Parsers and Generated Fields

Tag Fields Created by Parser aws-cloudtrail
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser aws-cloudtrail
Vendor FieldCPS FieldDescription
Vendor.digestStartTime@timestampFallback timestamp if eventTime not present
Vendor.eventTime@timestampEvent timestamp in UTC
Vendor.time@timestampAlternative timestamp field
Vendor.digestS3Bucketcloud.Storage.bucket_nameAlternative S3 bucket name source
Vendor.requestParameters.bucketNamecloud.Storage.bucket_nameS3 bucket name
Vendor.awsAccountIdcloud.account.idAlternative account ID source
Vendor.recipientAccountIdcloud.account.idFallback account ID source
Vendor.userIdentity.accountIdcloud.account.idAWS account ID
Vendor.requestParameters.instanceIdcloud.instance.idEC2 instance ID
Vendor.awsRegioncloud.regionAWS region
Vendor.errorCodeerror.codeError code
Vendor.errorMessageerror.messageError details
Vendor.eventNameevent.actionEvent action name
Vendor.eventIDevent.idEvent ID
Vendor.errorCodeevent.outcomeMaps to "failure" if present
Vendor.responseElements.ConsoleLoginevent.outcomeConsole login outcome (success/failure)
Vendor.eventSourceevent.providerEvent source service
Vendor.errorMessageevent.reasonError reason
Vendor.previousDigestHashValuefile.hash.sha256When hash algorithm is SHA-256
Vendor.digestS3Objectfile.pathS3 object path
Vendor.requestParameters.Hosthost.nameHost name (lowercase)
Vendor.sourceIPAddresssource.addressSource address (lowercase)
Vendor.tlsDetails.cipherSuitetls.cipherTLS cipher suite
Vendor.tlsDetails.tlsVersiontls.version_protocol,Split into protocol and version
Vendor.userIdentity.onBehalfOf.userIduser.idUser ID for IdentityCenterUser type
Vendor.userIdentity.principalIduser.idUser ID
Vendor.additionalEventData.UserNameuser.nameFallback user name
Vendor.requestParameters.roleSessionNameuser.nameUser name for AWSAccount type
Vendor.userIdentity.invokedByuser.nameUser name for AWSService type
Vendor.userIdentity.sessionContext.sessionIssuer.userNameuser.nameUser name for AssumedRole type
Vendor.userIdentity.userNameuser.nameUser name for IAMUser type
Vendor.requestParameters.roleArnuser.roles[]Role ARN for SAMLUser, Role types
Vendor.userIdentity.onBehalfOf.identityStoreArnuser.roles[]Role ARN for IdentityCenterUser type
Vendor.userIdentity.sessionContext.sessionIssuer.arnuser.roles[]Role ARN for AssumedRole type
Vendor.userAgentuser_agent.originalUser agent string