| Column Name | Column Data Type |
accounts Input Column
The list of Amazon Web Services accounts for which log sources are displayed. | VARCHAR[] |
Show child fields- accounts[]
|
regions Input Column
The list of Regions for which log sources are displayed. | VARCHAR[] |
Show child fields- regions[]
|
sources Input Column
Specify the sources from which you want to collect logs. | STRUCT( "aws_log_source" STRUCT( "source_name" VARCHAR, "source_version" VARCHAR ), "custom_log_source" STRUCT( "attributes" STRUCT( "crawler_arn" VARCHAR, "database_arn" VARCHAR, "table_arn" VARCHAR ), "provider" STRUCT( "location" VARCHAR, "role_arn" VARCHAR ), "source_name" VARCHAR, "source_version" VARCHAR ) )[] |
Show child fields- sources[]
Show child fields- sources[].aws_log_source
Amazon Security Lake supports log and event collection for natively supported Amazon Web Services. For more information, see the Amazon Security Lake User Guide. Show child fields- sources[].aws_log_source.source_name
The name for a Amazon Web Services source. This must be a Regionally unique value.
- sources[].aws_log_source.source_version
The version for a Amazon Web Services source. This must be a Regionally unique value.
- sources[].custom_log_source
Amazon Security Lake supports custom source types. For more information, see the Amazon Security Lake User Guide. Show child fields- sources[].custom_log_source.attributes
The attributes of a third-party custom source. Show child fields- sources[].custom_log_source.attributes.crawler_arn
The ARN of the Glue crawler.
- sources[].custom_log_source.attributes.database_arn
The ARN of the Glue database where results are written, such as: arn:aws:daylight:us-east-1::database/sometable/*.
- sources[].custom_log_source.attributes.table_arn
The ARN of the Glue table.
- sources[].custom_log_source.provider
The details of the log provider for a third-party custom source. Show child fields- sources[].custom_log_source.provider.location
The location of the partition in the Amazon S3 bucket for Security Lake.
- sources[].custom_log_source.provider.role_arn
The ARN of the IAM role to be used by the entity putting logs into your custom source partition. Security Lake will apply the correct access policies to this role, but you must first manually create the trust policy for this role. The IAM role name must start with the text 'Security Lake'. The IAM role must trust the logProviderAccountId to assume the role.
- sources[].custom_log_source.source_name
The name for a third-party custom source. This must be a Regionally unique value.
- sources[].custom_log_source.source_version
The version for a third-party custom source. This must be a Regionally unique value.
|
_aws_profile Input Column
The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role. | STRUCT( "type" VARCHAR, "name" VARCHAR, "account_id" VARCHAR, "via_profile_name" VARCHAR, "assumed_role_arn" VARCHAR, "organization" STRUCT( "account_name" VARCHAR, "id" VARCHAR, "tags" STRUCT( "key" VARCHAR, "value" VARCHAR )[], "master_account" STRUCT( "id" VARCHAR, "email" VARCHAR ), "parents" STRUCT( "type" VARCHAR, "id" VARCHAR, "name" VARCHAR, "tags" STRUCT( "key" VARCHAR, "value" VARCHAR )[] )[] ) ) |
Show child fields- _aws_profile.account_id
The AWS account id
- _aws_profile.assumed_role_arn
The ARN of the assumed role
- _aws_profile.name
The unique name of the profile.
- _aws_profile.organization
Information about this profile's membership in the AWS organization. Show child fields- _aws_profile.organization.account_name
The name of account speciifed by the organization
- _aws_profile.organization.id
The organization id
- _aws_profile.organization.master_account
Show child fields- _aws_profile.organization.master_account.email
The organization master account email address
- _aws_profile.organization.master_account.id
The organization master account id
- _aws_profile.organization.parents[]
Show child fields- _aws_profile.organization.parents[].id
The id of the parent
- _aws_profile.organization.parents[].name
The name of the parent
- _aws_profile.organization.parents[].tags[]
Show child fields- _aws_profile.organization.parents[].tags[].key
- _aws_profile.organization.parents[].tags[].value
- _aws_profile.organization.parents[].type
The type of parent can be an organization unit or a root
- _aws_profile.organization.tags[]
Show child fields- _aws_profile.organization.tags[].key
- _aws_profile.organization.tags[].value
- _aws_profile.type
The type of profile, either 'credentials' or 'assumed_role'
- _aws_profile.via_profile_name
This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.
|
_aws_region Input Column
The AWS region to use. | VARCHAR |
account
Specify the account from which you want to collect logs. | VARCHAR |
region
Specify the Regions from which you want to collect logs. | VARCHAR |