Layer: Cloud
This documentation provides detailed information about all fields available for XDR for Cloud - AWS VPC Flow Logs.
| Field Name | Type | Searchable | General Field | Description | Example | Products |
|---|---|---|---|---|---|---|
| action | string | true | - | The traffic processing action |
|
XDR for Cloud - AWS VPC Flow Logs |
| azId | string | true | - | The Availability Zone ID | apse2-az3 | XDR for Cloud - AWS VPC Flow Logs |
| bytes | string | true | - | The number of transmitted data bytes | 15044 | XDR for Cloud - AWS VPC Flow Logs |
| dpt | int | true | Port | The service destination port of the private application server (dstport) | 443 |
|
| dst | string | true |
|
The destination IP address (dstaddr) | 10.10.10.10 |
|
| end | long | false | - | The time when the last data packet was received (in Unix seconds) | 1616729349 | XDR for Cloud - AWS VPC Flow Logs |
| eventId | string | true | - | The event ID |
|
|
| eventName | string | true | - | The name of the log event |
|
|
| eventTime | real | true | - | The time the agent or product detected the event | 1657135700000 |
|
| flowDirection | string | true | - | The network interface traffic direction |
|
|
| flowType | string | true | - | The type of traffic (type) |
|
XDR for Cloud - AWS VPC Flow Logs |
| instanceId | string | true | - | The instance ID | i-01234567890abcdef | XDR for Cloud - AWS VPC Flow Logs |
| logStatus | string | true | - | The VPC Flow Log status |
|
XDR for Cloud - AWS VPC Flow Logs |
| packets | string | true | - | The number of transmitted data packets | 14 | XDR for Cloud - AWS VPC Flow Logs |
| pktDstAddr | string | true |
|
The packet level destination IP | 10.10.10.10 | XDR for Cloud - AWS VPC Flow Logs |
| pktDstCloudServiceName | string | true | - | The subset IP address range name for cloud service destination IP (pkt-dst-aws-service) |
|
XDR for Cloud - AWS VPC Flow Logs |
| pktSrcAddr | string | true |
|
The packet level source IP | 10.10.10.10 | XDR for Cloud - AWS VPC Flow Logs |
| pktSrcCloudServiceName | string | true | - | The subset IP address range name for cloud service source IP (pkt-src-aws-service) |
|
XDR for Cloud - AWS VPC Flow Logs |
| pname | string | true | - | The product name |
|
|
| spt | int | true | Port | The virtual port of the source assigned to the Secure Access Module (srcport) | 57763 |
|
| src | string | true |
|
The source IP address (srcaddr) | 10.10.10.10 |
|
| start | real | false | - | The time when the first data packet was received (in Unix seconds) | 1616729292 | XDR for Cloud - AWS VPC Flow Logs |
| subLocationId | string | true | - | The sublocation ID |
|
XDR for Cloud - AWS VPC Flow Logs |
| subLocationType | string | true | - | The sublocation type |
|
XDR for Cloud - AWS VPC Flow Logs |
| subnetId | string | true | - | The subnet ID | subnet-01234567890abcdef | XDR for Cloud - AWS VPC Flow Logs |
| tcpFlags | int | true | - | The bitmask value of the FIN/SYN/RST/SYN-ACK TCP flags |
|
XDR for Cloud - AWS VPC Flow Logs |
| trafficPath | int | true | - | The egress traffic path number |
|
XDR for Cloud - AWS VPC Flow Logs |
| vpcFlowLogsVersion | int | false | - | The VPC Flow Logs version (version) |
|
|
| vpcId | string | true | - | The VPC ID | vpc-01234567890abcdef | XDR for Cloud - AWS VPC Flow Logs |
Generated by XDR Common Schema Public Doc Generator V2