Skip to content

Latest commit

 

History

History
35 lines (28 loc) · 1014 Bytes

3059a962-1a71-4daa-a7b7-47b2d7e321e0.md

File metadata and controls

35 lines (28 loc) · 1014 Bytes

Mappings: AWS API Gateway

Input Requirements

Input Value
Vendor AWS
Product API Gateway
Log Format JSON
Event ID Regex Pattern _default_

Record Output

Output Value
Vendor Amazon AWS
Product API Gateway
Record Type NetworkHTTP

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
accountId message.accountId
cloud_provider None The static text AWS is populated in this schema field.
cloud_service None The static text API Gateway is populated in this schema field.
http_method message.httpMethod
http_response_contentLength message.responseLength
http_response_statusCode message.status
http_userAgent message.userAgent
srcDevice_ip message_ip
tcpProtocol message.protocol
timestamp message.requestTime We expect the orginal record value of message.requestTime is in the format dd/MMM/yyyy:HH:mm:ss Z
user_authDomain message.domain