Releases: lnfernux/log-baseline
Releases · lnfernux/log-baseline
Release list
Log Baseline 0.3.0
Separates security value from storage tier and records the rule behind each recommendation. Data 0.3.0, schema 1.2.0.
Changes
classificationfollows value rules C1-C9 mapped to ASD's priority logs for SIEM ingestion and CISA's M-21-31 guidance.recommendedTierfollows tier rules T1-T5. Volume no longer sets the classification.- Reclassified 89 tables. 88 moved to primary, including all Entra ID sign-in log types, firewall, DNS, proxy, flow, storage access, database audit, security tool admin audit, and collaboration audit tables.
DnsInventorymoved to secondary. - Moved DNS and network session tables (
DnsEvents,ASimDnsActivityLogs,ASimNetworkSessionLogs,ASimWebSessionLogs, and others) from Analytics to Data lake. - Recommended Analytics for 40 tables that previously recommended Data lake but do not support the Auxiliary/Lake plan. Validation now rejects that combination.
- Added optional
volumeClass,volumeDriver,valueRule, andtierRulefields and populated them for every classification. - Added 16 tables: Defender for Endpoint custom data collection, Intune, and Azure VMware Solution.
- Added provenance for ASD, CISA, Microsoft Sentinel data lake documentation, the Azure Monitor table reference, the volume model, and the classification rules.
- The review importer replaces changed records, adds reviewed source records, and regenerates the pre-made baselines.
Compatibility
The data contract is backward compatible: the new fields are optional and no existing field changed. The 89 reclassifications and 78 tier changes do change Log Horizon's per-table recommendations once it vendors 0.3.0.
Log Baseline 0.2.0
Log Baseline 0.1.0
Full Changelog: https://github.com/lnfernux/log-baseline/commits/v0.1.0