Skip to content

Latest commit

 

History

History
39 lines (32 loc) · 1.4 KB

2d163beb-e486-405f-a2a4-7134e25493aa.md

File metadata and controls

39 lines (32 loc) · 1.4 KB

Mappings: CloudTrail - elasticfilesystem.amazonaws.com - NewClientConnection

Input Requirements

Input Value
Vendor AWS
Product CloudTrail
Log Format JSON
Event ID Regex Pattern AwsServiceEvent-NewClientConnection

Record Output

Output Value
Vendor Amazon AWS
Product CloudTrail
Record Type AuditResourceAccess

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
accountId userIdentity.accountId
action eventName
application eventSource
cloud_provider None The static text AWS is populated in this schema field.
cloud_region awsRegion
cloud_service None The static text Elastic File System is populated in this schema field.
description None The static text This event is emitted from the Elastic File System when a connection is authorized immediately after an initial connection, and immediately after a reconnection is populated in this schema field.
device_ip sourceIPAddress
http_userAgent userAgent
normalizedSeverity None The static text 1 is populated in this schema field.
resource resources.1.ARN
srcDevice_ip sourceIPAddress
timestamp eventTime We expect the orginal record value of eventTime is in the format yyyy-MM-dd'T'HH:mm:ssZ
user_userId userIdentity.principalId
user_username userIdentity.sessionContext.sourceIdentity