Document toolboxDocument toolbox

cloud.aws.vpc

Introduction

The tags beginning with cloud.aws.vpc identify events generated by Amazon VPC.

Valid tags and data tables 

The full tag must have 4 levels. The first two are fixed as cloud.aws.vpc. The fourth level indicates the event subtype.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Amazon VPC

cloud.aws.vpc.flow

cloud.aws.vpc.flow

For more information, read more About Devo tags.

Table structure

These are the fields displayed in this table:

cloud.aws.vpc.flow

Field

Type

Source field name

Extra fields

Field

Type

Source field name

Extra fields

eventdate

timestamp

 

 

ACCID_TAG

str

ACCID

 

REGION_TAG

str

REGION

 

version

int8

 

 

accountId

str

 

 

interface_id

str

 

 

srcaddr

ip4

 

 

dstaddr

ip4

 

 

srcport

int8

 

 

dstport

int8

 

 

protocol

int8

 

 

packets

int8

 

 

bytes

int8

 

 

start_date

timestamp

 

 

end_date

timestamp

 

 

action

str

 

 

log_status

str

 

 

vpc_id

str

 

 

subnet_id

str

 

 

instance_id

str

 

 

tcp_flags

str

 

 

type

str

 

 

pkt_srcaddr

ip4

 

 

pkt_dstaddr

ip4

 

 

region

str

 

 

az_id

str

 

 

sublocation_type

str

 

 

sublocation_id

str

 

 

pkt_src_aws_service

str

 

 

pkt_dst_aws_service

str

 

 

flow_direction

str

 

 

traffic_path

str

 

 

message

str

rawMessage

 

hostchain

str

 

✓

tag

str

 

✓

rawMessage

str

 

v