Document toolboxDocument toolbox

cef0.amazon

Introduction

The tables cef0.amazon.* identify events in CEF format generated by Amazon Web Service (AWS) services.

Tag structure

Events in CEF format don't have a specific tag structure, as explained in Technologies supported in CEF syslog format. They are always sent to a table with the structure cef0.deviceVendor.deviceProduct.

In this case, the valid data tables are:

TagData table
cef0.amazon.acmcef0.amazon.acm
cef0.amazon.autoscalingcef0.amazon.autoscaling
cef0.amazon.applicationInsightscef0.amazon.applicationInsights
cef0.amazon.appstreamcef0.amazon.appstream
cef0.amazon.awscef0.amazon.aws
cef0.amazon.backupcef0.amazon.backup
cef0.amazon.cecef0.amazon.ce
cef0.amazon.clouddirectorycef0.amazon.clouddirectory
cef0.amazon.cloudhsmcef0.amazon.cloudhsm
cef0.amazon.cloudtrailcef0.amazon.cloudtrail
cef0.amazon.codecommitcef0.amazon.codecommit
cef0.amazon.codepipelinecef0.amazon.codepipeline
cef0.amazon.cognitoIdpcef0.amazon.cognitoIdp
cef0.amazon.computeOptimizercef0.amazon.computeOptimizer
cef0.amazon.configcef0.amazon.config
cef0.amazon.datapipelinecef0.amazon.datapipeline
cef0.amazon.directconnectcef0.amazon.directconnect
cef0.amazon.dscef0.amazon.ds
cef0.amazon.dynamodbcef0.amazon.dynamodb
cef0.amazon.ec2cef0.amazon.ec2
cef0.amazon.ecrcef0.amazon.ecr
cef0.amazon.ecscef0.amazon.ecs
cef0.amazon.elasticachecef0.amazon.elasticache
cef0.amazon.elasticbeanstalkcef0.amazon.elasticbeanstalk
cef0.amazon.elasticfilesystemcef0.amazon.elasticfilesystem
cef0.amazon.elasticloadbalancingcef0.amazon.elasticloadbalancing
cef0.amazon.elasticmapreducecef0.amazon.elasticmapreduce
cef0.amazon.ekscef0.amazon.eks
cef0.amazon.escef0.amazon.es
cef0.amazon.forecastcef0.amazon.forecast
cef0.amazon.forecastcef0.amazon.forecast
cef0.amazon.gameliftcef0.amazon.gamelift
cef0.amazon.glaciercef0.amazon.glacier
cef0.amazon.guarddutycef0.amazon.guardduty
cef0.amazon.healthcef0.amazon.health
cef0.amazon.iamcef0.amazon.iam
cef0.amazon.iotcef0.amazon.iot
cef0.amazon.kinesiscef0.amazon.kinesis
cef0.amazon.kinesisanalyticscef0.amazon.kinesisanalytics
cef0.amazon.kmscef0.amazon.kms
cef0.amazon.lambdacef0.amazon.lambda
cef0.amazon.logscef0.amazon.logs
cef0.amazon.migrationhubcef0.amazon.migrationhub
cef0.amazon.monitoringcef0.amazon.monitoring
cef0.amazon.organizationscef0.amazon.organizations
cef0.amazon.pricelistcef0.amazon.pricelist
cef0.amazon.quicksightcef0.amazon.quicksight
cef0.amazon.ramcef0.amazon.ram
cef0.amazon.rdscef0.amazon.rds
cef0.amazon.redshiftcef0.amazon.redshift
cef0.amazon.resourceGroupscef0.amazon.resourceGroups
cef0.amazon.route53cef0.amazon.route53
cef0.amazon.s3cef0.amazon.s3
cef0.amazon.sagemakercef0.amazon.sagemaker
cef0.amazon.sbdcef0.amazon.sbd
cef0.amazon.secretsmanagercef0.amazon.secretsmanager
cef0.amazon.securityhubcef0.amazon.securityhub
cef0.amazon.servicediscoverycef0.amazon.servicediscovery
cef0.amazon.sescef0.amazon.ses
cef0.amazon.snscef0.amazon.sns
cef0.amazon.ssmcef0.amazon.ssm
cef0.amazon.storagegatewaycef0.amazon.storagegateway
cef0.amazon.stscef0.amazon.sts
cef0.amazon.swfcef0.amazon.swf
cef0.amazon.taggingcef0.amazon.tagging
cef0.amazon.trustedAdvisorcef0.amazon.trustedAdvisor
cef0.amazon.workdocscef0.amazon.workdocs
cef0.amazon.workspacescef0.amazon.workspaces
cef0.amazon.servicequotascef0.amazon.servicequotas
cef0.amazon.dmscef0.amazon.dms
cef0.amazon.billingconsolecef0.amazon.billingconsole
cef0.amazon.route53resolvercef0.amazon.route53resolver
cef0.amazon.firehosecef0.amazon.firehose
cef0.amazon.licenseManagercef0.amazon.licenseManager
cef0.amazon.accessAnalyzercef0.amazon.accessAnalyzer
cef0.amazon.daxcef0.amazon.dax
cef0.amazon.dataexchangecef0.amazon.dataexchange
cef0.amazon.codedeploycef0.amazon.codedeploy
cef0.amazon.wellarchitectedcef0.amazon.wellarchitected
cef0.amazon.fsxcef0.amazon.fsx
cef0.amazon.smscef0.amazon.sms
cef0.amazon.discoverycef0.amazon.discovery
cef0.amazon.picef0.amazon.pi
cef0.amazon.redshiftDatacef0.amazon.redshiftData
cef0.amazon.ec2InstanceConnectcef0.amazon.ec2InstanceConnect
cef0.amazon.eventscef0.amazon.events
cef0.amazon.mgncef0.amazon.mgn
cef0.amazon.greengrasscef0.amazon.greengrass
cef0.amazon.outpostscef0.amazon.outposts
cef0.amazon.xraycef0.amazon.xray
cef0.amazon.cognitoIdentitycef0.amazon.cognitoIdentity
cef0.amazon.robomakercef0.amazon.robomaker
cef0.amazon.databrewcef0.amazon.databrew
cef0.amazon.macie2cef0.amazon.macie2
cef0.amazon.networkFirewallcef0.amazon.networkFirewall
cef0.amazon.networkmanagercef0.amazon.networkmanager
cef0.amazon.savingsplanscef0.amazon.savingsplans
cef0.amazon.gluecef0.amazon.glue
cef0.amazon.statescef0.amazon.states
cef0.amazon.amazonmqcef0.amazon.amazonmq
cef0.amazon.appconfigcef0.amazon.appconfig
cef0.amazon.comprehendcef0.amazon.comprehend
cef0.amazon.dlmcef0.amazon.dlm
cef0.amazon.globalacceleratorcef0.amazon.globalaccelerator
cef0.amazon.ioteventscef0.amazon.iotevents
cef0.amazon.wafcef0.amazon.waf
cef0.amazon.wafRegionalcef0.amazon.wafRegional
cef0.amazon.wafv2cef0.amazon.wafv2
cef0.amazon.cloud9cef0.amazon.cloud9
cef0.amazon.codebuildcef0.amazon.codebuild
cef0.amazon.codeguruReviewercef0.amazon.codeguruReviewer
cef0.amazon.emrContainerscef0.amazon.emrContainers
cef0.amazon.iotanalyticscef0.amazon.iotanalytics
cef0.amazon.kafkacef0.amazon.kafka
cef0.amazon.opsworkscef0.amazon.opsworks
cef0.amazon.qldbcef0.amazon.qldb
cef0.amazon.sqscef0.amazon.sqs
cef0.amazon.syntheticscef0.amazon.synthetics
cef0.amazon.profilecef0.amazon.profile
cef0.amazon.route53domainscef0.amazon.route53domains
cef0.amazon.serverlessrepocef0.amazon.serverlessrepo
cef0.amazon.shieldcef0.amazon.shield
cef0.amazon.lightsailcef0.amazon.lightsail
cef0.amazon.imagebuildercef0.amazon.imagebuilder
cef0.amazon.groundstationcef0.amazon.groundstation
cef0.amazon.frauddetectorcef0.amazon.frauddetector
cef0.amazon.fmscef0.amazon.fms

How is the data sent to Devo?

Learn more about CEF syslog format and how Devo tags these events in Technologies supported in CEF syslog format.

Log samples

The following are sample logs sent to some of the cef0.amazon tables. Find how the information will be parsed in your data table under each sample log.

Extra columns

Fields marked as Extra in the table below are not shown by default in data tables and need to be explicitly requested in the query. You can find them marked as Extra when you perform a query so they can be easily identified. Learn more about this in Selecting unrevealed columns.