Skip to content

Latest commit

 

History

History
39 lines (32 loc) · 1.12 KB

10cc2415-7909-4610-a417-7e755696a0a5.md

File metadata and controls

39 lines (32 loc) · 1.12 KB

Mappings: CloudTrail - ecs.amazonaws.com - AwsApiCall-ExecuteCommand

Input Requirements

Input Value
Vendor AWS
Product CloudTrail
Log Format JSON
Event ID Regex Pattern AwsApiCall-ExecuteCommand

Record Output

Output Value
Vendor Amazon AWS
Product CloudTrail
Record Type Audit

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
accountId userIdentity.accountId
action eventName
application eventSource
cloud_provider None The static text AWS is populated in this schema field.
cloud_region awsRegion
cloud_service None The static text ECS is populated in this schema field.
commandLine requestParameters.command
device_container_name requestParameters.container
device_ip sourceIPAddress
errorCode errorCode
errorText errorMessage
http_userAgent userAgent
srcDevice_ip sourceIPAddress
timestamp eventTime We expect the orginal record value of eventTime is in the format yyyy-MM-dd'T'HH:mm:ss'Z'
user_username userIdentity.sessionContext.sourceIdentity