Parsers and Generated Fields

Tag Fields Created by Parser aws-guardduty
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser aws-guardduty
Source FieldCPS Field
Vendor.accountIdcloud.account.id
Vendor.resource.instanceDetails.instanceIdcloud.instance.id
Vendor.resource.instanceDetails.instanceTypecloud.machine.type
Vendor.partitioncloud.provider
Vendor.regioncloud.region
Vendor.service.serviceNamecloud.service.name
Vendor.service.action.networkConnectionAction.localIpDetails.ipAddressV4destination.address
Vendor.service.action.networkConnectionAction.remoteIpDetails.ipAddressV4destination.address
destination.addressdestination.ip
Vendor.service.action.dnsRequestAction.domaindns.question.name
Vendor.service.action.actionTypeevent.action
Vendor.createdAtevent.created
Vendor.service.eventLastSeenevent.end
Vendor.idevent.id
Vendor.service.action.awsApiCallAction.serviceNameevent.provider
Vendor.severityevent.severity
Vendor.service.eventFirstSeenevent.start
cloud.instance.idhost.id
Vendor.resource.instanceDetails.platformhost.os.platform
cloud.machine.typehost.type
Vendor.service.action.dnsRequestAction.protocolnetwork.transport
Vendor.service.action.networkConnectionAction.protocolnetwork.transport
Vendor.typerule.name
Vendor.service.action.awsApiCallAction.remoteIpDetails.ipAddressV4source.address
Vendor.service.action.kubernetesApiCallAction.remoteIpDetails.ipAddressV4source.address
Vendor.service.action.networkConnectionAction.localIpDetails.ipAddressV4source.address
Vendor.service.action.networkConnectionAction.remoteIpDetails.ipAddressV4source.address
Vendor.service.action.rdsLoginAttemptAction.remoteIpDetails.ipAddressV4source.address
source.addresssource.ip
Vendor.service.action.networkConnectionAction.localPortDetails.portsource.port
Vendor.resource.accessKeyDetails.principalIduser.id
Vendor.resource.kubernetesDetails.kubernetesUserDetails.uiduser.id
Vendor.resource.accessKeyDetails.userNameuser.name
Vendor.resource.kubernetesDetails.kubernetesUserDetails.usernameuser.name
Vendor.resource.rdsDbUserDetails.useruser.name
Tag Fields Created by Parser guardduty-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser guardduty-json
Source FieldCPS Field
Vendor.accountIdcloud.account.id
Vendor.resource.instanceDetails.instanceIdcloud.instance.id
resource.instanceDetails.instanceTypecloud.machine.type
Vendor.partitioncloud.provider
Vendor.regioncloud.region
Vendor.service.serviceNamecloud.service.name
Vendor.service.action.networkConnectionAction.localIpDetails.ipAddressV4;destination.address
Vendor.service.action.networkConnectionAction.remoteIpDetails.ipAddressV4destination.address
destination.addressdestination.ip
Vendor.service.action.dnsRequestAction.domaindns.question.name
Vendor.service.action.actionTypeevent.action
Vendor.createdAtevent.created
Vendor.service.eventLastSeenevent.end
Vendor.idevent.id
Vendor.service.action.awsApiCallAction.serviceNameevent.provider
Vendor.severityevent.severity
Vendor.service.eventFirstSeenevent.start
cloud.instance.idhost.id
Vendor.resource.instanceDetails.platformhost.os.platform
cloud.machine.typehost.type
Vendor.service.action.dnsRequestAction.protocolnetwork.transport
Vendor.service.action.networkConnectionAction.protocolnetwork.transport
Vendor.typerule.name
Vendor.service.action.awsApiCallAction.remoteIpDetails.ipAddressV4source.address
Vendor.service.action.kubernetesApiCallAction.remoteIpDetails.ipAddressV4source.address
Vendor.service.action.networkConnectionAction.localIpDetails.ipAddressV4;source.address
Vendor.service.action.networkConnectionAction.remoteIpDetails.ipAddressV4source.address
Vendor.service.action.rdsLoginAttemptAction.remoteIpDetails.ipAddressV4source.address
source.addresssource.ip
Vendor.service.action.networkConnectionAction.localPortDetails.portsource.port
Vendor.resource.accessKeyDetails.principalIduser.id
Vendor.resource.kubernetesDetails.kubernetesUserDetails.uiduser.id
Vendor.resource.accessKeyDetails.userNameuser.name
Vendor.resource.kubernetesDetails.kubernetesUserDetails.usernameuser.name
Vendor.resource.rdsDbUserDetails.useruser.name
Vendor.resource.kubernetesDetails.kubernetesUserDetails.groupsuser.roles