Field Name
|
Type
|
General Field
|
Description
|
Example
|
Products
|
additionalEventData
|
|
-
|
The additional data about the event that was not part of the request or response
|
|
|
apiVersion
|
|
-
|
The API version associated with the AwsApiCall eventType value
|
|
|
awsRegion
|
|
-
|
The AWS region that the request was made to
|
|
|
errorCode
|
|
-
|
The AWS service error code
|
|
|
errorMessage
|
|
-
|
The error description
|
|
|
eventCase
|
|
-
|
The AWS service that the request was made to
|
|
|
eventCategory
|
|
-
|
The event category used in LookupEvents calls
|
|
|
eventID
|
|
-
|
The GUID generated by AWS CloudTrail to identify events
|
|
|
eventName
|
|
-
|
The name of the log event
|
|
|
eventSource
|
|
-
|
The AWS service the request was made to
|
|
|
eventSubId
|
|
-
|
The access type
|
|
|
eventTime
|
|
-
|
The time the agent or product detected the event
|
|
|
eventType
|
|
-
|
The type of event that generated the event record
|
|
|
eventVersion
|
|
-
|
The version of the log event format
|
|
|
filterRiskLevel
|
|
-
|
The top-level risk level of the event
|
|
|
groupId
|
|
-
|
The group ID for the management scope filter
|
|
|
logReceivedTime
|
|
-
|
The time when the XDR log was received
|
|
|
policyTreePath
|
|
-
|
The policy tree path (endpoint only)
|
|
|
productCode
|
|
-
|
The internal product code
|
|
|
readOnly
|
|
-
|
Whether the operation is read-only
|
|
|
recipientAccountId
|
|
-
|
The Account ID that received the event
|
|
|
requestID
|
|
-
|
The value that identifies the request (the service being called generates this value)
|
|
|
requestParameters
|
|
-
|
The parameters, if any, that were sent with the request (parameters are documented
in the API reference docs for the appropriate AWS service)
|
|
|
resources
|
|
-
|
The list of resources accessed in the event
|
|
|
responseElements
|
|
-
|
The response elements for actions that made changes (create, update, or delete actions)
|
|
|
serviceEventDetails
|
|
-
|
The service event (including what triggered the event and the result)
|
|
|
sharedEventID
|
|
-
|
The GUID generated by AWS CloudTrail to uniquely identify CloudTrail events (from
the same AWS action that is sent to different AWS accounts)
|
|
|
sourceIPAddress
|
|
|
The IP address the request was made from (For actions that originate from the service
console, the address reported is for the underlying customer resource, not the console
web server. For services in AWS, only the DNS name is displayed.)
|
|
|
tags
|
|
-
|
The detected technique ID based on the alert filter
|
|
|
userAgent
|
|
|
The user agent or the agent through which the request was made
|
|
|
userIdentity
|
|
-
|
The information about the user that made a request
|
|
|
uuid
|
|
-
|
The unique key of the log
|
|
|
vpcEndpointId
|
|
-
|
The VPC endpoint in which requests were made from a VPC to another AWS service (such
as Amazon S3)
|
|
|
Views: