Skip to content

Latest commit

 

History

History
36 lines (29 loc) · 1.02 KB

FDE55C18-7338-41E3-8DB2-3AD5EF6D8831.md

File metadata and controls

36 lines (29 loc) · 1.02 KB

Mappings: Recon_IAMUser (Sumo Logic)

Input Requirements

Input Value
Vendor AWS
Product GuardDuty-Sumo-Logic
Log Format JSON
Event ID Regex Pattern Recon:IAMUser/.*

Record Output

Output Value
Vendor Amazon AWS
Product GuardDuty
Record Type Audit

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
accountId accountId
description title
device_hostname resource.instanceDetails.networkInterfaces.1.privateDnsName
device_ip resource.instanceDetails.networkInterfaces.1.privateIpAddress
device_uniqueId resource.instanceDetails.instanceId
normalizedSeverity severity
severity severity
threat_name description
threat_ruleType None The static text direct is populated in this schema field.
threat_signalName description
timestamp time We expect the orginal record value of time is in the format yyyy-MM-dd'T'HH:mm:ss'Z'
user_username resource.accessKeyDetails.userName