Parsers and Generated Fields

Tag Fields Created by Parser aws-guardduty
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser aws-guardduty
Vendor FieldCPS FieldDescription
Vendor.accountIdcloud.account.idAWS account identifier
Vendor.accountIdcloud.account.id  
Vendor.resource.instanceDetails.instanceIdcloud.instance.idEC2 instance ID
Vendor.resource.instanceDetails.instanceIdcloud.instance.id  
Vendor.resource.instanceDetails.platformcloud.instance.nameInstance platform
Vendor.resource.instanceDetails.instanceTypecloud.instance.typeEC2 instance type
Vendor.resource.instanceDetails.instanceTypecloud.machine.type  
Vendor.partitioncloud.partitionAWS partition
Vendor.partitioncloud.provider  
Vendor.regioncloud.regionAWS region
Vendor.regioncloud.region  
Vendor.service.serviceNamecloud.service.name  
Vendor.service.action.networkConnectionAction.localIpDetails.ipAddressV4destination.address  
Vendor.service.action.networkConnectionAction.remoteIpDetails.ipAddressV4destination.address  
Vendor.service.action.networkConnectionAction.remoteIpDetails.ipAddressV4destination.ipRemote IP address
destination.addressdestination.ip 
Vendor.service.action.dnsRequestAction.domaindns.question.name  
Vendor.service.action.actionTypeevent.actionAction type from GuardDuty finding
Vendor.service.action.actionTypeevent.action  
Vendor.createdAtevent.createdEvent creation timestamp
Vendor.createdAtevent.created  
Vendor.service.eventLastSeenevent.endLast occurrence of event
Vendor.service.eventLastSeenevent.end  
Vendor.idevent.idUnique identifier
Vendor.idevent.id  
Vendor.service.action.awsApiCallAction.serviceNameevent.providerAWS service name
Vendor.service.action.awsApiCallAction.serviceNameevent.provider  
Vendor.severityevent.severityMapped severity (90 for >9, 70 for >7, 50 for >4, 30 for >=1)
Vendor.service.eventFirstSeenevent.startFirst occurrence of event
Vendor.service.eventFirstSeenevent.start  
cloud.instance.idhost.id 
Vendor.resource.instanceDetails.platformhost.os.platform  
cloud.machine.typehost.type 
Vendor.service.action.networkConnectionAction.protocolnetwork.protocolNetwork protocol used
Vendor.service.action.dnsRequestAction.protocolnetwork.transport  
Vendor.service.action.networkConnectionAction.protocolnetwork.transport  
Vendor.typerule.name  
Vendor.service.serviceNameservice.nameService name
Vendor.service.action.awsApiCallAction.remoteIpDetails.ipAddressV4source.address  
Vendor.service.action.kubernetesApiCallAction.remoteIpDetails.ipAddressV4source.address  
Vendor.service.action.networkConnectionAction.localIpDetails.ipAddressV4source.address  
Vendor.service.action.networkConnectionAction.remoteIpDetails.ipAddressV4source.address  
Vendor.service.action.rdsLoginAttemptAction.remoteIpDetails.ipAddressV4source.address  
Vendor.service.action.networkConnectionAction.localIpDetails.ipAddressV4source.ipLocal IP address
source.addresssource.ip 
Vendor.service.action.networkConnectionAction.localPortDetails.portsource.portLocal port number
Vendor.service.action.networkConnectionAction.localPortDetails.portsource.port  
Vendor.resource.accessKeyDetails.principalIduser.idPrincipal ID from access key
Vendor.resource.accessKeyDetails.principalIduser.id  
Vendor.resource.kubernetesDetails.kubernetesUserDetails.uiduser.id  
Vendor.resource.accessKeyDetails.userNameuser.nameUsername from access key details
Vendor.resource.accessKeyDetails.userNameuser.name  
Vendor.resource.kubernetesDetails.kubernetesUserDetails.usernameuser.name  
Vendor.resource.rdsDbUserDetails.useruser.name  
Tag Fields Created by Parser guardduty-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser guardduty-json
Vendor FieldCPS FieldDescription
Vendor.accountIdcloud.account.id 
Vendor.resource.instanceDetails.instanceIdcloud.instance.id 
resource.instanceDetails.instanceTypecloud.machine.type 
Vendor.partitioncloud.provider 
Vendor.regioncloud.region 
Vendor.service.serviceNamecloud.service.name 
Vendor.service.action.networkConnectionAction.localIpDetails.ipAddressV4;destination.address 
Vendor.service.action.networkConnectionAction.remoteIpDetails.ipAddressV4destination.address 
destination.addressdestination.ip 
Vendor.service.action.dnsRequestAction.domaindns.question.name 
Vendor.service.action.actionTypeevent.action 
Vendor.createdAtevent.created 
Vendor.service.eventLastSeenevent.end 
Vendor.idevent.id 
Vendor.service.action.awsApiCallAction.serviceNameevent.provider 
Vendor.severityevent.severity 
Vendor.service.eventFirstSeenevent.start 
cloud.instance.idhost.id 
Vendor.resource.instanceDetails.platformhost.os.platform 
cloud.machine.typehost.type 
Vendor.service.action.dnsRequestAction.protocolnetwork.transport 
Vendor.service.action.networkConnectionAction.protocolnetwork.transport 
Vendor.typerule.name 
Vendor.service.action.awsApiCallAction.remoteIpDetails.ipAddressV4source.address 
Vendor.service.action.kubernetesApiCallAction.remoteIpDetails.ipAddressV4source.address 
Vendor.service.action.networkConnectionAction.localIpDetails.ipAddressV4;source.address 
Vendor.service.action.networkConnectionAction.remoteIpDetails.ipAddressV4source.address 
Vendor.service.action.rdsLoginAttemptAction.remoteIpDetails.ipAddressV4source.address 
source.addresssource.ip 
Vendor.service.action.networkConnectionAction.localPortDetails.portsource.port 
Vendor.resource.accessKeyDetails.principalIduser.id 
Vendor.resource.kubernetesDetails.kubernetesUserDetails.uiduser.id 
Vendor.resource.accessKeyDetails.userNameuser.name 
Vendor.resource.kubernetesDetails.kubernetesUserDetails.usernameuser.name 
Vendor.resource.rdsDbUserDetails.useruser.name 
Vendor.resource.kubernetesDetails.kubernetesUserDetails.groupsuser.roles