|
| 1 | +{ |
| 2 | + "expected": [ |
| 3 | + { |
| 4 | + "@timestamp": "2024-10-08T12:24:16.000Z", |
| 5 | + "actor": { |
| 6 | + "entity": { |
| 7 | + "id": [ |
| 8 | + "arn:aws:iam::000000000:user/test@elastic.co" |
| 9 | + ] |
| 10 | + } |
| 11 | + }, |
| 12 | + "aws": { |
| 13 | + "cloudtrail": { |
| 14 | + "additional_eventdata": "{SignatureVersion=SigV4, CipherSuite=TLS_AES_128_GCM_SHA256, bytesTransferredIn=0, SSEApplied=Default_SSE_S3, AuthenticationMethod=AuthHeader, x-amz-id-2=hFhfe14yINVvz+alr1rC5zPFufFU087OGEbVwf5HpD1BYs5D2llscEUSD7DUGjlSYkOEoay+oVk=, bytesTransferredOut=224}", |
| 15 | + "event_category": "Data", |
| 16 | + "event_type": "AwsApiCall", |
| 17 | + "event_version": "1.09", |
| 18 | + "flattened": { |
| 19 | + "additional_eventdata": { |
| 20 | + "SSEApplied": "Default_SSE_S3" |
| 21 | + } |
| 22 | + }, |
| 23 | + "read_only": false, |
| 24 | + "recipient_account_id": "000000000", |
| 25 | + "request_id": "62A9N2AH4P4YKG2B", |
| 26 | + "request_parameters": "{bucketName=elastic-cspm-cloudtrail-test-bucket, Host=elastic-cspm-cloudtrail-test-bucket.s3.us-east-1.amazonaws.com, x-amz-copy-source=elastic-cspm-cloudtrail-test-bucket/test-copy-object/README.md, key=test-copy-object/README-copy.md}", |
| 27 | + "resources": [ |
| 28 | + { |
| 29 | + "arn": "arn:aws:s3:::elastic-cspm-cloudtrail-test-bucket/test-copy-object/README.md", |
| 30 | + "type": "AWS::S3::Object" |
| 31 | + }, |
| 32 | + { |
| 33 | + "arn": "arn:aws:s3:::elastic-cspm-cloudtrail-test-bucket/test-copy-object/README-copy.md", |
| 34 | + "type": "AWS::S3::Object" |
| 35 | + }, |
| 36 | + { |
| 37 | + "account_id": "000000000", |
| 38 | + "arn": "arn:aws:s3:::elastic-cspm-cloudtrail-test-bucket", |
| 39 | + "type": "AWS::S3::Bucket" |
| 40 | + } |
| 41 | + ], |
| 42 | + "response_elements": "{x-amz-server-side-encryption=AES256}", |
| 43 | + "user_identity": { |
| 44 | + "access_key_id": "ACCESSKEYID", |
| 45 | + "arn": "arn:aws:iam::000000000:user/test@elastic.co", |
| 46 | + "type": "IAMUser" |
| 47 | + } |
| 48 | + } |
| 49 | + }, |
| 50 | + "cloud": { |
| 51 | + "account": { |
| 52 | + "id": "000000000" |
| 53 | + }, |
| 54 | + "region": "us-east-1" |
| 55 | + }, |
| 56 | + "ecs": { |
| 57 | + "version": "8.11.0" |
| 58 | + }, |
| 59 | + "event": { |
| 60 | + "action": "CopyObject", |
| 61 | + "created": "2021-11-11T01:02:03.123456789Z", |
| 62 | + "id": "0c06e2ff-5e88-44e6-a081-57871bbe770b", |
| 63 | + "kind": "event", |
| 64 | + "original": "{\"eventVersion\":\"1.09\",\"userIdentity\":{\"type\":\"IAMUser\",\"principalId\":\"ACCESSKEYID\",\"arn\":\"arn:aws:iam::000000000:user/test@elastic.co\",\"accountId\":\"000000000\",\"accessKeyId\":\"ACCESSKEYID\",\"userName\":\"test@elastic.co\"},\"eventTime\":\"2024-10-08T12:24:16Z\",\"eventSource\":\"s3.amazonaws.com\",\"eventName\":\"CopyObject\",\"awsRegion\":\"us-east-1\",\"sourceIPAddress\":\"216.160.83.56\",\"userAgent\":\"[aws-cli/2.17.60 md/awscrt#0.21.2 ua/2.0 os/macos#23.6.0 md/arch#x86_64 lang/python#3.12.6 md/pyimpl#CPython cfg/retry-mode#standard md/installer#exe md/prompt#off md/command#s3api.copy-object]\",\"requestParameters\":{\"bucketName\":\"elastic-cspm-cloudtrail-test-bucket\",\"Host\":\"elastic-cspm-cloudtrail-test-bucket.s3.us-east-1.amazonaws.com\",\"x-amz-copy-source\":\"elastic-cspm-cloudtrail-test-bucket/test-copy-object/README.md\",\"key\":\"test-copy-object/README-copy.md\"},\"responseElements\":{\"x-amz-server-side-encryption\":\"AES256\"},\"additionalEventData\":{\"SignatureVersion\":\"SigV4\",\"CipherSuite\":\"TLS_AES_128_GCM_SHA256\",\"bytesTransferredIn\":0,\"SSEApplied\":\"Default_SSE_S3\",\"AuthenticationMethod\":\"AuthHeader\",\"x-amz-id-2\":\"hFhfe14yINVvz+alr1rC5zPFufFU087OGEbVwf5HpD1BYs5D2llscEUSD7DUGjlSYkOEoay+oVk=\",\"bytesTransferredOut\":224},\"requestID\":\"62A9N2AH4P4YKG2B\",\"eventID\":\"0c06e2ff-5e88-44e6-a081-57871bbe770b\",\"readOnly\":false,\"resources\":[{\"type\":\"AWS::S3::Object\",\"ARN\":\"arn:aws:s3:::elastic-cspm-cloudtrail-test-bucket/test-copy-object/README-copy.md\"},{\"accountId\":\"000000000\",\"type\":\"AWS::S3::Bucket\",\"ARN\":\"arn:aws:s3:::elastic-cspm-cloudtrail-test-bucket\"},{\"type\":\"AWS::S3::Object\",\"ARN\":\"arn:aws:s3:::elastic-cspm-cloudtrail-test-bucket/test-copy-object/README.md\"}],\"eventType\":\"AwsApiCall\",\"recipientAccountId\":\"000000000\",\"eventCategory\":\"Data\",\"tlsDetails\":{\"tlsVersion\":\"TLSv1.3\",\"cipherSuite\":\"TLS_AES_128_GCM_SHA256\",\"clientProvidedHostHeader\":\"elastic-cspm-cloudtrail-test-bucket.s3.us-east-1.amazonaws.com\"}}", |
| 65 | + "outcome": "success", |
| 66 | + "provider": "s3.amazonaws.com", |
| 67 | + "type": [ |
| 68 | + "info" |
| 69 | + ] |
| 70 | + }, |
| 71 | + "related": { |
| 72 | + "entity": [ |
| 73 | + "arn:aws:s3:::elastic-cspm-cloudtrail-test-bucket", |
| 74 | + "test@elastic.co", |
| 75 | + "elastic-cspm-cloudtrail-test-bucket", |
| 76 | + "ACCESSKEYID", |
| 77 | + "arn:aws:iam::000000000:user/test@elastic.co", |
| 78 | + "arn:aws:s3:::elastic-cspm-cloudtrail-test-bucket/test-copy-object/README-copy.md", |
| 79 | + "arn:aws:s3:::elastic-cspm-cloudtrail-test-bucket/test-copy-object/README.md" |
| 80 | + ], |
| 81 | + "user": [ |
| 82 | + "ACCESSKEYID", |
| 83 | + "test@elastic.co" |
| 84 | + ] |
| 85 | + }, |
| 86 | + "source": { |
| 87 | + "address": "216.160.83.56", |
| 88 | + "as": { |
| 89 | + "number": 209 |
| 90 | + }, |
| 91 | + "geo": { |
| 92 | + "city_name": "Milton", |
| 93 | + "continent_name": "North America", |
| 94 | + "country_iso_code": "US", |
| 95 | + "country_name": "United States", |
| 96 | + "location": { |
| 97 | + "lat": 47.2513, |
| 98 | + "lon": -122.3149 |
| 99 | + }, |
| 100 | + "region_iso_code": "US-WA", |
| 101 | + "region_name": "Washington" |
| 102 | + }, |
| 103 | + "ip": "216.160.83.56" |
| 104 | + }, |
| 105 | + "tags": [ |
| 106 | + "preserve_original_event", |
| 107 | + "actor_target_mapping" |
| 108 | + ], |
| 109 | + "target": { |
| 110 | + "entity": { |
| 111 | + "id": [ |
| 112 | + "arn:aws:s3:::elastic-cspm-cloudtrail-test-bucket", |
| 113 | + "arn:aws:s3:::elastic-cspm-cloudtrail-test-bucket/test-copy-object/README-copy.md", |
| 114 | + "arn:aws:s3:::elastic-cspm-cloudtrail-test-bucket/test-copy-object/README.md" |
| 115 | + ] |
| 116 | + } |
| 117 | + }, |
| 118 | + "tls": { |
| 119 | + "cipher": "TLS_AES_128_GCM_SHA256", |
| 120 | + "client": { |
| 121 | + "server_name": "elastic-cspm-cloudtrail-test-bucket.s3.us-east-1.amazonaws.com" |
| 122 | + }, |
| 123 | + "version": "1.3", |
| 124 | + "version_protocol": "tls" |
| 125 | + }, |
| 126 | + "user": { |
| 127 | + "email": "test@elastic.co", |
| 128 | + "id": "ACCESSKEYID", |
| 129 | + "name": "test@elastic.co" |
| 130 | + }, |
| 131 | + "user_agent": { |
| 132 | + "device": { |
| 133 | + "name": "Other" |
| 134 | + }, |
| 135 | + "name": "aws-cli", |
| 136 | + "original": "[aws-cli/2.17.60 md/awscrt#0.21.2 ua/2.0 os/macos#23.6.0 md/arch#x86_64 lang/python#3.12.6 md/pyimpl#CPython cfg/retry-mode#standard md/installer#exe md/prompt#off md/command#s3api.copy-object]", |
| 137 | + "version": "2.17.60" |
| 138 | + } |
| 139 | + }, |
| 140 | + { |
| 141 | + "@timestamp": "2021-11-11T01:02:03.123456789Z", |
| 142 | + "ecs": { |
| 143 | + "version": "8.11.0" |
| 144 | + }, |
| 145 | + "event": { |
| 146 | + "created": "2021-11-11T01:02:03.123456789Z", |
| 147 | + "kind": "event", |
| 148 | + "outcome": "success", |
| 149 | + "type": [ |
| 150 | + "info" |
| 151 | + ] |
| 152 | + }, |
| 153 | + "tags": [ |
| 154 | + "preserve_original_event", |
| 155 | + "actor_target_mapping" |
| 156 | + ] |
| 157 | + } |
| 158 | + ] |
| 159 | +} |
0 commit comments