Introduction
The tags beginning with cloud.aws.guardduty
identify events generated by AWS GuardDuty.
Valid tags and data tables
The full tag must have 4 levels. The first 3 are fixed as cloud.aws.guardduty
. The fourth level indicates the event subtype.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
AWS GuardDuty |
|
|
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in these tables:
cloud.aws.guardduty.events
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
|
|
| |
timestamp |
|
| time | |
ACCID_TAG |
|
| ACCID | |
REGION_TAG |
|
| REGION | |
detail_type |
|
|
| |
detail_title |
|
|
| |
detail_findings_title |
|
|
| |
detail_findings_compliance_status |
|
|
| |
detail_findings_remediation_recommendation_url |
|
|
| |
version |
|
|
| |
id |
|
|
| |
source |
|
|
| |
account |
|
|
| |
region |
|
|
| |
resources_str |
| join(resources, ',') | resources | |
detail_schemaVersion |
|
|
| |
detail_accountId |
|
|
| |
detail_region |
|
|
| |
detail_partition |
|
|
| |
detail_id |
|
|
| |
detail_arn |
|
|
| |
detail_severity |
|
|
| |
detail_createdAt |
|
|
| |
detail_updatedAt |
|
|
| |
detail_description |
|
|
| |
detail_detail_type |
|
|
| |
detail_resource_resourceType |
|
|
| |
detail_resource_instanceDetails_instanceId |
|
|
| |
detail_resource_instanceDetails_instanceType |
|
|
| |
detail_resource_instanceDetails_launchTime |
|
|
| |
detail_resource_instanceDetails_platform |
|
|
| |
productCodes_productCodeId_str |
| join(productCodes_productCodeId, ',') | productCodes_productCodeId | |
productCodes_productCodeType_str |
| join(productCodes_productCodeType, ',') | productCodes_productCodeType | |
detail_resource_instanceDetails_iamInstanceProfile_arn |
|
|
| |
detail_resource_instanceDetails_iamInstanceProfile_id |
|
|
| |
networkInterfaces_networkInterfaceId_str |
| join(networkInterfaces_networkInterfaceId, ',') | networkInterfaces_networkInterfaceId | |
networkInterfaces_subnetId_str |
| join(networkInterfaces_subnetId, ',') | networkInterfaces_subnetId | |
networkInterfaces_vpcId_str |
| join(networkInterfaces_vpcId, ',') | networkInterfaces_vpcId | |
networkInterfaces_privateDnsName_str |
| join(networkInterfaces_privateDnsName, ',') | networkInterfaces_privateDnsName | |
networkInterfaces_publicIp_str |
| join(networkInterfaces_publicIp, ',') | networkInterfaces_publicIp | |
networkInterfaces_ipv6Addresses_str |
| join(networkInterfaces_ipv6Addresses, ',') | networkInterfaces_ipv6Addresses | |
networkInterfaces_publicDnsName_str |
| join(networkInterfaces_publicDnsName, ',') | networkInterfaces_publicDnsName | |
networkInterfaces_privateIpAddress_str |
| join(networkInterfaces_privateIpAddress, ',') | networkInterfaces_privateIpAddress | |
networkInterfaces_securityGroups_str |
| join(networkInterfaces_securityGroups, ',') | networkInterfaces_securityGroups | |
tags_value_str |
| join(tags_value, ',') | tags_value | |
tags_key_str |
| join(tags_key, ',') | tags_key | |
detail_resource_instanceDetails_instanceState |
|
|
| |
detail_resource_instanceDetails_availabilityZone |
|
|
| |
detail_resource_instanceDetails_imageId |
|
|
| |
detail_resource_instanceDetails_imageDescription |
|
|
| |
detail_service_serviceName |
|
|
| |
detail_service_detectorId |
|
|
| |
detail_service_action_actionType |
|
|
| |
detail_service_action_dnsRequestAction_domain |
|
|
| |
detail_service_action_dnsRequestAction_protocol |
|
|
| |
detail_service_action_dnsRequestAction_blocked |
|
|
| |
detail_service_action_networkConnectionAction_connectionDirection |
|
|
| |
detail_service_action_networkConnectionAction_remoteIpDetails_ipAddressV4 |
|
|
| |
detail_service_action_networkConnectionAction_remoteIpDetails_organization_asn |
|
|
| |
detail_service_action_networkConnectionAction_remoteIpDetails_organization_asnOrg |
|
|
| |
detail_service_action_networkConnectionAction_remoteIpDetails_organization_isp |
|
|
| |
detail_service_action_networkConnectionAction_remoteIpDetails_organization_org |
|
|
| |
detail_service_action_networkConnectionAction_remoteIpDetails_country_countryName |
|
|
| |
detail_service_action_networkConnectionAction_remoteIpDetails_city_cityName |
|
|
| |
detail_service_action_networkConnectionAction_remoteIpDetails_geoLocation_lat |
|
|
| |
detail_service_action_networkConnectionAction_remoteIpDetails_geoLocation_lon |
|
|
| |
detail_service_action_networkConnectionAction_remotePortDetails_port |
|
|
| |
detail_service_action_networkConnectionAction_remotePortDetails_portName |
|
|
| |
detail_service_action_networkConnectionAction_localPortDetails_port |
|
|
| |
detail_service_action_networkConnectionAction_localPortDetails_portName |
|
|
| |
detail_service_action_networkConnectionAction_protocol |
|
|
| |
detail_service_action_networkConnectionAction_blocked |
|
|
| |
detail_service_resourceRole |
|
|
| |
detail_service_additionalInfo_portsScannedSample |
|
|
| |
detail_service_additionalInfo_portsScannedSample_str |
| replace(replace(stringify(json(detail_service_additionalInfo_portsScannedSample)), "[", ""), "]", "") | detail_service_additionalInfo_portsScannedSample | |
detail_service_additionalInfo_threatListName |
|
|
| |
detail_service_additionalInfo_sample |
|
|
| |
threatIntelligenceDetails_threatNames_str |
| join(threatIntelligenceDetails_threatNames, ',') | threatIntelligenceDetails_threatNames | |
threatIntelligenceDetails_threatListName_str |
| join(threatIntelligenceDetails_threatListName, ',') | threatIntelligenceDetails_threatListName | |
detail_service_eventFirstSeen |
|
|
| |
detail_service_eventLastSeen |
|
|
| |
detail_service_archived |
|
|
| |
detail_service_count |
|
|
| |
detail_findings_schemaVersion |
|
|
| |
detail_findings_id |
|
|
| |
detail_findings_productArn |
|
|
| |
detail_findings_generatorId |
|
|
| |
detail_findings_awsAccountId |
|
|
| |
detail_findings_types_str |
| join(detail_findings_types, ',') | detail_findings_types | |
detail_findings_firstObservedAt |
|
|
| |
detail_findings_lastObservedAt |
|
|
| |
detail_findings_createdAt |
|
|
| |
detail_findings_updatedAt |
|
|
| |
detail_findings_severity_product |
|
|
| |
detail_findings_severity_normalized |
|
|
| |
detail_findings_description |
|
|
| |
detail_findings_remediation_recommendation_text |
|
|
| |
detail_findings_productFields_standardsGuideArn |
|
|
| |
detail_findings_productFields_standardsGuideSubscriptionArn |
|
|
| |
detail_findings_productFields_ruleId |
|
|
| |
detail_findings_productFields_recommendationUrl |
|
|
| |
detail_findings_productFields_relatedAWSResources_0_name |
|
|
| |
detail_findings_productFields_relatedAWSResources_0_type |
|
|
| |
detail_findings_productFields_recordState |
|
|
| |
detail_findings_productFields_aws_securityhub_findingId |
|
|
| |
detail_findings_productFields_aws_securityhub_severityLabel |
|
|
| |
detail_findings_productFields_aws_securityhub_productName |
|
|
| |
detail_findings_productFields_aws_securityhub_companyName |
|
|
| |
detail_findings_resources_type |
|
|
| |
detail_findings_resources_id |
|
|
| |
detail_findings_resources_partition |
|
|
| |
detail_findings_resources_region |
|
|
| |
detail_findings_resources_details_other_path |
|
|
| |
detail_findings_resources_details_other_userName |
|
|
| |
detail_findings_resources_details_other_userId |
|
|
| |
detail_findings_resources_details_other_arn |
|
|
| |
detail_findings_resources_details_other_createDate |
|
|
| |
detail_findings_recordState |
|
|
| |
detail_findings_workflowState |
|
|
| |
detail_findings_approximateArrivalTimestamp |
| timestamp(int8(detail_findings_approximateArrivalTimestamp_float * 1000)) | detail_findings_approximateArrivalTimestamp_float | |
hostchain |
|
|
| ✓ |
tag |
|
|
| ✓ |
rawMessage |
|
|
| ✓ |
cloud.aws.guardduty.findings
Field |
| Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
|
|
| |
ACCID_TAG |
|
| ACCID | |
REGION_TAG |
|
| REGION | |
schemaVersion |
|
|
| |
accountId |
|
|
| |
region |
|
|
| |
partition |
|
|
| |
id |
|
|
| |
arn |
|
|
| |
type |
|
|
| |
resource_resourceType |
|
|
| |
resource_accessKeyDetails_accessKeyId |
|
|
| |
resource_accessKeyDetails_principalId |
|
|
| |
resource_accessKeyDetails_userType |
|
|
| |
resource_accessKeyDetails_userName |
|
|
| |
resource_instanceDetails_instanceId |
|
|
| |
resource_instanceDetails_instanceType |
|
|
| |
resource_instanceDetails_launchTime |
|
|
| |
resource_instanceDetails_platform |
|
|
| |
resource_instanceDetails_productCodes |
|
|
| |
resource_instanceDetails_iamInstanceProfile_arn |
|
|
| |
resource_instanceDetails_iamInstanceProfile_id |
|
|
| |
resource_instanceDetails_networkInterfaces_networkInterfaceId_str |
| join(resource_instanceDetails_networkInterfaces_networkInterfaceId, ',') | resource_instanceDetails_networkInterfaces_networkInterfaceId | |
resource_instanceDetails_networkInterfaces_privateIpAddresses_str |
| join(resource_instanceDetails_networkInterfaces_privateIpAddresses, ',') | resource_instanceDetails_networkInterfaces_privateIpAddresses | |
resource_instanceDetails_networkInterfaces_subnetId_str |
| join(resource_instanceDetails_networkInterfaces_subnetId, ',') | resource_instanceDetails_networkInterfaces_subnetId | |
resource_instanceDetails_networkInterfaces_vpcId_str |
| join(resource_instanceDetails_networkInterfaces_vpcId, ',') | resource_instanceDetails_networkInterfaces_vpcId | |
resource_instanceDetails_networkInterfaces_privateDnsName_str |
| join(resource_instanceDetails_networkInterfaces_privateDnsName, ',') | resource_instanceDetails_networkInterfaces_privateDnsName | |
resource_instanceDetails_networkInterfaces_securityGroups_str |
| join(resource_instanceDetails_networkInterfaces_securityGroups, ',') | resource_instanceDetails_networkInterfaces_securityGroups | |
resource_instanceDetails_networkInterfaces_publicIp_str |
| join(resource_instanceDetails_networkInterfaces_publicIp, ',') | resource_instanceDetails_networkInterfaces_publicIp | |
resource_instanceDetails_networkInterfaces_ipv6Addresses_str |
| join(resource_instanceDetails_networkInterfaces_ipv6Addresses, ',') | resource_instanceDetails_networkInterfaces_ipv6Addresses | |
resource_instanceDetails_networkInterfaces_publicDnsName_str |
| join(resource_instanceDetails_networkInterfaces_publicDnsName, ',') | resource_instanceDetails_networkInterfaces_publicDnsName | |
resource_instanceDetails_networkInterfaces_privateIpAddress_str |
| join(resource_instanceDetails_networkInterfaces_privateIpAddress, ',') | resource_instanceDetails_networkInterfaces_privateIpAddress | |
resource_instanceDetails_tags_value_str |
| join(resource_instanceDetails_tags_value, ',') | resource_instanceDetails_tags_value | |
resource_instanceDetails_tags_key_str |
| join(resource_instanceDetails_tags_key, ',') | resource_instanceDetails_tags_key | |
resource_instanceDetails_instanceState |
|
|
| |
resource_instanceDetails_availabilityZone |
|
|
| |
resource_instanceDetails_imageId |
|
|
| |
resource_instanceDetails_imageDescription |
|
|
| |
resource_s3BucketDetails_str |
| join(resource_s3BucketDetails, ',') | resource_s3BucketDetails | |
resource_instanceDetails_outpostArn |
|
|
| |
service_serviceName |
|
|
| |
service_detectorId |
|
|
| |
service_action_actionType |
|
|
| |
service_action_awsApiCallAction_api |
|
|
| |
service_action_awsApiCallAction_serviceName |
|
|
| |
service_action_awsApiCallAction_callerType |
|
|
| |
service_action_awsApiCallAction_remoteIpDetails_ipAddressV4 |
|
|
| |
service_action_awsApiCallAction_remoteIpDetails_organization_asn |
|
|
| |
service_action_awsApiCallAction_remoteIpDetails_organization_asnOrg |
|
|
| |
service_action_awsApiCallAction_remoteIpDetails_organization_isp |
|
|
| |
service_action_awsApiCallAction_remoteIpDetails_organization_org |
|
|
| |
service_action_awsApiCallAction_remoteIpDetails_country_countryName |
|
|
| |
service_action_awsApiCallAction_remoteIpDetails_city_cityName |
|
|
| |
service_action_awsApiCallAction_remoteIpDetails_geoLocation_lat |
|
|
| |
service_action_awsApiCallAction_remoteIpDetails_geoLocation_lon |
|
|
| |
service_action_awsApiCallAction_affectedResources |
|
|
| |
service_action_dnsRequestAction_domain |
|
|
| |
service_action_dnsRequestAction_protocol |
|
|
| |
service_action_dnsRequestAction_blocked |
|
|
| |
service_action_networkConnectionAction_blocked |
|
|
| |
service_action_networkConnectionAction_connectionDirection |
|
|
| |
service_action_networkConnectionAction_localPortDetails_port |
|
|
| |
service_action_networkConnectionAction_localPortDetails_portName |
|
|
| |
service_action_networkConnectionAction_protocol |
|
|
| |
service_action_networkConnectionAction_localIpDetails_ipAddressV4 |
|
|
| |
service_action_networkConnectionAction_remoteIpDetails_city_cityName |
|
|
| |
service_action_networkConnectionAction_remoteIpDetails_country_countryCode |
|
|
| |
service_action_networkConnectionAction_remoteIpDetails_country_countryName |
|
|
| |
service_action_networkConnectionAction_remoteIpDetails_geoLocation_lat |
|
|
| |
service_action_networkConnectionAction_remoteIpDetails_geoLocation_lon |
|
|
| |
service_action_networkConnectionAction_remoteIpDetails_ipAddressV4 |
|
|
| |
service_action_networkConnectionAction_remoteIpDetails_organization_asn |
|
|
| |
service_action_networkConnectionAction_remoteIpDetails_organization_asnOrg |
|
|
| |
service_action_networkConnectionAction_remoteIpDetails_organization_isp |
|
|
| |
service_action_networkConnectionAction_remoteIpDetails_organization_org |
|
|
| |
service_action_networkConnectionAction_remotePortDetails_port |
|
|
| |
service_action_networkConnectionAction_remotePortDetails_portName |
|
|
| |
service_action_portProbeAction_portProbeDetails_localPortDetails_str |
| join(service_action_portProbeAction_portProbeDetails_localPortDetails, ',') | service_action_portProbeAction_portProbeDetails_localPortDetails | |
service_action_portProbeAction_portProbeDetails_remoteIpDetails_str |
| join(service_action_portProbeAction_portProbeDetails_remoteIpDetails, ',') | service_action_portProbeAction_portProbeDetails_remoteIpDetails | |
service_action_portProbeAction_blocked |
|
|
| |
service_resourceRole |
|
|
| |
service_additionalInfo_recentApiCalls_api_str |
| join(service_additionalInfo_recentApiCalls_api, ',') | service_additionalInfo_recentApiCalls_api | |
service_additionalInfo_recentApiCalls_count_str |
| replace(replace(stringify(json(service_additionalInfo_recentApiCalls_count)), "[", ""), "]", "") | service_additionalInfo_recentApiCalls_count | |
service_additionalInfo_threatName |
|
|
| |
service_additionalInfo_threatListName |
|
|
| |
service_evidence_threatIntelligenceDetails_threatNames_str |
| join(service_evidence_threatIntelligenceDetails_threatNames, ',') | service_evidence_threatIntelligenceDetails_threatNames | |
service_evidence_threatIntelligenceDetails_threatListName_str |
| join(service_evidence_threatIntelligenceDetails_threatListName, ',') | service_evidence_threatIntelligenceDetails_threatListName | |
service_eventFirstSeen |
|
|
| |
service_eventLastSeen |
|
|
| |
service_archived |
|
|
| |
service_count |
|
|
| |
service_userFeedback |
|
|
| |
severity |
|
|
| |
confidence |
|
|
| |
createdAt |
|
|
| |
updatedAt |
|
|
| |
title |
|
|
| |
description |
|
|
| |
hostchain |
|
|
| |
tag |
|
|
| |
rawMessage |
|
|
|