Parsers and Generated Fields

Tag Fields Created by Parser aws-cloudtrail
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser aws-cloudtrail
Source FieldCPS Field
Vendor.digestS3Bucket;cloud.Storage.bucket_name
Vendor.requestParameters.bucketName;cloud.Storage.bucket_name
Vendor.awsAccountId;cloud.account.id
Vendor.recipientAccountId;cloud.account.id
Vendor.userIdentity.accountId;cloud.account.id
Vendor.awsRegioncloud.region
Vendor.errorCodeerror.code
Vendor.errorMessageerror.message
Vendor.eventNameevent.action
Vendor.eventIDevent.id
Vendor.eventSourceevent.provider
Vendor.errorMessage;event.reason
Vendor.digestS3Objectfile.path
Vendor.sourceIPAddresssource.ip
source.address;source.ip
Vendor.userIdentity.principalIduser.id
Vendor.requestParameters.roleArn;user.roles[0]
Vendor.userIdentity.sessionContext.sessionIssuer.arn;user.roles[0]
Vendor.userAgentuser_agent.original