Skip to content

Latest commit

 

History

History
37 lines (30 loc) · 1023 Bytes

1c9f12ea-e54e-42b4-b4ab-ef616ae18c69.md

File metadata and controls

37 lines (30 loc) · 1023 Bytes

Mappings: AWS Elastic Load Balancer - Custom Parser

Input Requirements

Input Value
Vendor AWS
Product Elastic Load Balancer
Log Format JSON
Event ID Regex Pattern _default_

Record Output

Output Value
Vendor Amazon AWS
Product Elastic Load Balancer
Record Type NetworkHTTP

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
bytesIn received_bytes
bytesOut sent_bytes
cloud_provider None The static text AWS is populated in this schema field.
cloud_service None The static text Elastic Load Balancer is populated in this schema field.
dstDevice_ip target_ip
dstPort target_port
http_method request_type
http_response_statusCode target_status_code
http_url request_url
http_userAgent user_agent
srcDevice_ip client_ip
srcPort client_port
timestamp time We expect the orginal record value of time is in the format yyyy-MM-dd'T'HH:mm:ss