Table of Contents | ||||
---|---|---|---|---|
|
...
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
AWS Web Application Firewall (WAF) |
|
|
For more information, read more about Devo tags.
How is the data sent to Devo?
Logs generated by AWS WAF service can be sent to AWS CloudWatch Logs, S3, and Kinesis Data Firehose services.
...
These are the fields displayed in this table:
cloud.aws.waf.logs
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
| |||
hostname |
| |||
ACCID |
| |||
ACCID_actual |
|
REGION |
|
timestamp |
| |||
formatVersion |
|
webaclId |
|
terminatingRuleId |
| |||
terminatingRuleType |
|
action |
|
terminatingRuleMatchDetails_conditionType_ |
str |
|
|
httpRequest_country
str
| terminatingRuleMatchDetails_conditionType | |||
terminatingRuleMatchDetails_location_str |
|
|
|
|
terminatingRuleMatchDetails_ |
location |
terminatingRuleMatchDetails_ |
matchedData_ |
str |
|
|
|
|
terminatingRuleMatchDetails_ |
matchedData | |
httpSourceName |
|
httpSourceId |
|
ruleGroupList_ruleGroupId_ |
str |
httpSourceName
str
|
httpSourceId
str
| ruleGroupList_ruleGroupId | |||
ruleGroupList_terminatingRule_ruleId_str |
|
|
|
|
ruleGroupList_terminatingRule_ |
ruleId |
ruleGroupList_terminatingRule_action_str |
|
|
|
ruleGroupList_terminatingRule_action |
ruleGroupList_terminatingRule_ |
ruleMatchDetails_str |
|
|
|
|
ruleGroupList_terminatingRule_ |
ruleMatchDetails |
ruleGroupList_ |
nonTerminatingMatchingRules_str |
|
|
|
|
ruleGroupList_ |
nonTerminatingMatchingRules |
ruleGroupList_ |
excludedRules_str |
|
|
|
|
ruleGroupList_ |
REGION
str
excludedRules | |||||
rateBasedRuleList_rateBasedRuleId_str |
|
| rateBasedRuleList_rateBasedRuleId |
rawMessage
str
rateBasedRuleList_limitKey_str |
|
|
|
|
rateBasedRuleList_ |
limitKey |
rateBasedRuleList_ |
maxRateAllowed_str |
|
|
|
|
rateBasedRuleList_ |
responseCodeSent
int4
maxRateAllowed | ||||
nonTerminatingMatchingRules_action_str |
|
|
|
|
nonTerminatingMatchingRules_ |
action |
nonTerminatingMatchingRules_ |
ruleId_str |
|
|
|
|
nonTerminatingMatchingRules_ |
ruleId |
requestHeadersInserted_ |
name_str |
|
|
|
|
requestHeadersInserted_ |
name |
requestHeadersInserted_ |
value_str |
|
|
|
|
ruleGroupList_terminatingRule_action
requestHeadersInserted_value | ||||
responseCodeSent |
| |||
httpRequest_clientIp |
| |||
httpRequest_country |
| |||
httpRequest_headers_name_str |
|
|
|
|
|
httpRequest_ |
headers_ |
name |
httpRequest_ |
headers_ |
value_str |
|
|
|
|
|
httpRequest_ |
headers_ |
value |
httpRequest_uri |
| |||
httpRequest_args |
|
httpRequest_httpVersion |
|
httpRequest_ |
httpMethod |
|
Code Block |
---|
join(terminatingRuleMatchDetails_conditionType, ',') |
terminatingRuleMatchDetails_conditionType
httpRequest_requestId |
| |||
labels_name_str |
|
|
|
|
labels_ |
terminatingRuleType
str
timestamp
timestamp
webaclId
str
name | |
hostchain |
|
Code Block |
---|
join(terminatingRuleMatchDetails_matchedData, ',') |
terminatingRuleMatchDetails_matchedData
✓ | ||||
tag |
| ✓ | ||
rawMessage |
| ✓ |