cloud.aws.guardduty
Introduction
The tags beginning with cloud.aws.guardduty
identify events generated by AWS GuardDuty.
Valid tags and data tables
The full tag must have 4 levels. The first 3 are fixed as cloud.aws.guardduty
. The fourth level indicates the event subtype.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
AWS GuardDuty |
|
|
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in these tables:
cloud.aws.guardduty.events
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
| Â | Â | Â |
timestamp |
| Â | time | Â |
ACCID_TAG |
| Â | ACCID | Â |
REGION_TAG |
| Â | REGION | Â |
detail_type |
| Â | Â | Â |
detail_title |
| Â | Â | Â |
detail_findings_title |
| Â | Â | Â |
detail_findings_compliance_status |
| Â | Â | Â |
detail_findings_remediation_recommendation_url |
| Â | Â | Â |
version |
| Â | Â | Â |
id |
| Â | Â | Â |
source |
| Â | Â | Â |
account |
| Â | Â | Â |
region |
| Â | Â | Â |
resources_str |
| join(resources, ',') | resources | Â |
detail_schemaVersion |
| Â | Â | Â |
detail_accountId |
| Â | Â | Â |
detail_region |
| Â | Â | Â |
detail_partition |
| Â | Â | Â |
detail_id |
| Â | Â | Â |
detail_arn |
| Â | Â | Â |
detail_severity |
| Â | Â | Â |
detail_createdAt |
| Â | Â | Â |
detail_updatedAt |
| Â | Â | Â |
detail_description |
| Â | Â | Â |
detail_detail_type |
| Â | Â | Â |
detail_resource_resourceType |
| Â | Â | Â |
detail_resource_instanceDetails_instanceId |
| Â | Â | Â |
detail_resource_instanceDetails_instanceType |
| Â | Â | Â |
detail_resource_instanceDetails_launchTime |
| Â | Â | Â |
detail_resource_instanceDetails_platform |
| Â | Â | Â |
productCodes_productCodeId_str |
| join(productCodes_productCodeId, ',') | productCodes_productCodeId | Â |
productCodes_productCodeType_str |
| join(productCodes_productCodeType, ',') | productCodes_productCodeType | Â |
detail_resource_instanceDetails_iamInstanceProfile_arn |
| Â | Â | Â |
detail_resource_instanceDetails_iamInstanceProfile_id |
| Â | Â | Â |
networkInterfaces_networkInterfaceId_str |
| networkInterfaces_networkInterfaceId | Â | |
networkInterfaces_subnetId_str |
| networkInterfaces_subnetId | Â | |
networkInterfaces_vpcId_str |
| networkInterfaces_vpcId | Â | |
networkInterfaces_privateDnsName_str |
| networkInterfaces_privateDnsName | Â | |
networkInterfaces_publicIp_str |
| networkInterfaces_publicIp | Â | |
networkInterfaces_ipv6Addresses_str |
| networkInterfaces_ipv6Addresses | Â | |
networkInterfaces_publicDnsName_str |
| networkInterfaces_publicDnsName | Â | |
networkInterfaces_privateIpAddress_str |
| networkInterfaces_privateIpAddress | Â | |
networkInterfaces_securityGroups_str |
| networkInterfaces_securityGroups | Â | |
tags_value_str |
| tags_value | Â | |
tags_key_str |
| tags_key | Â | |
detail_resource_instanceDetails_instanceState |
| Â | Â | Â |
detail_resource_instanceDetails_availabilityZone |
| Â | Â | Â |
detail_resource_instanceDetails_imageId |
| Â | Â | Â |
detail_resource_instanceDetails_imageDescription |
| Â | Â | Â |
detail_service_serviceName |
| Â | Â | Â |
detail_service_detectorId |
| Â | Â | Â |
detail_service_action_actionType |
| Â | Â | Â |
detail_service_action_dnsRequestAction_domain |
| Â | Â | Â |
detail_service_action_dnsRequestAction_protocol |
| Â | Â | Â |
detail_service_action_dnsRequestAction_blocked |
| Â | Â | Â |
detail_service_action_networkConnectionAction_connectionDirection |
| Â | Â | Â |
detail_service_action_networkConnectionAction_remoteIpDetails_ipAddressV4 |
| Â | Â | Â |
detail_service_action_networkConnectionAction_remoteIpDetails_organization_asn |
| Â | Â | Â |
detail_service_action_networkConnectionAction_remoteIpDetails_organization_asnOrg |
| Â | Â | Â |
detail_service_action_networkConnectionAction_remoteIpDetails_organization_isp |
| Â | Â | Â |
detail_service_action_networkConnectionAction_remoteIpDetails_organization_org |
| Â | Â | Â |
detail_service_action_networkConnectionAction_remoteIpDetails_country_countryName |
| Â | Â | Â |
detail_service_action_networkConnectionAction_remoteIpDetails_city_cityName |
| Â | Â | Â |
detail_service_action_networkConnectionAction_remoteIpDetails_geoLocation_lat |
| Â | Â | Â |
detail_service_action_networkConnectionAction_remoteIpDetails_geoLocation_lon |
| Â | Â | Â |
detail_service_action_networkConnectionAction_remotePortDetails_port |
| Â | Â | Â |
detail_service_action_networkConnectionAction_remotePortDetails_portName |
| Â | Â | Â |
detail_service_action_networkConnectionAction_localPortDetails_port |
| Â | Â | Â |
detail_service_action_networkConnectionAction_localPortDetails_portName |
| Â | Â | Â |
detail_service_action_networkConnectionAction_protocol |
| Â | Â | Â |
detail_service_action_networkConnectionAction_blocked |
| Â | Â | Â |
detail_service_resourceRole |
| Â | Â | Â |
detail_service_additionalInfo_portsScannedSample |
| Â | Â | Â |
detail_service_additionalInfo_portsScannedSample_str |
| detail_service_additionalInfo_portsScannedSample | Â | |
detail_service_additionalInfo_threatListName |
| Â | Â | Â |
detail_service_additionalInfo_sample |
| Â | Â | Â |
threatIntelligenceDetails_threatNames_str |
| threatIntelligenceDetails_threatNames | Â | |
threatIntelligenceDetails_threatListName_str |
| threatIntelligenceDetails_threatListName | Â | |
detail_service_eventFirstSeen |
| Â | Â | Â |
detail_service_eventLastSeen |
| Â | Â | Â |
detail_service_archived |
| Â | Â | Â |
detail_service_count |
| Â | Â | Â |
detail_findings_schemaVersion |
| Â | Â | Â |
detail_findings_id |
| Â | Â | Â |
detail_findings_productArn |
| Â | Â | Â |
detail_findings_generatorId |
| Â | Â | Â |
detail_findings_awsAccountId |
| Â | Â | Â |
detail_findings_types_str |
| detail_findings_types | Â | |
detail_findings_firstObservedAt |
| Â | Â | Â |
detail_findings_lastObservedAt |
| Â | Â | Â |
detail_findings_createdAt |
| Â | Â | Â |
detail_findings_updatedAt |
| Â | Â | Â |
detail_findings_severity_product |
| Â | Â | Â |
detail_findings_severity_normalized |
| Â | Â | Â |
detail_findings_description |
| Â | Â | Â |
detail_findings_remediation_recommendation_text |
| Â | Â | Â |
detail_findings_productFields_standardsGuideArn |
| Â | Â | Â |
detail_findings_productFields_standardsGuideSubscriptionArn |
| Â | Â | Â |
detail_findings_productFields_ruleId |
| Â | Â | Â |
detail_findings_productFields_recommendationUrl |
| Â | Â | Â |
detail_findings_productFields_relatedAWSResources_0_name |
| Â | Â | Â |
detail_findings_productFields_relatedAWSResources_0_type |
| Â | Â | Â |
detail_findings_productFields_recordState |
| Â | Â | Â |
detail_findings_productFields_aws_securityhub_findingId |
| Â | Â | Â |
detail_findings_productFields_aws_securityhub_severityLabel |
| Â | Â | Â |
detail_findings_productFields_aws_securityhub_productName |
| Â | Â | Â |
detail_findings_productFields_aws_securityhub_companyName |
| Â | Â | Â |
detail_findings_resources_type |
| Â | Â | Â |
detail_findings_resources_id |
| Â | Â | Â |
detail_findings_resources_partition |
| Â | Â | Â |
detail_findings_resources_region |
| Â | Â | Â |
detail_findings_resources_details_other_path |
| Â | Â | Â |
detail_findings_resources_details_other_userName |
| Â | Â | Â |
detail_findings_resources_details_other_userId |
| Â | Â | Â |
detail_findings_resources_details_other_arn |
| Â | Â | Â |
detail_findings_resources_details_other_createDate |
| Â | Â | Â |
detail_findings_recordState |
| Â | Â | Â |
detail_findings_workflowState |
| Â | Â | Â |
detail_findings_approximateArrivalTimestamp |
| detail_findings_approximateArrivalTimestamp_float | Â | |
hostchain |
|  |  | ✓ |
tag |
|  |  | ✓ |
rawMessage |
|  |  | ✓ |
cloud.aws.guardduty.findings
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
| Â | Â | Â |
ACCID_TAG |
| Â | ACCID | Â |
REGION_TAG |
| Â | REGION | Â |
schemaVersion |
| Â | Â | Â |
accountId |
| Â | Â | Â |
region |
| Â | Â | Â |
partition |
| Â | Â | Â |
id |
| Â | Â | Â |
arn |
| Â | Â | Â |
type |
| Â | Â | Â |
resource_resourceType |
| Â | Â | Â |
resource_accessKeyDetails_accessKeyId |
| Â | Â | Â |
resource_accessKeyDetails_principalId |
| Â | Â | Â |
resource_accessKeyDetails_userType |
| Â | Â | Â |
resource_accessKeyDetails_userName |
| Â | Â | Â |
resource_instanceDetails_instanceId |
| Â | Â | Â |
resource_instanceDetails_instanceType |
| Â | Â | Â |
resource_instanceDetails_launchTime |
| Â | Â | Â |
resource_instanceDetails_platform |
| Â | Â | Â |
resource_instanceDetails_productCodes |
| Â | Â | Â |
resource_instanceDetails_iamInstanceProfile_arn |
| Â | Â | Â |
resource_instanceDetails_iamInstanceProfile_id |
| Â | Â | Â |
resource_instanceDetails_networkInterfaces_networkInterfaceId_str |
| resource_instanceDetails_networkInterfaces_networkInterfaceId | Â | |
resource_instanceDetails_networkInterfaces_privateIpAddresses_str |
| resource_instanceDetails_networkInterfaces_privateIpAddresses | Â | |
resource_instanceDetails_networkInterfaces_subnetId_str |
| resource_instanceDetails_networkInterfaces_subnetId | Â | |
resource_instanceDetails_networkInterfaces_vpcId_str |
| resource_instanceDetails_networkInterfaces_vpcId | Â | |
resource_instanceDetails_networkInterfaces_privateDnsName_str |
| resource_instanceDetails_networkInterfaces_privateDnsName | Â | |
resource_instanceDetails_networkInterfaces_securityGroups_str |
| resource_instanceDetails_networkInterfaces_securityGroups | Â | |
resource_instanceDetails_networkInterfaces_publicIp_str |
| resource_instanceDetails_networkInterfaces_publicIp | Â | |
resource_instanceDetails_networkInterfaces_ipv6Addresses_str |
| resource_instanceDetails_networkInterfaces_ipv6Addresses | Â | |
resource_instanceDetails_networkInterfaces_publicDnsName_str |
| resource_instanceDetails_networkInterfaces_publicDnsName | Â | |
resource_instanceDetails_networkInterfaces_privateIpAddress_str |
| resource_instanceDetails_networkInterfaces_privateIpAddress | Â | |
resource_instanceDetails_tags_value_str |
| resource_instanceDetails_tags_value | Â | |
resource_instanceDetails_tags_key_str |
| resource_instanceDetails_tags_key | Â | |
resource_instanceDetails_instanceState |
| Â | Â | Â |
resource_instanceDetails_availabilityZone |
| Â | Â | Â |
resource_instanceDetails_imageId |
| Â | Â | Â |
resource_instanceDetails_imageDescription |
| Â | Â | Â |
resource_s3BucketDetails_str |
| resource_s3BucketDetails | Â | |
resource_instanceDetails_outpostArn |
| Â | Â | Â |
service_serviceName |
| Â | Â | Â |
service_detectorId |
| Â | Â | Â |
service_action_actionType |
| Â | Â | Â |
service_action_awsApiCallAction_api |
| Â | Â | Â |
service_action_awsApiCallAction_serviceName |
| Â | Â | Â |
service_action_awsApiCallAction_callerType |
| Â | Â | Â |
service_action_awsApiCallAction_remoteIpDetails_ipAddressV4 |
| Â | Â | Â |
service_action_awsApiCallAction_remoteIpDetails_organization_asn |
| Â | Â | Â |
service_action_awsApiCallAction_remoteIpDetails_organization_asnOrg |
| Â | Â | Â |
service_action_awsApiCallAction_remoteIpDetails_organization_isp |
| Â | Â | Â |
service_action_awsApiCallAction_remoteIpDetails_organization_org |
| Â | Â | Â |
service_action_awsApiCallAction_remoteIpDetails_country_countryName |
| Â | Â | Â |
service_action_awsApiCallAction_remoteIpDetails_city_cityName |
| Â | Â | Â |
service_action_awsApiCallAction_remoteIpDetails_geoLocation_lat |
| Â | Â | Â |
service_action_awsApiCallAction_remoteIpDetails_geoLocation_lon |
| Â | Â | Â |
service_action_awsApiCallAction_affectedResources |
| Â | Â | Â |
service_action_dnsRequestAction_domain |
| Â | Â | Â |
service_action_dnsRequestAction_protocol |
| Â | Â | Â |
service_action_dnsRequestAction_blocked |
| Â | Â | Â |
service_action_networkConnectionAction_blocked |
| Â | Â | Â |
service_action_networkConnectionAction_connectionDirection |
| Â | Â | Â |
service_action_networkConnectionAction_localPortDetails_port |
| Â | Â | Â |
service_action_networkConnectionAction_localPortDetails_portName |
| Â | Â | Â |
service_action_networkConnectionAction_protocol |
| Â | Â | Â |
service_action_networkConnectionAction_localIpDetails_ipAddressV4 |
| Â | Â | Â |
service_action_networkConnectionAction_remoteIpDetails_city_cityName |
| Â | Â | Â |
service_action_networkConnectionAction_remoteIpDetails_country_countryCode |
| Â | Â | Â |
service_action_networkConnectionAction_remoteIpDetails_country_countryName |
| Â | Â | Â |
service_action_networkConnectionAction_remoteIpDetails_geoLocation_lat |
| Â | Â | Â |
service_action_networkConnectionAction_remoteIpDetails_geoLocation_lon |
| Â | Â | Â |
service_action_networkConnectionAction_remoteIpDetails_ipAddressV4 |
| Â | Â | Â |
service_action_networkConnectionAction_remoteIpDetails_organization_asn |
| Â | Â | Â |
service_action_networkConnectionAction_remoteIpDetails_organization_asnOrg |
| Â | Â | Â |
service_action_networkConnectionAction_remoteIpDetails_organization_isp |
| Â | Â | Â |
service_action_networkConnectionAction_remoteIpDetails_organization_org |
| Â | Â | Â |
service_action_networkConnectionAction_remotePortDetails_port |
| Â | Â | Â |
service_action_networkConnectionAction_remotePortDetails_portName |
| Â | Â | Â |
service_action_portProbeAction_portProbeDetails_localPortDetails_str |
| service_action_portProbeAction_portProbeDetails_localPortDetails | Â | |
service_action_portProbeAction_portProbeDetails_localPortDetails_port_str |
| service_action_portProbeAction_portProbeDetails_localPortDetails_port | Â | |
service_action_portProbeAction_portProbeDetails_localPortDetails_portName_str |
| service_action_portProbeAction_portProbeDetails_localPortDetails_portName | Â | |
service_action_portProbeAction_portProbeDetails_remoteIpDetails_str |
| service_action_portProbeAction_portProbeDetails_remoteIpDetails | Â | |
service_action_portProbeAction_portProbeDetails_remoteIpDetails_city_str |
| service_action_portProbeAction_portProbeDetails_remoteIpDetails_city | Â | |
service_action_portProbeAction_portProbeDetails_remoteIpDetails_city_cityName_str |
| service_action_portProbeAction_portProbeDetails_remoteIpDetails_city_cityName | Â | |
service_action_portProbeAction_portProbeDetails_remoteIpDetails_country_str |
| service_action_portProbeAction_portProbeDetails_remoteIpDetails_country | Â | |
service_action_portProbeAction_portProbeDetails_remoteIpDetails_country_countryCode_str |
| service_action_portProbeAction_portProbeDetails_remoteIpDetails_country_countryCode | Â | |
service_action_portProbeAction_portProbeDetails_remoteIpDetails_country_countryName_str |
| service_action_portProbeAction_portProbeDetails_remoteIpDetails_country_countryName | Â | |
service_action_portProbeAction_portProbeDetails_remoteIpDetails_geoLocation_str |
| service_action_portProbeAction_portProbeDetails_remoteIpDetails_geoLocation | Â | |
service_action_portProbeAction_portProbeDetails_remoteIpDetails_geoLocation_lat_str |
| service_action_portProbeAction_portProbeDetails_remoteIpDetails_geoLocation_lat | Â | |
service_action_portProbeAction_portProbeDetails_remoteIpDetails_geoLocation_lon_str |
| service_action_portProbeAction_portProbeDetails_remoteIpDetails_geoLocation_lon | Â | |
service_action_portProbeAction_portProbeDetails_remoteIpDetails_ipAddressV4_str |
| service_action_portProbeAction_portProbeDetails_remoteIpDetails_ipAddressV4 | Â | |
service_action_portProbeAction_portProbeDetails_remoteIpDetails_ipAddressV6_str |
| service_action_portProbeAction_portProbeDetails_remoteIpDetails_ipAddressV6 | Â | |
service_action_portProbeAction_portProbeDetails_remoteIpDetails_organization_str |
| service_action_portProbeAction_portProbeDetails_remoteIpDetails_organization | Â | |
service_action_portProbeAction_portProbeDetails_remoteIpDetails_organization_asn_str |
| service_action_portProbeAction_portProbeDetails_remoteIpDetails_organization_asn | Â | |
service_action_portProbeAction_portProbeDetails_remoteIpDetails_organization_asnOrg_str |
| service_action_portProbeAction_portProbeDetails_remoteIpDetails_organization_asnOrg | Â | |
service_action_portProbeAction_portProbeDetails_remoteIpDetails_organization_isp_str |
| service_action_portProbeAction_portProbeDetails_remoteIpDetails_organization_isp | Â | |
service_action_portProbeAction_portProbeDetails_remoteIpDetails_organization_org_str |
| service_action_portProbeAction_portProbeDetails_remoteIpDetails_organization_org | Â | |
service_action_portProbeAction_portProbeDetails_localIpDetails_str |
| service_action_portProbeAction_portProbeDetails_localIpDetails | Â | |
service_action_portProbeAction_portProbeDetails_localIpDetails_ipAddressV4_str |
| service_action_portProbeAction_portProbeDetails_localIpDetails_ipAddressV4 | Â | |
service_action_portProbeAction_portProbeDetails_localIpDetails_ipAddressV6_str |
| service_action_portProbeAction_portProbeDetails_localIpDetails_ipAddressV6 | Â | |
service_action_portProbeAction_blocked |
| Â | Â | Â |
service_resourceRole |
| Â | Â | Â |
service_additionalInfo_recentApiCalls_api_str |
| service_additionalInfo_recentApiCalls_api | Â | |
service_additionalInfo_recentApiCalls_count_str |
| service_additionalInfo_recentApiCalls_count | Â | |
service_additionalInfo_threatName |
| Â | Â | Â |
service_additionalInfo_threatListName |
| Â | Â | Â |
service_evidence_threatIntelligenceDetails_threatNames_str |
| service_evidence_threatIntelligenceDetails_threatNames | Â | |
service_evidence_threatIntelligenceDetails_threatListName_str |
| service_evidence_threatIntelligenceDetails_threatListName | Â | |
service_eventFirstSeen |
| Â | Â | Â |
service_eventLastSeen |
| Â | Â | Â |
service_archived |
| Â | Â | Â |
service_count |
| Â | Â | Â |
service_userFeedback |
| Â | Â | Â |
severity |
| Â | Â | Â |
confidence |
| Â | Â | Â |
createdAt |
| Â | Â | Â |
updatedAt |
| Â | Â | Â |
title |
| Â | Â | Â |
description |
| Â | Â | Â |
hostchain |
|  |  | ✓ |
tag |
|  |  | ✓ |
rawMessage |
|  |  | ✓ |