-
Notifications
You must be signed in to change notification settings - Fork 562
[AWS CloudTrail] Add cloud.account.id field mapping #15057
Copy link
Copy link
Closed
Labels
Integration:awsAWSAWSTeam:SDE-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]Crest developers on the Security Integrations team [elastic/sit-crest-contractors]Team:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]enhancementNew feature or requestNew feature or request
Metadata
Metadata
Assignees
Labels
Integration:awsAWSAWSTeam:SDE-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]Crest developers on the Security Integrations team [elastic/sit-crest-contractors]Team:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]enhancementNew feature or requestNew feature or request
Type
Fields
Give feedbackNo fields configured for issues without a type.
We are seeing reports that several CloudTrail event types are not mapping the
cloud.account.idfield fromaws.cloudtrail.recipient_account_id.One customer report displays the following counts of
event.actionwith the filternot cloud.account.id:*Sample data available on request.