Document toolboxDocument toolbox

cloud.aws.guardduty

Introduction

The tags beginning with cloud.aws.guardduty identify events generated by AWS.

Valid tags and data tables

The full tag must have 4 levels. The first two are fixed as cloud.aws. The third level identifies the type of events sent, and the fourth level indicates the event subtype.

Technology

Brand

Type

Subtype

Technology

Brand

Type

Subtype

cloud

aws

guardduty

  • events

  • findings

These are the valid tags and corresponding data tables that will receive the parsers' data:

Tag

Data table

Tag

Data table

cloud.aws.guardduty.events

cloud.aws.guardduty.events

cloud.aws.guardduty.findings

cloud.aws.guardduty.findings

Â