Layer: Cloud
This documentation provides detailed information about all fields available for XDR for Cloud - AWS VPC Flow Logs.
Field Name | Type | Searchable | General Field | Description | Example | Products |
---|---|---|---|---|---|---|
action | string | true | - | The traffic processing action |
|
XDR for Cloud - AWS VPC Flow Logs |
azId | string | true | - | The Availability Zone ID | apse2-az3 | XDR for Cloud - AWS VPC Flow Logs |
bytes | string | true | - | The number of transmitted data bytes | 15044 | XDR for Cloud - AWS VPC Flow Logs |
dpt | int | true | Port | The service destination port of the private application server (dstport) | 443 |
|
dst | string | true |
|
The destination IP address (dstaddr) | 10.10.10.10 |
|
end | long | false | - | The time when the last data packet was received (in Unix seconds) | 1616729349 | XDR for Cloud - AWS VPC Flow Logs |
eventId | string | true | - | The event ID |
|
|
eventName | string | true | - | The name of the log event |
|
|
eventTime | real | true | - | The time the agent or product detected the event | 1657135700000 |
|
flowDirection | string | true | - | The network interface traffic direction |
|
|
flowType | string | true | - | The type of traffic (type) |
|
XDR for Cloud - AWS VPC Flow Logs |
instanceId | string | true | - | The instance ID | i-01234567890abcdef | XDR for Cloud - AWS VPC Flow Logs |
logStatus | string | true | - | The VPC Flow Log status |
|
XDR for Cloud - AWS VPC Flow Logs |
packets | string | true | - | The number of transmitted data packets | 14 | XDR for Cloud - AWS VPC Flow Logs |
pktDstAddr | string | true |
|
The packet level destination IP | 10.10.10.10 | XDR for Cloud - AWS VPC Flow Logs |
pktDstCloudServiceName | string | true | - | The subset IP address range name for cloud service destination IP (pkt-dst-aws-service) |
|
XDR for Cloud - AWS VPC Flow Logs |
pktSrcAddr | string | true |
|
The packet level source IP | 10.10.10.10 | XDR for Cloud - AWS VPC Flow Logs |
pktSrcCloudServiceName | string | true | - | The subset IP address range name for cloud service source IP (pkt-src-aws-service) |
|
XDR for Cloud - AWS VPC Flow Logs |
pname | string | true | - | The product name |
|
|
spt | int | true | Port | The virtual port of the source assigned to the Secure Access Module (srcport) | 57763 |
|
src | string | true |
|
The source IP address (srcaddr) | 10.10.10.10 |
|
start | real | false | - | The time when the first data packet was received (in Unix seconds) | 1616729292 | XDR for Cloud - AWS VPC Flow Logs |
subLocationId | string | true | - | The sublocation ID |
|
XDR for Cloud - AWS VPC Flow Logs |
subLocationType | string | true | - | The sublocation type |
|
XDR for Cloud - AWS VPC Flow Logs |
subnetId | string | true | - | The subnet ID | subnet-01234567890abcdef | XDR for Cloud - AWS VPC Flow Logs |
tcpFlags | int | true | - | The bitmask value of the FIN/SYN/RST/SYN-ACK TCP flags |
|
XDR for Cloud - AWS VPC Flow Logs |
trafficPath | int | true | - | The egress traffic path number |
|
XDR for Cloud - AWS VPC Flow Logs |
vpcFlowLogsVersion | int | false | - | The VPC Flow Logs version (version) |
|
|
vpcId | string | true | - | The VPC ID | vpc-01234567890abcdef | XDR for Cloud - AWS VPC Flow Logs |
Generated by XDR Common Schema Public Doc Generator V2