Mappings: CloudTrail - signin.amazonaws.com - All AwsConsoleSignIn events
Input | Value |
---|---|
Vendor | AWS |
Product | CloudTrail |
Log Format | JSON |
Event ID Regex Pattern | AwsConsoleSignIn-(ConsoleLogin|CheckMfa|ExitRole|RenewRole|SwitchRole) |
Output | Value |
---|---|
Vendor | Amazon AWS |
Product | CloudTrail |
Record Type | Authentication |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
accountId | userIdentity.accountId | |
action | eventName | |
application | eventSource | |
authProvider | additionalEventData.SamlProviderArn | |
cause | errorMessage | |
cloud_provider | None | The static text AWS is populated in this schema field. |
cloud_region | awsRegion | |
cloud_service | None | The static text SignIn is populated in this schema field. |
description | eventName | This is a lookup field. More info to come in the catalog later... |
device_ip | sourceIPAddress | |
http_userAgent | userAgent | |
mfa | additionalEventData.MFAUsed | This is a lookup field. More info to come in the catalog later... |
normalizedAction | eventName | This is a lookup field. More info to come in the catalog later... |
normalizedResource | eventName | This is a lookup field. More info to come in the catalog later... |
normalizedSeverity | eventName | This is a lookup field. More info to come in the catalog later... |
srcDevice_ip | sourceIPAddress | |
success | responseElements.ConsoleLogin | This is a lookup field. More info to come in the catalog later... |
timestamp | eventTime | We expect the orginal record value of eventTime is in the format yyyy-MM-dd'T'HH:mm:ss'Z' |
user_userId | userIdentity.principalId | |
user_username | userIdentity.sessionContext.sourceIdentity |