vpc.aws
Introduction
The tags beginning with vpc.aws
identify events generated by Amazon Web Services.
Valid tags and data tables
The full tag must have 3 levels. The first two are fixed as vpc.aws
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Tags | Data tables |
---|---|
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in this table:
vpc.aws.flow
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
|
|
version |
|
|
|
accountId |
|
|
|
interface_id |
|
|
|
srcaddr |
|
|
|
dstaddr |
|
|
|
srcport |
|
|
|
dstport |
|
|
|
protocol |
|
|
|
packets |
|
|
|
bytes |
|
|
|
start_date |
|
|
|
end_date |
|
|
|
action |
|
|
|
log_status |
|
|
|
vpc_id |
|
|
|
subnet_id |
|
|
|
instance_id |
|
|
|
tcp_flags |
|
|
|
type |
|
|
|
pkt_srcaddr |
|
|
|
pkt_dstaddr |
|
|
|
region |
|
|
|
az_id |
|
|
|
sublocation_type |
|
|
|
sublocation_id |
|
|
|
pkt_src_aws_service |
|
|
|
pkt_dst_aws_service |
|
|
|
flow_direction |
|
|
|
traffic_path |
|
|
|
rawMessage |
| rawSource | ✓ |
hostchain |
|
| ✓ |
tag |
|
| ✓ |