Parsers and Generated Fields

Tag Fields Created by Parser aws-waf
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser aws-waf
Vendor FieldCPS FieldDescription
Vendor.actionevent.actionAction taken by WAF
Vendor.httpRequest.requestIdhttp.request.idUnique request identifier
Vendor.httpRequest.httpMethodhttp.request.methodHTTP method used
Vendor.httpRequest.httpVersionnetwork.protocol,HTTP protocol version, split into protocol and version
Vendor.terminatingRuleIdrule.idWAF rule identifier
Vendor.terminatingRuleTyperule.rulesetWAF rule type
Vendor.httpRequest.countrysource.geo.country_iso_codeCountry code of client IP
Vendor.httpRequest.clientIpsource.ipClient IP address
Vendor.httpRequest.uriurl.pathRequest URI path
Vendor.httpRequest.argsurl.queryURL query parameters