Skip to content

Commit 4b70500

Browse files
committed
Merge remote-tracking branch 'origin/datasource_enrichment' into datasource_enrichment
2 parents 6488af7 + ebe5db3 commit 4b70500

File tree

103 files changed

+226
-250
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

103 files changed

+226
-250
lines changed

data_sources/asl_aws_cloudtrail.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,6 @@ supported_TA:
2525
url: https://splunkbase.splunk.com/app/1876
2626
version: 7.9.1
2727
output_fields:
28-
- action
2928
- dest
3029
- user
3130
- user_agent

data_sources/aws_cloudtrail_assumerolewithsaml.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -133,7 +133,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "SAMLUser", "pri
133133
"eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management",
134134
"recipientAccountId": "111111111111"}'
135135
output_fields:
136-
- action
137136
- dest
138137
- user
139138
- user_agent

data_sources/aws_cloudtrail_consolelogin.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -109,7 +109,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "acco
109109
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
110110
"clientProvidedHostHeader": "signin.aws.amazon.com"}}'
111111
output_fields:
112-
- action
113112
- dest
114113
- user
115114
- user_agent

data_sources/aws_cloudtrail_copyobject.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -125,7 +125,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
125125
"eventType": "AwsApiCall", "managementEvent": false, "recipientAccountId": "111111111111",
126126
"eventCategory": "Data"}'
127127
output_fields:
128-
- action
129128
- dest
130129
- user
131130
- user_agent

data_sources/aws_cloudtrail_createaccesskey.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -109,7 +109,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
109109
"AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId":
110110
"121521347698"}'
111111
output_fields:
112-
- action
113112
- dest
114113
- user
115114
- user_agent

data_sources/aws_cloudtrail_createkey.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -156,7 +156,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
156156
"eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management",
157157
"recipientAccountId": "111111111111"}'
158158
output_fields:
159-
- action
160159
- dest
161160
- user
162161
- user_agent

data_sources/aws_cloudtrail_createloginprofile.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -108,7 +108,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
108108
"AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId":
109109
"111111111111"}'
110110
output_fields:
111-
- action
112111
- dest
113112
- user
114113
- user_agent

data_sources/aws_cloudtrail_createnetworkaclentry.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -127,7 +127,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
127127
"6d1ce00e-4099-463c-8a4d-2af2fb2178ba", "readOnly": false, "eventType": "AwsApiCall",
128128
"managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
129129
output_fields:
130-
- action
131130
- dest
132131
- user
133132
- user_agent

data_sources/aws_cloudtrail_createpolicyversion.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -112,7 +112,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
112112
"AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId":
113113
"111111111111"}'
114114
output_fields:
115-
- action
116115
- dest
117116
- user
118117
- user_agent

data_sources/aws_cloudtrail_createsnapshot.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -124,7 +124,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
124124
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
125125
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "ec2.us-west-2.amazonaws.com"}}'
126126
output_fields:
127-
- action
128127
- dest
129128
- user
130129
- user_agent

data_sources/aws_cloudtrail_createtask.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -127,7 +127,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
127127
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "datasync.us-west-2.amazonaws.com"},
128128
"sessionCredentialFromConsole": "true"}'
129129
output_fields:
130-
- action
131130
- dest
132131
- user
133132
- user_agent

data_sources/aws_cloudtrail_createvirtualmfadevice.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -106,7 +106,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip
106106
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
107107
"140429656527", "eventCategory": "Management", "sessionCredentialFromConsole": "true"}'
108108
output_fields:
109-
- action
110109
- dest
111110
- user
112111
- user_agent

data_sources/aws_cloudtrail_deactivatemfadevice.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -106,7 +106,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip
106106
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
107107
"111111111111", "eventCategory": "Management"}'
108108
output_fields:
109-
- action
110109
- dest
111110
- user
112111
- user_agent

data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -104,7 +104,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip
104104
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
105105
"111111111111", "eventCategory": "Management", "sessionCredentialFromConsole": "true"}'
106106
output_fields:
107-
- action
108107
- dest
109108
- user
110109
- user_agent

data_sources/aws_cloudtrail_deletealarms.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -147,7 +147,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
147147
"managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
148148
"Management"}'
149149
output_fields:
150-
- action
151150
- dest
152151
- user
153152
- user_agent

data_sources/aws_cloudtrail_deletedetector.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -104,7 +104,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
104104
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
105105
"111111111111", "eventCategory": "Management"}'
106106
output_fields:
107-
- action
108107
- dest
109108
- user
110109
- user_agent

data_sources/aws_cloudtrail_deletegroup.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -108,7 +108,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
108108
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory":
109109
"Management", "recipientAccountId": "121522247101"}'
110110
output_fields:
111-
- action
112111
- dest
113112
- user
114113
- user_agent

data_sources/aws_cloudtrail_deleteipset.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -104,7 +104,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
104104
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
105105
"111111111111", "eventCategory": "Management"}'
106106
output_fields:
107-
- action
108107
- dest
109108
- user
110109
- user_agent

data_sources/aws_cloudtrail_deleteloggroup.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -106,7 +106,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
106106
"eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite":
107107
"ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "logs.us-west-2.amazonaws.com"}}'
108108
output_fields:
109-
- action
110109
- dest
111110
- user
112111
- user_agent

data_sources/aws_cloudtrail_deletelogstream.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -107,7 +107,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
107107
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
108108
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "logs.us-west-2.amazonaws.com"}}'
109109
output_fields:
110-
- action
111110
- dest
112111
- user
113112
- user_agent

data_sources/aws_cloudtrail_deletenetworkaclentry.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -115,7 +115,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
115115
"b9e05770-e9b0-4ba1-91e8-6537097e06e7", "readOnly": false, "eventType": "AwsApiCall",
116116
"managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
117117
output_fields:
118-
- action
119118
- dest
120119
- user
121120
- user_agent

data_sources/aws_cloudtrail_deletepolicy.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -106,7 +106,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
106106
"abd071bf-0a38-4fab-af4a-5eee55f0935e", "readOnly": false, "eventType": "AwsApiCall",
107107
"managementEvent": true, "eventCategory": "Management", "recipientAccountId": "151521547504"}'
108108
output_fields:
109-
- action
110109
- dest
111110
- user
112111
- user_agent

data_sources/aws_cloudtrail_deleterule.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -108,7 +108,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
108108
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
109109
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "waf.amazonaws.com"}}'
110110
output_fields:
111-
- action
112111
- dest
113112
- user
114113
- user_agent

data_sources/aws_cloudtrail_deletesnapshot.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -151,7 +151,6 @@ example_log: '{"eventVersion": "1.09", "userIdentity": {"type": "AssumedRole", "
151151
"managementEvent": true, "recipientAccountId": "11111111111111", "eventCategory":
152152
"Management", "sessionCredentialFromConsole": "true"}'
153153
output_fields:
154-
- action
155154
- dest
156155
- user
157156
- user_agent

data_sources/aws_cloudtrail_deletetrail.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -104,7 +104,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
104104
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
105105
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "cloudtrail.us-west-2.amazonaws.com"}}'
106106
output_fields:
107-
- action
108107
- dest
109108
- user
110109
- user_agent

data_sources/aws_cloudtrail_deletevirtualmfadevice.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -104,7 +104,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip
104104
"managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
105105
"Management", "sessionCredentialFromConsole": "true"}'
106106
output_fields:
107-
- action
108107
- dest
109108
- user
110109
- user_agent

data_sources/aws_cloudtrail_deletewebacl.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -106,7 +106,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
106106
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
107107
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "waf.amazonaws.com"}}'
108108
output_fields:
109-
- action
110109
- dest
111110
- user
112111
- user_agent

data_sources/aws_cloudtrail_describeeventaggregates.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -101,7 +101,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip
101101
"AwsApiCall", "managementEvent": true, "recipientAccountId": "1111111111111111", "eventCategory":
102102
"Management", "sessionCredentialFromConsole": "true"}'
103103
output_fields:
104-
- action
105104
- dest
106105
- user
107106
- user_agent

data_sources/aws_cloudtrail_describeimagescanfindings.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -900,7 +900,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
900900
"readOnly": true, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
901901
"111111111111", "eventCategory": "Management"}'
902902
output_fields:
903-
- action
904903
- dest
905904
- user
906905
- user_agent

data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -103,7 +103,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
103103
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
104104
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "iam.amazonaws.com"}}'
105105
output_fields:
106-
- action
107106
- dest
108107
- user
109108
- user_agent

data_sources/aws_cloudtrail_getobject.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -118,7 +118,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
118118
"eventCategory": "Data", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite":
119119
"ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "security-content.s3.us-west-2.amazonaws.com"}}'
120120
output_fields:
121-
- action
122121
- dest
123122
- user
124123
- user_agent

data_sources/aws_cloudtrail_getpassworddata.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -119,7 +119,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
119119
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
120120
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "ec2.us-west-2.amazonaws.com"}}'
121121
output_fields:
122-
- action
123122
- dest
124123
- user
125124
- user_agent

data_sources/aws_cloudtrail_jobcreated.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -87,7 +87,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"accountId": "1111111111
8787
"status": "New", "jobEventId": "4e70d2f1053c07a79d9be9a14e486020", "failureCodes":
8888
[], "statusChangeReason": []}, "eventCategory": "Management"}'
8989
output_fields:
90-
- action
9190
- dest
9291
- user
9392
- user_agent

data_sources/aws_cloudtrail_modifydbinstance.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -198,7 +198,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
198198
"AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
199199
"Management", "sessionCredentialFromConsole": "true"}'
200200
output_fields:
201-
- action
202201
- dest
203202
- user
204203
- user_agent

data_sources/aws_cloudtrail_modifyimageattribute.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -112,7 +112,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
112112
"AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
113113
"Management", "sessionCredentialFromConsole": "true"}'
114114
output_fields:
115-
- action
116115
- dest
117116
- user
118117
- user_agent

data_sources/aws_cloudtrail_modifysnapshotattribute.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -104,7 +104,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
104104
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
105105
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "ec2.us-west-2.amazonaws.com"}}'
106106
output_fields:
107-
- action
108107
- dest
109108
- user
110109
- user_agent

data_sources/aws_cloudtrail_putbucketacl.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -120,7 +120,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
120120
"ARN": "arn:aws:s3:::patricktestbucket19"}], "eventType": "AwsApiCall", "managementEvent":
121121
true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
122122
output_fields:
123-
- action
124123
- dest
125124
- user
126125
- user_agent

data_sources/aws_cloudtrail_putbucketlifecycle.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -124,7 +124,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
124124
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
125125
"clientProvidedHostHeader": "my-cloudtrail-bucket-alfsujjpnbpguqrh.s3.us-west-2.amazonaws.com"}}'
126126
output_fields:
127-
- action
128127
- dest
129128
- user
130129
- user_agent

data_sources/aws_cloudtrail_putbucketreplication.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -144,7 +144,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
144144
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
145145
"clientProvidedHostHeader": "s3.us-west-2.amazonaws.com"}}'
146146
output_fields:
147-
- action
148147
- dest
149148
- user
150149
- user_agent

data_sources/aws_cloudtrail_putbucketversioning.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -132,7 +132,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
132132
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
133133
"clientProvidedHostHeader": "s3.us-west-2.amazonaws.com"}}'
134134
output_fields:
135-
- action
136135
- dest
137136
- user
138137
- user_agent

data_sources/aws_cloudtrail_putimage.yml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -155,8 +155,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
155155
"eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111",
156156
"eventCategory": "Management"}'
157157
output_fields:
158-
- action
159-
- dest
160158
- user
161159
- user_agent
162160
- src

data_sources/aws_cloudtrail_putkeypolicy.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -134,7 +134,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
134134
"eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management",
135135
"recipientAccountId": "111111111111"}'
136136
output_fields:
137-
- action
138137
- dest
139138
- user
140139
- user_agent

data_sources/aws_cloudtrail_replacenetworkaclentry.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -121,7 +121,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
121121
"46fe04b8-d007-4933-8bb8-c8b65c1121fa", "readOnly": false, "eventType": "AwsApiCall",
122122
"managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
123123
output_fields:
124-
- action
125124
- dest
126125
- user
127126
- user_agent

data_sources/aws_cloudtrail_setdefaultpolicyversion.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -103,7 +103,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
103103
"AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId":
104104
"111111111111"}'
105105
output_fields:
106-
- action
107106
- dest
108107
- user
109108
- user_agent

data_sources/aws_cloudtrail_stoplogging.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -98,7 +98,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
9898
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
9999
"clientProvidedHostHeader": "cloudtrail.us-west-2.amazonaws.com"}}'
100100
output_fields:
101-
- action
102101
- dest
103102
- user
104103
- user_agent

data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -110,7 +110,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip
110110
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
111111
"111111111111", "eventCategory": "Management", "sessionCredentialFromConsole": "true"}'
112112
output_fields:
113-
- action
114113
- dest
115114
- user
116115
- user_agent

data_sources/aws_cloudtrail_updateloginprofile.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -100,7 +100,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
100100
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory":
101101
"Management", "recipientAccountId": "111111111111"}'
102102
output_fields:
103-
- action
104103
- dest
105104
- user
106105
- user_agent

data_sources/aws_cloudtrail_updatesamlprovider.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -191,7 +191,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
191191
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory":
192192
"Management", "recipientAccountId": "111111111111"}'
193193
output_fields:
194-
- action
195194
- dest
196195
- user
197196
- user_agent

data_sources/aws_cloudtrail_updatetrail.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -111,7 +111,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
111111
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
112112
"clientProvidedHostHeader": "cloudtrail.us-west-2.amazonaws.com"}}'
113113
output_fields:
114-
- action
115114
- dest
116115
- user
117116
- user_agent

0 commit comments

Comments
 (0)