Parsers and Generated Fields

Tag Fields Created by Parser aws-guardduty
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser aws-guardduty
Vendor FieldCPS FieldDescription
Vendor.accountIdcloud.account.idAWS account identifier
Vendor.resource.instanceDetails.instanceIdcloud.instance.idEC2 instance ID
Vendor.resource.instanceDetails.instanceTypecloud.machine.typeEC2 instance type
Vendor.partitioncloud.providerAWS partition
Vendor.regioncloud.regionAWS region
Vendor.service.serviceNamecloud.service.nameService name
Vendor.service.action.networkConnectionAction.localIpDetails.ipAddressV4destination.addressLocal IP address for outbound network connections
Vendor.service.action.networkConnectionAction.localIpDetails.ipAddressV4;destination.address 
Vendor.service.action.networkConnectionAction.remoteIpDetails.ipAddressV4destination.addressRemote IP address for outbound network connections
destination.addressdestination.ip 
Vendor.service.action.dnsRequestAction.domaindns.question.nameDNS domain being queried
Vendor.service.action.actionTypeevent.actionAction type from GuardDuty finding
Vendor.createdAtevent.createdEvent creation timestamp
Vendor.service.eventLastSeenevent.endLast occurrence of event
Vendor.idevent.idUnique identifier
Vendor.service.action.awsApiCallAction.serviceNameevent.providerAWS service name
Vendor.titleevent.reasonTitle of the GuardDuty finding
Vendor.severityevent.severity Mapped severity (90 for >9, 70 for >7, 50 for >4, 30 for >=1)
Vendor.service.eventFirstSeenevent.startFirst occurrence of event
cloud.instance.idhost.id 
Vendor.resource.instanceDetails.platformhost.os.platformInstance platform
cloud.machine.typehost.type 
Vendor.service.action.networkConnectionAction.connectionDirectionnetwork.directionNetwork connection direction (lowercased)
Vendor.service.action.dnsRequestAction.protocolnetwork.transportDNS protocol used
Vendor.service.action.networkConnectionAction.protocolnetwork.transportNetwork protocol used
Vendor.typerule.nameGuardDuty finding type
Vendor.service.action.awsApiCallAction.remoteIpDetails.ipAddressV4source.addressRemote IP address for AWS API calls
Vendor.service.action.kubernetesApiCallAction.remoteIpDetails.ipAddressV4source.addressRemote IP address for Kubernetes API calls
Vendor.service.action.networkConnectionAction.localIpDetails.ipAddressV4source.addressLocal IP address for inbound network connections
Vendor.service.action.networkConnectionAction.localIpDetails.ipAddressV4;source.address 
Vendor.service.action.networkConnectionAction.remoteIpDetails.ipAddressV4source.addressRemote IP address for inbound network connections
Vendor.service.action.rdsLoginAttemptAction.remoteIpDetails.ipAddressV4source.addressRemote IP address for RDS login attempts
source.addresssource.ip 
Vendor.service.action.networkConnectionAction.localPortDetails.portsource.portLocal port number
Vendor.resource.accessKeyDetails.principalIduser.idPrincipal ID from access key details
Vendor.resource.kubernetesDetails.kubernetesUserDetails.uiduser.idKubernetes user ID
Vendor.resource.accessKeyDetails.userNameuser.nameUsername from access key details
Vendor.resource.kubernetesDetails.kubernetesUserDetails.usernameuser.nameKubernetes username
Vendor.resource.rdsDbUserDetails.useruser.nameRDS database username
Vendor.resource.kubernetesDetails.kubernetesUserDetails.groupsuser.rolesKubernetes user groups