Skip to content

Latest commit

 

History

History
34 lines (27 loc) · 735 Bytes

ebf71fee-dfb0-4c9e-908c-59938fccf201.md

File metadata and controls

34 lines (27 loc) · 735 Bytes

Mappings: AWS CloudWatch Custom

Input Requirements

Input Value
Vendor AWS
Product CloudWatch
Log Format JSON
Event ID Regex Pattern _default_

Record Output

Output Value
Vendor Amazon AWS
Product CloudWatch
Record Type Audit

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
description msg
device_ip host
http_method method
http_referer referer
http_response_statusCode status
http_url uri
http_userAgent user-agent
tcpProtocol protocol
timestamp timestamp We expect the orginal record value of timestamp is in the format epoch_ms
user_username username