Skip to content

Latest commit

 

History

History
44 lines (37 loc) · 1.73 KB

47b7d4bc-c062-460e-b39a-e28d171523e9.md

File metadata and controls

44 lines (37 loc) · 1.73 KB

Mappings: CloudTrail - signin.amazonaws.com - All AwsConsoleSignIn events

Input Requirements

Input Value
Vendor AWS
Product CloudTrail
Log Format JSON
Event ID Regex Pattern AwsConsoleSignIn-(ConsoleLogin|CheckMfa|ExitRole|RenewRole|SwitchRole)

Record Output

Output Value
Vendor Amazon AWS
Product CloudTrail
Record Type Authentication

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
accountId userIdentity.accountId
action eventName
application eventSource
authProvider additionalEventData.SamlProviderArn
cause errorMessage
cloud_provider None The static text AWS is populated in this schema field.
cloud_region awsRegion
cloud_service None The static text SignIn is populated in this schema field.
description eventName This is a lookup field. More info to come in the catalog later...
device_ip sourceIPAddress
http_userAgent userAgent
mfa additionalEventData.MFAUsed This is a lookup field. More info to come in the catalog later...
normalizedAction eventName This is a lookup field. More info to come in the catalog later...
normalizedResource eventName This is a lookup field. More info to come in the catalog later...
normalizedSeverity eventName This is a lookup field. More info to come in the catalog later...
srcDevice_ip sourceIPAddress
success responseElements.ConsoleLogin This is a lookup field. More info to come in the catalog later...
timestamp eventTime We expect the orginal record value of eventTime is in the format yyyy-MM-dd'T'HH:mm:ss'Z'
user_userId userIdentity.principalId
user_username userIdentity.sessionContext.sourceIdentity