Skip to content

Latest commit

 

History

History
40 lines (33 loc) · 1.35 KB

5406ec15-2203-460b-bd6e-ea8facf33082.md

File metadata and controls

40 lines (33 loc) · 1.35 KB

Mappings: CloudTrail - secretsmanager.amazonaws.com - SecretVersionDeletion

Input Requirements

Input Value
Vendor AWS
Product CloudTrail
Log Format JSON
Event ID Regex Pattern AwsServiceEvent-SecretVersionDeletion

Record Output

Output Value
Vendor Amazon AWS
Product CloudTrail
Record Type Audit

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
accountId userIdentity.accountId
action eventName
application eventSource
cloud_provider None The static text AWS is populated in this schema field.
cloud_region awsRegion
cloud_service None The static text Secrets Manager is populated in this schema field.
description None The static text A request to delete a version of a secret in Secret Manager issued. is populated in this schema field.
device_ip sourceIPAddress
http_userAgent userAgent
normalizedAction None The static text delete is populated in this schema field.
normalizedSeverity None The static text 1 is populated in this schema field.
srcDevice_ip sourceIPAddress
threat_name eventName
timestamp eventTime We expect the orginal record value of eventTime is in the format yyyy-MM-dd'T'HH:mm:ssZ
user_userId userIdentity.invokedBy
user_username userIdentity.invokedBy