Field Name
|
Type
|
General Field
|
Description
|
Example
|
Products
|
additionalEventData
|
|
-
|
The additional data about the event that was not part of the request or response
|
|
|
apiVersion
|
|
-
|
The API version associated with the AwsApiCall eventType value
|
|
|
awsRegion
|
|
-
|
AWS region that the request was made to
|
|
|
errorCode
|
|
-
|
The AWS service error code
|
|
|
errorMessage
|
|
-
|
The error description
|
|
|
eventCase
|
|
-
|
The AWS service that the request was made to
|
|
|
eventCategory
|
|
-
|
The event category used in LookupEvents calls
|
|
|
eventID
|
|
-
|
The GUID generated by AWS CloudTrail to identify events
|
|
|
eventName
|
|
-
|
The name of the log event
|
|
|
eventSource
|
|
-
|
The AWS service the request was made to
|
|
|
eventSubId
|
|
-
|
The access type
|
|
|
eventTime
|
|
-
|
The time the agent or product detected the event
|
|
|
eventType
|
|
-
|
The type of event that generated the event record
|
|
|
eventVersion
|
|
-
|
The log event format version
|
|
|
filterRiskLevel
|
|
-
|
The top-level risk level of the event
|
|
|
groupId
|
|
-
|
The group ID for the management scope filter
|
|
|
logReceivedTime
|
|
-
|
The time when the XDR log was received
|
|
|
policyTreePath
|
|
-
|
The policy tree path (endpoint only)
|
|
|
productCode
|
|
-
|
The internal product code
|
|
|
readOnly
|
|
-
|
Whether the operation is read-only
|
|
|
recipientAccountId
|
|
-
|
The Account ID that received the event
|
|
|
requestID
|
|
-
|
The request ID
|
|
|
requestParameters
|
|
-
|
The parameters, if any, that were sent with the request
|
|
|
resources
|
|
-
|
The list of resources accessed in the event
|
|
|
responseElements
|
|
-
|
The response elements for actions that made changes (create, update, or delete actions)
|
|
|
serviceEventDetails
|
|
-
|
The service event details
|
|
|
sharedEventID
|
|
-
|
The GUID generated by AWS CloudTrail to uniquely identify CloudTrail events
|
|
|
sourceIPAddress
|
|
|
The IP address the request was made from (for service console: the customer resource,
for AWS services: the DNS name)
|
|
|
tags
|
|
-
|
The detected technique ID based on the alert filter
|
|
|
userAgent
|
|
|
The user agent or the agent through which the request was made
|
|
|
userIdentity
|
|
-
|
The information about the user that made a request
|
|
|
uuid
|
|
-
|
The unique key of the log
|
|
|
vpcEndpointId
|
|
-
|
The VPC endpoint in which requests were made from a VPC to another AWS service
|
|
|
Views: