vpc.aws
Introduction
The tags beginning with vpc.aws
identify events generated by Amazon Web Services.
Valid tags and data tables
The full tag must have 3 levels. The first two are fixed as vpc.aws
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Tags | Data tables |
---|---|
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in this table:
vpc.aws.flow
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
| Â | Â |
version |
| Â | Â |
accountId |
| Â | Â |
interface_id |
| Â | Â |
srcaddr |
| Â | Â |
dstaddr |
| Â | Â |
srcport |
| Â | Â |
dstport |
| Â | Â |
protocol |
| Â | Â |
packets |
| Â | Â |
bytes |
| Â | Â |
start_date |
| Â | Â |
end_date |
| Â | Â |
action |
| Â | Â |
log_status |
| Â | Â |
vpc_id |
| Â | Â |
subnet_id |
| Â | Â |
instance_id |
| Â | Â |
tcp_flags |
| Â | Â |
type |
| Â | Â |
pkt_srcaddr |
| Â | Â |
pkt_dstaddr |
| Â | Â |
region |
| Â | Â |
az_id |
| Â | Â |
sublocation_type |
| Â | Â |
sublocation_id |
| Â | Â |
pkt_src_aws_service |
| Â | Â |
pkt_dst_aws_service |
| Â | Â |
flow_direction |
| Â | Â |
traffic_path |
| Â | Â |
rawMessage |
| rawSource | ✓ |
hostchain |
|  | ✓ |
tag |
|  | ✓ |