Mappings: AWSGuardDuty - AwsServiceEvent-AWS API Call via CloudTrail
Input | Value |
---|---|
Vendor | AWS |
Product | GuardDuty |
Log Format | JSON |
Event ID Regex Pattern | AWS API Call via CloudTrail |
Output | Value |
---|---|
Vendor | Amazon AWS |
Product | GuardDuty |
Record Type | Audit |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
accountId | accountId | |
action | detail.eventType | |
cloud_provider | None | The static text AWS is populated in this schema field. |
cloud_region | detail.region | |
cloud_service | None | The static text GuardDuty is populated in this schema field. |
description | detail-type | |
device_ip | detail.sourceIPAddress | |
timestamp | eventTime | We expect the orginal record value of eventTime is in the format yyyy-MM-dd'T'HH:mm:ssZ |