] Lacework<!-- -->
<ul>
<li>Added new action: Close Alert</li>
</ul>
</li>
<li>[Updated] Active Directory V2<!-- -->
<ul>
<li>Updated action: User Attributes</li>
</ul>
</li>
<li>[Updated] Active Directory<!-- -->
<ul>
<li>Updated action: User Attributes V2</li>
</ul>
</li>
</ul>
<hr>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="january-3-2024---application-update">January 3, 2024 - Application Update<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#january-3-2024---application-update" class="hash-link" aria-label="Direct link to January 3, 2024 - Application Update" title="Direct link to January 3, 2024 - Application Update">​</a></h3>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="changes-and-enhancements-8">Changes and Enhancements<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#changes-and-enhancements-8" class="hash-link" aria-label="Direct link to Changes and Enhancements" title="Direct link to Changes and Enhancements">​</a></h4>
<ul>
<li>Playbooks: UserChoice nodes can be handled now from Slack workspace (see <a href="https://help.sumologic.com/docs/cloud-soar/automation/#configure-slack-for-cloud-soar">documentation</a>).</li>
</ul>
<h5 class="anchor anchorWithStickyNavbar_LWe7" id="cloud-soar-12">Cloud SOAR<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#cloud-soar-12" class="hash-link" aria-label="Direct link to Cloud SOAR" title="Direct link to Cloud SOAR">​</a></h5>
<ul>
<li>New privilege "Api Admin": Enabling this privilege in Log Analytics Platform will allow user to handle incident operations without being involved directly as investigator.</li>
</ul>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="bug-fixes-9">Bug fixes<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#bug-fixes-9" class="hash-link" aria-label="Direct link to Bug fixes" title="Direct link to Bug fixes">​</a></h4>
<ul>
<li>Fixed black screen when opening a Cloud SOAR or Automation Service URL with invalid session.</li>
<li>Playbooks:<!-- -->
<ul>
<li>Fixed: Parameters not being passed to nested playbooks.</li>
<li>Fixed: Configuration loss after being installed from App Central.</li>
<li>Placeholder TextArea with <code>&lt;</code> and <code>&gt;</code> that were converted in "spaces" in HTML.</li>
</ul>
</li>
</ul>
<h5 class="anchor anchorWithStickyNavbar_LWe7" id="cloud-soar-13">Cloud SOAR<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#cloud-soar-13" class="hash-link" aria-label="Direct link to Cloud SOAR" title="Direct link to Cloud SOAR">​</a></h5>
<ul>
<li>Groups: Fixed member removal that could result in broken requests.</li>
<li>Playbooks:<!-- -->
<ul>
<li>TextArea fixed placeholder view for Artifacts fields.</li>
<li>Incident ID placeholder available in node configuration.</li>
</ul>
</li>
</ul>
<h5 class="anchor anchorWithStickyNavbar_LWe7" id="automation-service">Automation Service<a href="https://help.sumologic.com/release-notes-csoar/2024/12/31/#automation-service" class="hash-link" aria-label="Direct link to Automation Service" title="Direct link to Automation Service">​</a></h5>
<ul>
<li>Playbooks: Start node parameters fixed by using a “.” or a "space" in parameter names that were converted into <code>_</code>.</li>
</ul>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[2023 Archive]]></title>
            <link>https://help.sumologic.com/release-notes-csoar/2023/12/31/</link>
            <guid>https://help.sumologic.com/release-notes-csoar/2023/12/31/</guid>
            <pubDate>Sun, 31 Dec 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[This is an archive of 2023 Cloud SOAR release notes. To view the full archive, click here.]]></description>
            <content:encoded><![CDATA[<a href="https://help.sumologic.com/release-notes-csoar/rss.xml"><img src="https://help.sumologic.com/img/release-notes/rss-orange2.png" alt="icon" width="50"></a>
<p>This is an archive of 2023 Cloud SOAR release notes. To view the full archive, <a href="https://help.sumologic.com/release-notes-csoar/archive/">click here</a>.</p>
<hr>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="december-04-2023---application-update">December 04, 2023 - Application Update<a href="https://help.sumologic.com/release-notes-csoar/2023/12/31/#december-04-2023---application-update" class="hash-link" aria-label="Direct link to December 04, 2023 - Application Update" title="Direct link to December 04, 2023 - Application Update">​</a></h3>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="changes-and-enhancements">Changes and Enhancements<a href="https://help.sumologic.com/release-notes-csoar/2023/12/31/#changes-and-enhancements" class="hash-link" aria-label="Direct link to Changes and Enhancements" title="Direct link to Changes and Enhancements">​</a></h4>
<ul>
<li>Playbooks: Added ability to dynamically select an authorizer in UserChoice node.</li>
</ul>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="cloud-soar">Cloud SOAR<a href="https://help.sumologic.com/release-notes-csoar/2023/12/31/#cloud-soar" class="hash-link" aria-label="Direct link to Cloud SOAR" title="Direct link to Cloud SOAR">​</a></h4>
<ul>
<li>Contextual menu now contains Open link in new tab action if URL is highlighted.</li>
</ul>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="automation-service">Automation Service<a href="https://help.sumologic.com/release-notes-csoar/2023/12/31/#automation-service" class="hash-link" aria-label="Direct link to Automation Service" title="Direct link to Automation Service">​</a></h4>
<ul>
<li>The Automation Service now permits you to execute Containment and Scheduled actions. App Central has been updated accordingly.</li>
<li>Manual playbook interaction through user choice node and manual action.</li>
</ul>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="bug-fixes">Bug fixes<a href="https://help.sumologic.com/release-notes-csoar/2023/12/31/#bug-fixes" class="hash-link" aria-label="Direct link to Bug fixes" title="Direct link to Bug fixes">​</a></h4>
<ul>
<li>Selecting a timestamp while testing integrations no longer results in the wrong timestamp being used.</li>
<li>Boolean values are no longer processed as null in actions/playbooks.</li>
<li>There is no longer an issue using a playbooks placeholder in the textArea for Incident fields.</li>
<li>Editing a playbook and publishing no longer causes an empty playbook.</li>
</ul>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="cloud-soar-1">Cloud SOAR<a href="https://help.sumologic.com/release-notes-csoar/2023/12/31/#cloud-soar-1" class="hash-link" aria-label="Direct link to Cloud SOAR" title="Direct link to Cloud SOAR">​</a></h4>
<ul>
<li>In playbooks, Incident fields are now available in condition nodes (they are no longer "NULL").</li>
<li>The file type is now displayed for Entities files.</li>
</ul>
<hr>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="november-20-2023---content-release">November 20, 2023 - Content Release<a href="https://help.sumologic.com/release-notes-csoar/2023/12/31/#november-20-2023---content-release" class="hash-link" aria-label="Direct link to November 20, 2023 - Content Release" title="Direct link to November 20, 2023 - Content Release">​</a></h3>
<p>This release introduces several new integrations, including <strong>Prisma Cloud</strong>, alongside various integrations that have been migrated and are now accessible through App Central.</p>
<p>We've also improved multiple integrations and introduced new actions, implemented various general fixes and enhancements.</p>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="integrations">Integrations<a href="https://help.sumologic.com/release-notes-csoar/2023/12/31/#integrations" class="hash-link" aria-label="Direct link to Integrations" title="Direct link to Integrations">​</a></h3>
<ul>
<li>[New] CylanceProtect<sup>*</sup></li>
<li>[New] ESMTP<sup>*</sup></li>
<li>[New] Elasticsearch V2<sup>*</sup></li>
<li>[New] EnergyLogserver<sup>*</sup></li>
<li>[New] FortiSIEM<sup>*</sup></li>
<li>[New] Gmail<sup>*</sup></li>
<li>[New] Javelin AD Protect<sup>*</sup></li>
<li>[New] Lastline Analyst<sup>*</sup></li>
<li>[New] POP3<sup>*</sup></li>
<li>[New] Prisma Cloud</li>
<li>[New] Triage Tools<sup>*</sup></li>
<li>[New] ZIP Tools<sup>*</sup></li>
<li>[Updated] Basic Tools<!-- -->
<ul>
<li>Added new action: Payload Regex</li>
</ul>
</li>
<li>[Updated] Sumo Logic<!-- -->
<ul>
<li>Following Actions Updated:<!-- -->
<ul>
<li>Updated Action: Aggregates Sumo Logic Daemon</li>
<li>Updated Action: Search Metrics</li>
<li>Updated Action: Search Sumo Logic Daemon</li>
</ul>
</li>
</ul>
</li>
<li>[Updated] VMware Carbon Black Cloud Platform<!-- -->
<ul>
<li>Updated with new Cloud SOAR API</li>
</ul>
</li>
</ul>
<p><sup>*</sup> These integrations have been migrated and are now available in this release.</p>
<hr>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="november-16-2023---application-update">November 16, 2023 - Application Update<a href="https://help.sumologic.com/release-notes-csoar/2023/12/31/#november-16-2023---application-update" class="hash-link" aria-label="Direct link to November 16, 2023 - Application Update" title="Direct link to November 16, 2023 - Application Update">​</a></h3>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="changes-and-enhancements-1">Changes and Enhancements<a href="https://help.sumologic.com/release-notes-csoar/2023/12/31/#changes-and-enhancements-1" class="hash-link" aria-label="Direct link to Changes and Enhancements" title="Direct link to Changes and Enhancements">​</a></h4>
<ul>
<li>Added documentation for <a href="https://help.sumologic.com/docs/platform-services/automation-service/automation-service-audit-logging/">Cloud SOAR Audit Logging</a>.</li>
</ul>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="bug-fixes-1">Bug fixes<a href="https://help.sumologic.com/release-notes-csoar/2023/12/31/#bug-fixes-1" class="hash-link" aria-label="Direct link to Bug fixes" title="Direct link to Bug fixes">​</a></h4>
<ul>
<li>Actions: Fixed run action causing page reload when response data is too large.</li>
<li>Playbooks: Removed Resource from inputs when selecting an Internal integration in add or edit node.</li>
<li>Playbooks actions: Fixed boolean values processed as null.</li>
</ul>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="cloud-soar-2">Cloud SOAR<a href="https://help.sumologic.com/release-notes-csoar/2023/12/31/#cloud-soar-2" class="hash-link" aria-label="Direct link to Cloud SOAR" title="Direct link to Cloud SOAR">​</a></h4>
<ul>
<li>Fixed API v3 change incident owner when using incorrect owner ID or with a Group ID.</li>
<li>Fixed "Incident Tools" action Add Note issue.</li>
<li>Fixed Playbooks "Run Test" against an Incident where modal remained with infinite loader.</li>
</ul>
<hr>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="november-1-2023---application-update">November 1, 2023 - Application Update<a href="https://help.sumologic.com/release-notes-csoar/2023/12/31/#november-1-2023---application-update" class="hash-link" aria-label="Direct link to November 1, 2023 - Application Update" title="Direct link to November 1, 2023 - Application Update">​</a></h3>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="sumo-logic-on-premises-soar-solution-end-of-life">Sumo Logic On-Premises SOAR Solution End-of-Life<a href="https://help.sumologic.com/release-notes-csoar/2023/12/31/#sumo-logic-on-premises-soar-solution-end-of-life" class="hash-link" aria-label="Direct link to Sumo Logic On-Premises SOAR Solution End-of-Life" title="Direct link to Sumo Logic On-Premises SOAR Solution End-of-Life">​</a></h4>
<p>As of <strong>November 15, 2023</strong>, Sumo Logic's on-premises SOAR solution no longer receives updates, and Sumo Logic Engineering no longer develops, repairs, maintains, or tests the software.</p>
<p>Effective <strong>December 31, 2024</strong>, Sumo Logic’s on-premises SOAR solution reaches end-of-life and becomes obsolete. Beginning on that date, it no longer receives applicable support entitled by active support contracts or by applicable warranty terms and conditions.</p>
<p>To upgrade to Sumo Logic’s <a href="https://help.sumologic.com/docs/cloud-soar/">Cloud SOAR</a> offering, reach out to your Sumo Logic representative.</p>
<hr>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="october-23-2023---content-release">October 23, 2023 - Content Release<a href="https://help.sumologic.com/release-notes-csoar/2023/12/31/#october-23-2023---content-release" class="hash-link" aria-label="Direct link to October 23, 2023 - Content Release" title="Direct link to October 23, 2023 - Content Release">​</a></h3>
<p>This release introduces several new integrations, including <strong>Atlassian Confluence</strong> and <strong>Google Drive</strong>, alongside various integrations that have been migrated and are now accessible through App Central.</p>
<p>We've also improved multiple integrations to leverage the new Cloud SOAR API, introduced new actions, and implemented various general fixes and enhancements.</p>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="integrations-1">Integrations<a href="https://help.sumologic.com/release-notes-csoar/2023/12/31/#integrations-1" class="hash-link" aria-label="Direct link to Integrations" title="Direct link to Integrations">​</a></h4>
<ul>
<li>[New] Atlassian Confluence</li>
<li>[New] Google Drive</li>
<li>[New]* Cofense</li>
<li>[New]* Microsoft EWS</li>
<li>[New]* SMTP V3</li>
<li>[New]* Microsoft EWS Extension</li>
<li>[New]* AbuseIPDB</li>
<li>[New]* APIVoid</li>
<li>[New]* VMware Carbon Black Cloud Endpoint Standard</li>
<li>[New]* VMware Carbon Black Cloud Enterprise EDR</li>
<li>[New]* VMware Carbon Black Cloud Platform</li>
<li>[New]* Lacework</li>
<li>[New]* Sumo Logic</li>
<li>[New]* Sumo Logic Notifications</li>
<li>[Updated] CSE Tools<!-- -->
<ul>
<li>Added new action: Insight Output Mapping</li>
</ul>
</li>
<li>[Updated] Microsoft EWS Daemon<!-- -->
<ul>
<li>Updated with new Cloud SOAR API</li>
</ul>
</li>
<li>[Updated] Sumo Logic CSE<!-- -->
<ul>
<li>Updated Daemon: Sumo Logic Insights Daemon Extended</li>
<li>Updated Daemon: Sumo Logic Insights Daemon</li>
</ul>
</li>
<li>[Updated] Mail Tools<!-- -->
<ul>
<li>Updated with new Cloud SOAR API</li>
</ul>
</li>
<li>[Updated] IMAP<!-- -->
<ul>
<li>Updated with new Cloud SOAR API</li>
</ul>
</li>
</ul>
<p><em>* These integrations have been migrated and are now available in this release.</em></p>
<hr>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="october-20-2023---application-update">October 20, 2023 - Application Update<a href="https://help.sumologic.com/release-notes-csoar/2023/12/31/#october-20-2023---application-update" class="hash-link" aria-label="Direct link to October 20, 2023 - Application Update" title="Direct link to October 20, 2023 - Application Update">​</a></h3>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="changes-and-enhancements-2">Changes and Enhancements<a href="https://help.sumologic.com/release-notes-csoar/2023/12/31/#changes-and-enhancements-2" class="hash-link" aria-label="Direct link to Changes and Enhancements" title="Direct link to Changes and Enhancements">​</a></h4>
<ul>
<li>Automation Bridge: ECR docker images are now replicated in all AWS regions.</li>
<li>App Central: Introduced Tags attribute for playbooks.</li>
<li>Audit Logs: Enabled events forwarding to Log Analytics Platform.</li>
<li>Playbooks: Improved status field update and granularity.</li>
</ul>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="cloud-soar-3">Cloud SOAR<a href="https://help.sumologic.com/release-notes-csoar/2023/12/31/#cloud-soar-3" class="hash-link" aria-label="Direct link to Cloud SOAR" title="Direct link to Cloud SOAR">​</a></h4>
<ul>
<li>Incident closing note: It is now part of APIv3 response and available as Read Only field in Incident Overview page.</li>
</ul>
<h4 class="anchor anchorWithStickyNavbar_LWe7" id="bug-fixes-2">Bug fixes<a href="https://help.sumologic.com/release-notes-csoar/2023/12/31/#bug-fixes-2" class="hash-link" aria-label="Direct link to Bug fixes" title="Direct link to Bug fixes">​</a></h4>
<h5 class="anchor anchorWithStickyNavbar_LWe7" id="cloud-soar-4">Cloud SOAR<a href="https://help.sumologic.com/release-notes-csoar/2023/12/31/#cloud-soar-4" class="hash-link" aria-label="Direct link to Cloud SOAR" title="Direct link to Cloud SOAR">​</a></h5>
<ul>
<li>Playbooks: Fixed display in task result table view for Authorizer.</li>
<li>Rules: Fixed bug not displaying all Integrations using same daemon.</li>
</ul>
<h5 class="anchor anchorWithStickyNavbar_LWe7" id="automation-service-1">Automation Service<a href="https://help.sumologic.com/release-notes-csoar/2023/12/31/#automation-service-1" class="hash-link" aria-label="Direct link to Automation Service" title="Direct link to Automation Service">​</a></h5>
<ul>
<li>Playbooks: Fixed possibility to add new playbook type.</li>
<li>Playbooks: Fixed killing playbook update status.</li>
</ul>
<hr>
<h3 class="anchor anchorWithStickyNavbar_LWe7" id="june-8-2023---introducing-the-new-release-notes-section-for-cloud-soar">June 8, 2023 - Introducing the new Release Notes section for Cloud SOAR<a href="https://help.sumologic.com/release-notes-csoar/2023/12/31/#june-8-2023---introducing-the-new-release-notes-section-for-cloud-soar" class="hash-link" aria-label="Direct link to June 8, 2023 - Introducing the new Release Notes section for Cloud SOAR" title="Direct link to June 8, 2023 - Introducing the new Release Notes section for Cloud SOAR">​</a></h3>
<p>We welcome you to the new Release Notes section of Cloud SOAR. Here you will find all the latest news about CSOAR, from new features, bug fixes, and changes to the application.</p>]]></content:encoded>
        </item>
    </channel>
</rss>