Skip to content

Latest commit

 

History

History
37 lines (30 loc) · 1.02 KB

2c6a02e4-89b0-4d30-b03d-45756f074266.md

File metadata and controls

37 lines (30 loc) · 1.02 KB

Mappings: CloudTrail Default Mapping

Input Requirements

Input Value
Vendor AWS
Product CloudTrail
Log Format JSON
Event ID Regex Pattern _default_

Record Output

Output Value
Vendor Amazon AWS
Product CloudTrail
Record Type Audit

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
accountId userIdentity.accountId
action eventName
application eventSource
bytesIn additionalEventData.bytesTransferredIn
bytesOut additionalEventData.bytesTransferredOut
cloud_provider None The static text AWS is populated in this schema field.
cloud_region awsRegion
device_ip sourceIPAddress
http_userAgent userAgent
srcDevice_ip sourceIPAddress
timestamp eventTime We expect the orginal record value of eventTime is in the format yyyy-MM-dd'T'HH:mm:ss'Z'
user_role userIdentity.sessionContext.sessionIssuer.userName
user_username userIdentity.sessionContext.sourceIdentity