Skip to content

Latest commit

 

History

History
39 lines (32 loc) · 1.31 KB

1c8fe1c9-f66f-439d-af45-37840a4f781e.md

File metadata and controls

39 lines (32 loc) · 1.31 KB

Mappings: CloudTrail - ecr.amazonaws.com - PolicyExecutionEvent

Input Requirements

Input Value
Vendor AWS
Product CloudTrail
Log Format JSON
Event ID Regex Pattern AwsServiceEvent-PolicyExecutionEvent

Record Output

Output Value
Vendor Amazon AWS
Product CloudTrail
Record Type AuditResourceAccess

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
accountId userIdentity.accountId
action eventName
application eventSource
cloud_provider None The static text AWS is populated in this schema field.
cloud_region awsRegion
cloud_service None The static text ECR is populated in this schema field.
description None The static text A policy took an automatic execution action to enforce the policy. is populated in this schema field.
device_ip sourceIPAddress
http_userAgent userAgent
normalizedAction None The static text execute is populated in this schema field.
normalizedSeverity None The static text 1 is populated in this schema field.
resource resources.1.ARN
srcDevice_ip sourceIPAddress
timestamp eventTime We expect the orginal record value of eventTime is in the format yyyy-MM-dd'T'HH:mm:ssZ
user_username userIdentity.invokedBy