Parsers and Generated Fields

Tag Fields Created by Parser aws-guardduty
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser aws-guardduty
Vendor FieldCPS FieldDescription
`event.category[]`ArrayVendor.service.action.actionType, source.address, destination.address
`event.type[]`ArrayVendor.service.action.*.blocked
`user.roles`ArrayVendor.resource.kubernetesDetails.kubernetesUserDetails.groups
`cloud.account.id`CopiedVendor.accountId
`cloud.instance.id`CopiedVendor.resource.instanceDetails.instanceId
`cloud.machine.type`CopiedVendor.resource.instanceDetails.instanceType
`cloud.provider`CopiedVendor.partition
`cloud.region`CopiedVendor.region
`cloud.service.name`CopiedVendor.service.serviceName
`destination.ip`Copieddestination.address
`dns.question.name`CopiedVendor.service.action.dnsRequestAction.domain
`event.action`CopiedVendor.service.action.actionType
`event.created`CopiedVendor.createdAt
`event.end`CopiedVendor.service.eventLastSeen
`event.id`CopiedVendor.id
`event.provider`CopiedVendor.service.action.awsApiCallAction.serviceName
`event.reason`CopiedVendor.title
`event.start`CopiedVendor.service.eventFirstSeen
`host.id`Copiedcloud.instance.id
`host.os.platform`CopiedVendor.resource.instanceDetails.platform
`host.type`Copiedcloud.machine.type
`rule.name`CopiedVendor.type
`source.ip`Copiedsource.address
`user.id`CopiedVendor.resource.accessKeyDetails.principalId, Vendor.resource.kubernetesDetails.kubernetesUserDetails.uid
`user.name`CopiedVendor.resource.accessKeyDetails.userName, Vendor.resource.kubernetesDetails.kubernetesUserDetails.username, Vendor.resource.rdsDbUserDetails.user
`destination.address`ExtractedVendor.service.action.networkConnectionAction.*.ipAddressV4, Vendor.resource.instanceDetails.networkInterfaces[0].privateIpAddress
`destination.port`ExtractedVendor.service.action.networkConnectionAction.*.port
`rule.category`ExtractedVendor.type
`rule.ruleset`ExtractedVendor.type
`source.address`ExtractedVendor.service.action.*.remoteIpDetails.ipAddressV4, Vendor.service.action.networkConnectionAction.localIpDetails.ipAddressV4
`source.port`ExtractedVendor.service.action.networkConnectionAction.*.port
`network.direction`LowercasedVendor.service.action.networkConnectionAction.connectionDirection
`network.transport`LowercasedVendor.service.action.networkConnectionAction.protocol, Vendor.service.action.dnsRequestAction.protocol
`event.severity`MappedVendor.severity
`@timestamp`ParsedVendor.updatedAt
`ecs.version`StaticNone
`event.kind`StaticVendor.severity
`event.module`StaticNone
Vendor.accountIdcloud.account.id 
Vendor.resource.instanceDetails.instanceIdcloud.instance.id 
Vendor.resource.instanceDetails.instanceTypecloud.machine.type 
Vendor.partitioncloud.provider 
Vendor.regioncloud.region 
Vendor.service.serviceNamecloud.service.name 
Vendor.resource.instanceDetails.networkInterfaces[0].privateIpAddressdestination.address 
Vendor.service.action.networkConnectionAction.localIpDetails.ipAddressV4destination.address 
Vendor.service.action.networkConnectionAction.remoteIpDetails.ipAddressV4destination.address 
destination.addressdestination.ip 
Vendor.service.action.dnsRequestAction.domaindns.question.name 
Vendor.service.action.actionTypeevent.action 
Vendor.createdAtevent.created 
Vendor.service.eventLastSeenevent.end 
Vendor.idevent.id 
Vendor.service.action.awsApiCallAction.serviceNameevent.provider 
Vendor.titleevent.reason 
Vendor.service.eventFirstSeenevent.start 
cloud.instance.idhost.id 
Vendor.resource.instanceDetails.platformhost.os.platform 
cloud.machine.typehost.type 
Vendor.service.action.dnsRequestAction.protocolnetwork.transport 
Vendor.service.action.networkConnectionAction.protocolnetwork.transport 
Vendor.typerule.name 
Vendor.service.action.awsApiCallAction.remoteIpDetails.ipAddressV4source.address 
Vendor.service.action.kubernetesApiCallAction.remoteIpDetails.ipAddressV4source.address 
Vendor.service.action.networkConnectionAction.localIpDetails.ipAddressV4source.address 
Vendor.service.action.networkConnectionAction.remoteIpDetails.ipAddressV4source.address 
Vendor.service.action.portProbeAction.portProbeDetails[0].remoteIpDetails.ipAddressV4source.address 
Vendor.service.action.rdsLoginAttemptAction.remoteIpDetails.ipAddressV4source.address 
source.addresssource.ip 
Vendor.resource.accessKeyDetails.principalIduser.id 
Vendor.resource.kubernetesDetails.kubernetesUserDetails.uiduser.id 
Vendor.resource.accessKeyDetails.userNameuser.name 
Vendor.resource.kubernetesDetails.kubernetesUserDetails.usernameuser.name 
Vendor.resource.rdsDbUserDetails.useruser.name