guardduty.accountId | CHARBUF | GuardDuty account ID |
guardduty.region | CHARBUF | GuardDuty region |
guardduty.time | CHARBUF | GuardDuty last updated event time |
guardduty.id | CHARBUF | GuardDuty ID |
guardduty.arn | CHARBUF | GuardDuty ARN |
guardduty.type | CHARBUF | GuardDuty type |
guardduty.resourceType | CHARBUF | GuardDuty resource type |
guardduty.actionType | CHARBUF | GuardDuty action type |
guardduty.resourceRole | CHARBUF | GuardDuty resource role |
guardduty.eventFirstSeen | CHARBUF | GuardDuty event first seen |
guardduty.eventLastSeen | CHARBUF | GuardDuty event last seen |
guardduty.threatFilesSha256 | LIST(CHARBUF) | GuardDuty threat files SHA-256 |
guardduty.archived | CHARBUF | GuardDuty archived |
guardduty.count | CHARBUF | GuardDuty count |
guardduty.severity | CHARBUF | GuardDuty severity |
guardduty.title | CHARBUF | GuardDuty title |
guardduty.description | CHARBUF | GuardDuty description |
guardduty.EC2.instanceId | CHARBUF | GuardDuty EC2 instance ID |
guardduty.EC2.instanceType | CHARBUF | GuardDuty EC2 instance type |
guardduty.IAM.principalId | CHARBUF | GuardDuty IAM principal ID |
guardduty.IAM.userName | CHARBUF | GuardDuty IAM user name |
guardduty.S3.bucketNames | LIST(CHARBUF) | GuardDuty S3 bucket names |
guardduty.S3.permissions | LIST(CHARBUF) | GuardDuty S3 permissions |
guardduty.EKS.clusterName | CHARBUF | GuardDuty EKS cluster name |
guardduty.EKS.workloadName | CHARBUF | GuardDuty EKS workload name |
guardduty.EKS.namespace | CHARBUF | GuardDuty EKS namespace |
guardduty.EKS.containers | LIST(CHARBUF) | GuardDuty EKS containers |
guardduty.EKS.userName | CHARBUF | GuardDuty EKS user name |
guardduty.EKS.serviceAccount | CHARBUF | GuardDuty EKS service account |
guardduty.ECS.clusterName | CHARBUF | GuardDuty ECS cluster name |
guardduty.ECS.clusterStatus | CHARBUF | GuardDuty ECS cluster status |
guardduty.ECS.task | CHARBUF | GuardDuty ECS task |
guardduty.ECS.containers | LIST(CHARBUF) | GuardDuty ECS containers |
guardduty.container.runtime | CHARBUF | GuardDuty container runtime |
guardduty.container.name | CHARBUF | GuardDuty container name |
guardduty.container.image | CHARBUF | GuardDuty container image |
guardduty.container.privileged | CHARBUF | GuardDuty container privileged |
guardduty.RDS.dbInstanceId | CHARBUF | GuardDuty RDS DB instance ID |
guardduty.RDS.userName | CHARBUF | GuardDuty RDS user name |
guardduty.RDS.database | CHARBUF | GuardDuty RDS database |
guardduty.RDS.application | CHARBUF | GuardDuty RDS application |
guardduty.lambda.functionName | CHARBUF | GuardDuty Lambda function name |
guardduty.lambda.role | CHARBUF | GuardDuty Lambda role |
guardduty.runtime.exepath | CHARBUF | GuardDuty runtime executable path |
guardduty.runtime.procname | CHARBUF | GuardDuty runtime process name |
guardduty.runtime.euid | CHARBUF | GuardDuty runtime effective user ID |
guardduty.runtime.pid | CHARBUF | GuardDuty runtime process ID |
guardduty.runtime.user | CHARBUF | GuardDuty runtime user |
guardduty.runtime.cmdline | CHARBUF | GuardDuty runtime command line |
guardduty.runtime.scriptPath | CHARBUF | GuardDuty runtime script path |
guardduty.runtime.threatFilePath | CHARBUF | GuardDuty runtime threat file path |
guardduty.runtime.toolName | CHARBUF | GuardDuty runtime tool name |
guardduty.runtime.toolCategory | CHARBUF | GuardDuty runtime tool category |
guardduty.EBS.scannedVolumes | LIST(CHARBUF) | GuardDuty EBS scanned volumes |
guardduty.EBS.skippedVolumes | LIST(CHARBUF) | GuardDuty EBS skipped volumes |
guardduty.EBS.scanId | CHARBUF | GuardDuty EBS scan ID |
guardduty.EBS.scanType | CHARBUF | GuardDuty EBS scan type |
guardduty.EBS.scanSeverity | CHARBUF | GuardDuty EBS scan severity |
guardduty.EBS.highestThreatName | CHARBUF | GuardDuty EBS highest threat name |
guardduty.EBS.threats | LIST(CHARBUF) | GuardDuty EBS threats |
guardduty.EBS.maliciousFilesCount | CHARBUF | GuardDuty EBS malicious files count |
guardduty.awsApiAction.api | CHARBUF | GuardDuty AWS API action API |
guardduty.awsApiAction.ip | CHARBUF | GuardDuty AWS API action IP |
guardduty.awsApiAction.srcInstance | CHARBUF | GuardDuty AWS API action source instance |
guardduty.dnsAction.protocol | CHARBUF | GuardDuty DNS action protocol |
guardduty.dnsAction.blocked | CHARBUF | GuardDuty DNS action blocked |
guardduty.dnsAction.domain | CHARBUF | GuardDuty DNS action domain |
guardduty.k8sApiAction.uri | CHARBUF | GuardDuty Kubernetes API action URI |
guardduty.k8sApiAction.resourceName | CHARBUF | GuardDuty Kubernetes API action resource name |
guardduty.k8sApiAction.namespace | CHARBUF | GuardDuty Kubernetes API action namespace |
guardduty.k8sApiAction.ip | CHARBUF | GuardDuty Kubernetes API action IP |
guardduty.networkAction.ip | CHARBUF | GuardDuty network action IP |
guardduty.networkAction.port | CHARBUF | GuardDuty network action port |
guardduty.networkAction.protocol | CHARBUF | GuardDuty network action protocol |
guardduty.networkAction.direction | CHARBUF | GuardDuty network action direction |
guardduty.networkAction.blocked | CHARBUF | GuardDuty network action blocked |
guardduty.portProbeAction.ports | LIST(CHARBUF) | GuardDuty port probe action ports |
guardduty.portProbeAction.srcIPs | LIST(CHARBUF) | GuardDuty port probe action source IPs |
guardduty.portProbeAction.blocked | CHARBUF | GuardDuty port probe action blocked |
guardduty.rdsLoginAction.apps | LIST(CHARBUF) | GuardDuty RDS login action applications |
guardduty.rdsLoginAction.ip | CHARBUF | GuardDuty RDS login action IP |