Mappings: AWS CloudWatch Custom
Input | Value |
---|---|
Vendor | AWS |
Product | CloudWatch |
Log Format | JSON |
Event ID Regex Pattern | _default_ |
Output | Value |
---|---|
Vendor | Amazon AWS |
Product | CloudWatch |
Record Type | Audit |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
description | msg | |
device_ip | host | |
http_method | method | |
http_referer | referer | |
http_response_statusCode | status | |
http_url | uri | |
http_userAgent | user-agent | |
tcpProtocol | protocol | |
timestamp | timestamp | We expect the orginal record value of timestamp is in the format epoch_ms |
user_username | username |