tm-v1-schema

AWS CloudTrail

Layer: Others

This documentation provides detailed information about all fields available for AWS CloudTrail.

Field Name Type Searchable General Field Description Example Products
additionalEventData dynamic true - The additional data about the event that was not part of the request {"SignatureVersion":"SigV4","CipherSuite":"ECDHE-RSA-AES128-GCM-SHA256"} AWS CloudTrail
apiVersion string true - API version associated with the AwsApiCall eventType value 2012-08-10 AWS CloudTrail
awsRegion string true - AWS region that the request was made to
  • us-east-1
  • us-east-2
  • us-west-1
AWS CloudTrail
errorCode string true - AWS service error code
  • ThrottlingException
  • InvalidParameterValueException
  • NoSuchLifecycleConfiguration
AWS CloudTrail
errorMessage string true - Description of the error
  • The specified bucket does not have a website configuration
  • An unknown error occurred
  • The lifecycle configuration does not exist
AWS CloudTrail
eventCategory string true - Event category used in LookupEvents calls
  • Management
  • Data
  • Insight
AWS CloudTrail
eventID string true - GUID generated by AWS CloudTrail to identify events 11111111-1111-1111-1111-111111111111 AWS CloudTrail
eventName string true - The name of the log event
  • PutObject
  • GetObject
  • DescribeTable
AWS CloudTrail
eventSource string true - The AWS service the request was made to
  • s3.amazonaws.com
  • dynamodb.amazonaws.com
  • xray.amazonaws.com
AWS CloudTrail
eventTime string true - The time the agent or product detected the event 2022-07-06T22:28:06+00:00 AWS CloudTrail
eventType string true - Type of event that generated the event record
  • AwsApiCall
  • AwsServiceEvent
  • AwsConsoleAction
AWS CloudTrail
eventVersion string true - Version of the log event format 1.08 AWS CloudTrail
readOnly bool true - Whether the operation is read-only
  • True
AWS CloudTrail
recipientAccountId string true - Account ID that received the event 123456789012 AWS CloudTrail
requestID string true - Value that identifies the request (The service being called generates this value) 11111111-1111-1111-1111-111111111111 AWS CloudTrail
requestParameters dynamic true - The parameters, if any, that were sent with the request (Parameters are documented in the API reference docs for the appropriate AWS service) {"durationSeconds": 3600, "roleSessionName":"BackplaneAssumeRoleSession"} AWS CloudTrail
resources dynamic true - List of resources accessed in the event [{"type":"AWS::S3::Object","ARN":"arn:aws:s3:::your-bucket/file.txt"}] AWS CloudTrail
responseElements dynamic true - Response elements for actions that made changes (create, update, or delete actions) {"user":{"createDate":"Mar 24, 2014 9:11:59 PM","userName":"Bob","arn":"arn:aws:iam::123456789012:user/Bob","path":"/","userId":"EXAMPLEUSERID"}} AWS CloudTrail
serviceEventDetails dynamic true - The service event (including what triggered the event and the result) {"lifecycleEventPolicy":{"policyVersion":1,"policyId":"11111111-1111-1111-1111-111111111111"}} AWS CloudTrail
sharedEventID string true - GUID generated by AWS CloudTrail to uniquely identify CloudTrail events (From the same AWS action that is sent to different AWS accounts) 11111111-1111-1111-1111-111111111111 AWS CloudTrail
sourceIPAddress string true
  • IPv4
  • IPv6
IP address the request was made from (For actions that originate from the service console, the address reported is for the underlying customer resource, not the console web server. For services in AWS, only the DNS name is displayed.)
  • 10.10.10.10
  • apigateway.amazonaws.com
  • config.amazonaws.com
AWS CloudTrail
userAgent string true CLICommand The user agent or the agent through which the request was made
  • signin.amazonaws.com
  • console.amazonaws.com
  • aws-cli/1.3.23 Python/2.7.6 Linux/2.6.18-164.el5
AWS CloudTrail
userIdentity dynamic true - Information about the user that made a request
  • {"type":"AWSService","invokedBy":"apigateway.amazonaws.com"}
  • {"type":"AWSService","invokedBy":"lambda.amazonaws.com"}
AWS CloudTrail
vpcEndpointId string true - VPC endpoint in which requests were made from a VPC to another AWS service (Such as Amazon S3) vpce-00000000000000000 AWS CloudTrail

Field Statistics


Generated by XDR Common Schema Public Doc Generator V2