cloud.aws.guardduty
Introduction
The tags beginning with cloud.aws.guardduty
identify events generated by AWS GuardDuty.
Valid tags and data tables
The full tag must have 4 levels. The first 3 are fixed as cloud.aws.guardduty
. The fourth level indicates the event subtype.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
AWS GuardDuty |
|
|
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in these tables:
cloud.aws.guardduty.events
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
|
|
|
|
timestamp |
|
| time |
|
ACCID_TAG |
|
| ACCID |
|
REGION_TAG |
|
| REGION |
|
detail_type |
|
|
|
|
detail_title |
|
|
|
|
detail_findings_title |
|
|
|
|
detail_findings_compliance_status |
|
|
|
|
detail_findings_remediation_recommendation_url |
|
|
|
|
version |
|
|
|
|
id |
|
|
|
|
source |
|
|
|
|
account |
|
|
|
|
region |
|
|
|
|
resources_str |
| join(resources, ',') | resources |
|
detail_schemaVersion |
|
|
|
|
detail_accountId |
|
|
|
|
detail_region |
|
|
|
|
detail_partition |
|
|
|
|
detail_id |
|
|
|
|
detail_arn |
|
|
|
|
detail_severity |
|
|
|
|
detail_createdAt |
|
|
|
|
detail_updatedAt |
|
|
|
|
detail_description |
|
|
|
|
detail_detail_type |
|
|
|
|
detail_resource_resourceType |
|
|
|
|
detail_resource_instanceDetails_instanceId |
|
|
|
|
detail_resource_instanceDetails_instanceType |
|
|
|
|
detail_resource_instanceDetails_launchTime |
|
|
|
|
detail_resource_instanceDetails_platform |
|
|
|
|
productCodes_productCodeId_str |
| join(productCodes_productCodeId, ',') | productCodes_productCodeId |
|
productCodes_productCodeType_str |
| join(productCodes_productCodeType, ',') | productCodes_productCodeType |
|
detail_resource_instanceDetails_iamInstanceProfile_arn |
|
|
|
|
detail_resource_instanceDetails_iamInstanceProfile_id |
|
|
|
|
networkInterfaces_networkInterfaceId_str |
| join(networkInterfaces_networkInterfaceId, ',') | networkInterfaces_networkInterfaceId |
|
networkInterfaces_subnetId_str |
| join(networkInterfaces_subnetId, ',') | networkInterfaces_subnetId |
|
networkInterfaces_vpcId_str |
| join(networkInterfaces_vpcId, ',') | networkInterfaces_vpcId |
|
networkInterfaces_privateDnsName_str |
| join(networkInterfaces_privateDnsName, ',') | networkInterfaces_privateDnsName |
|
networkInterfaces_publicIp_str |
| join(networkInterfaces_publicIp, ',') | networkInterfaces_publicIp |
|
networkInterfaces_ipv6Addresses_str |
| join(networkInterfaces_ipv6Addresses, ',') | networkInterfaces_ipv6Addresses |
|
networkInterfaces_publicDnsName_str |
| join(networkInterfaces_publicDnsName, ',') | networkInterfaces_publicDnsName |
|
networkInterfaces_privateIpAddress_str |
| join(networkInterfaces_privateIpAddress, ',') | networkInterfaces_privateIpAddress |
|
networkInterfaces_securityGroups_str |
| join(networkInterfaces_securityGroups, ',') | networkInterfaces_securityGroups |
|
tags_value_str |
| join(tags_value, ',') | tags_value |
|
tags_key_str |
| join(tags_key, ',') | tags_key |
|
detail_resource_instanceDetails_instanceState |
|
|
|
|
detail_resource_instanceDetails_availabilityZone |
|
|
|
|
detail_resource_instanceDetails_imageId |
|
|
|
|
detail_resource_instanceDetails_imageDescription |
|
|
|
|
detail_service_serviceName |
|
|
|
|
detail_service_detectorId |
|
|
|
|
detail_service_action_actionType |
|
|
|
|
detail_service_action_dnsRequestAction_domain |
|
|
|
|
detail_service_action_dnsRequestAction_protocol |
|
|
|
|
detail_service_action_dnsRequestAction_blocked |
|
|
|
|
detail_service_action_networkConnectionAction_connectionDirection |
|
|
|
|
detail_service_action_networkConnectionAction_remoteIpDetails_ipAddressV4 |
|
|
|
|
detail_service_action_networkConnectionAction_remoteIpDetails_organization_asn |
|
|
|
|
detail_service_action_networkConnectionAction_remoteIpDetails_organization_asnOrg |
|
|
|
|
detail_service_action_networkConnectionAction_remoteIpDetails_organization_isp |
|
|
|
|
detail_service_action_networkConnectionAction_remoteIpDetails_organization_org |
|
|
|
|
detail_service_action_networkConnectionAction_remoteIpDetails_country_countryName |
|
|
|
|
detail_service_action_networkConnectionAction_remoteIpDetails_city_cityName |
|
|
|
|
detail_service_action_networkConnectionAction_remoteIpDetails_geoLocation_lat |
|
|
|
|
detail_service_action_networkConnectionAction_remoteIpDetails_geoLocation_lon |
|
|
|
|
detail_service_action_networkConnectionAction_remotePortDetails_port |
|
|
|
|
detail_service_action_networkConnectionAction_remotePortDetails_portName |
|
|
|
|
detail_service_action_networkConnectionAction_localPortDetails_port |
|
|
|
|
detail_service_action_networkConnectionAction_localPortDetails_portName |
|
|
|
|
detail_service_action_networkConnectionAction_protocol |
|
|
|
|
detail_service_action_networkConnectionAction_blocked |
|
|
|
|
detail_service_resourceRole |
|
|
|
|
detail_service_additionalInfo_portsScannedSample |
|
|
|
|
detail_service_additionalInfo_portsScannedSample_str |
| replace(replace(stringify(json(detail_service_additionalInfo_portsScannedSample)), "[", ""), "]", "") | detail_service_additionalInfo_portsScannedSample |
|
detail_service_additionalInfo_threatListName |
|
|
|
|
detail_service_additionalInfo_sample |
|
|
|
|
threatIntelligenceDetails_threatNames_str |
| join(threatIntelligenceDetails_threatNames, ',') | threatIntelligenceDetails_threatNames |
|
threatIntelligenceDetails_threatListName_str |
| join(threatIntelligenceDetails_threatListName, ',') | threatIntelligenceDetails_threatListName |
|
detail_service_eventFirstSeen |
|
|
|
|
detail_service_eventLastSeen |
|
|
|
|
detail_service_archived |
|
|
|
|
detail_service_count |
|
|
|
|
detail_findings_schemaVersion |
|
|
|
|
detail_findings_id |
|
|
|
|
detail_findings_productArn |
|
|
|
|
detail_findings_generatorId |
|