Skip to content

Latest commit

 

History

History
34 lines (27 loc) · 917 Bytes

E1B8B90C-1A2A-4502-AB0D-E65B122DE9EE.md

File metadata and controls

34 lines (27 loc) · 917 Bytes

Mappings: AWSGuardDuty_Persistence (Sumo Logic)

Input Requirements

Input Value
Vendor AWS
Product GuardDuty-Sumo-Logic
Log Format JSON
Event ID Regex Pattern Persistence.*

Record Output

Output Value
Vendor Amazon AWS
Product GuardDuty
Record Type Endpoint

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
accountId accountId
description title
device_ip service.action.awsApiCallAction.remoteIpDetails.ipAddressV4
normalizedSeverity severity
severity severity
threat_name type
threat_ruleType None The static text direct is populated in this schema field.
threat_signalName description
timestamp time We expect the orginal record value of time is in the format yyyy-MM-dd'T'HH:mm:ss'Z'
user_username resource.accessKeyDetails.userName