cloud.aws.firewall
Introduction
The tags beginning with cloud.aws.firewall
identify events generated by AWS Network Firewall.
Valid tags and data tablesÂ
The full tag must have 4 levels. The first 3 are fixed as cloud.aws.firewall
. The fourth level indicates the event subtype.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
AWS Network Firewall |
|
|
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in these tables:
cloud.aws.firewall.alert
Field | Type | Extra fields |
---|---|---|
eventdate |
| Â |
hostname |
| Â |
ACCID |
| Â |
REGION |
| Â |
firewall_name |
| Â |
availability_zone |
| Â |
event_timestamp |
| Â |
event__timestamp |
| Â |
event__flow_id |
| Â |
event__event_type |
| Â |
event__src_ip |
| Â |
event__src_port |
| Â |
event__dest_ip |
| Â |
event__dest_port |
| Â |
event__proto |
| Â |
event__tx_id |
| Â |
event__alert__action |
| Â |
event__alert__signature_id |
| Â |
event__alert__rev |
| Â |
event__alert__signature |
| Â |
event__alert__category |
| Â |
event__alert__severity |
| Â |
event__http__hostname |
| Â |
event__http__url |
| Â |
event__http__http_user_agent |
| Â |
event__http__http_method |
| Â |
event__http__protocol |
| Â |
event__http__length |
| Â |
event__app_proto |
| Â |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
cloud.aws.firewall.netflow
Field | Type | Extra fields |
---|---|---|
eventdate |
| Â |
hostname |
| Â |
ACCID |
| Â |
REGION |
| Â |
firewall_name |
| Â |
availability_zone |
| Â |
event_timestamp |
| Â |
event__timestamp |
| Â |
event__flow_id |
| Â |
event__event_type |
| Â |
event__src_ip |
| Â |
event__src_port |
| Â |
event__dest_ip |
| Â |
event__dest_port |
| Â |
event__proto |
| Â |
event__netflow__pkts |
| Â |
event__netflow__bytes |
| Â |
event__netflow__start |
| Â |
event__netflow__end |
| Â |
event__netflow__age |
| Â |
event__netflow__min_ttl |
| Â |
event__netflow__max_ttl |
| Â |
event__tcp__tcp_flags |
| Â |
event__tcp__syn |
| Â |
event__tcp__ecn |
| Â |
event__tcp__cwr |
| Â |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |