Field Name
|
Type
|
General Field
|
Description
|
Example
|
Products
|
additionalEventData
|
-
|
-
|
The additional data about the event that was not part of the request or response |
|
|
apiVersion
|
-
|
-
|
The API version associated with the AwsApiCall eventType value
|
|
|
awsRegion
|
-
|
-
|
The AWS region that the request was made to
|
|
|
errorCode
|
-
|
-
|
The AWS service error code
|
|
|
errorMessage
|
-
|
-
|
The error description
|
|
|
eventCase
|
-
|
-
|
The AWS service that the request was made to
|
|
|
eventCategory
|
-
|
-
|
The event category used in LookupEvents calls
|
|
|
eventID
|
-
|
-
|
The GUID generated by AWS CloudTrail to identify events
|
|
|
eventName
|
-
|
-
|
The name of the requested action (one of the actions in the API for the service)
|
|
|
eventSource
|
-
|
-
|
The AWS service the request was made to
|
|
|
eventSubId
|
-
|
-
|
The access type
|
|
|
eventTime
|
-
|
-
|
The time the agent detected the event
|
|
|
eventType
|
-
|
-
|
The type of event that generated the event record
|
|
|
eventVersion
|
-
|
-
|
The version of the log event format
|
|
|
filterRiskLevel
|
-
|
-
|
The top-level risk level of the event
|
|
|
logReceivedTime
|
-
|
-
|
The time when the XDR log was received
|
|
|
policyTreePath
|
-
|
-
|
The policy tree path (endpoint only)
|
|
|
productCode
|
-
|
-
|
The internal product code
|
|
|
readOnly
|
-
|
-
|
Whether the operation is read-only
|
|
|
recipientAccountId
|
-
|
-
|
The Account ID that received the event
|
|
|
requestID
|
-
|
-
|
The value that identifies the request (the service being called generates this value)
|
|
|
requestParameters
|
-
|
-
|
The parameters that were sent with the request (documented in the API reference docs
for each AWS
service)
|
|
|
resources
|
-
|
-
|
The list of resources accessed in the event
|
|
|
responseElements
|
-
|
-
|
The response elements for actions that made changes (create, update, or delete actions)
|
|
|
serviceEventDetails
|
-
|
-
|
The service event (including what triggered the event and the result)
|
|
|
sharedEventID
|
-
|
-
|
The GUID generated by AWS CloudTrail to uniquely identify CloudTrail events (from
the same AWS
action that is sent to different AWS accounts)
|
|
|
sourceIPAddress
|
-
|
|
The IP address the request was made from (For actions that originate from the service
console,
the address reported is for the underlying customer resource, not
the console web server. For services in AWS, only the DNS name is
displayed.)
|
|
|
tags
|
-
|
-
|
The detected technique ID based on the alert filter
|
|
|
userAgent
|
-
|
|
The agent through which the request was made (such as the AWS Management Console,
an AWS service,
the AWS SDKs, or the AWS CLI)
|
|
|
userIdentity
|
-
|
-
|
The information about the user that made a request
|
|
|
uuid
|
-
|
-
|
The unique key of the log entry
|
|
|
vpcEndpointId
|
-
|
-
|
The VPC endpoint in which requests were made from a VPC to another AWS service (such
as Amazon
S3)
|
|
|
Views: