Parsing Rules
View as code (Beta)
Preview the Terraform and Kubernetes YAML representation of any saved rule group. Open from the rule list ⋮ more actions menu → View as Code. Tabs for Terraform (default) and K8s, with copy, download, search, and collapse/expand controls. Learn more
Custom log enrichment and log normalization
Custom log enrichment is now even more intuitive — enrich logs from specific columns in your CSV file, download enriched files, and use them as data sources in DataPrime queries. Learn more
Log normalization — standardize keys for commonly occurring values across various security log types. Learn more
Stringify and Parse JSON Field rules
New Parsing Rules — Stringify JSON Field and Parse JSON Field rules to parse escaped JSON values within a field to a valid JSON object and vice versa. Learn more

