Cloud

cloud

The Cloud object contains information about a cloud or Software-as-a-Service account or similar construct, such as AWS Account ID, regions, organizations, folders, compartments, tenants, etc.

Attributes

CaptionNameTypeDescription
AccountaccountAccount[]

The account object describes details about the account that was the source or target of the activity.

Cloud Partitioncloud_partitionString

The canonical cloud partition name to which the region is assigned (e.g. AWS Partitions: aws, aws-cn, aws-us-gov).

OrganizationorgOrganization[]

Organization and org unit relevant to the event or object.

Project IDproject_uidString

The unique identifier of a Cloud project.

🚧 WARNING: DEPRECATED

Project ID has been deprecated since 1.4.0. Use the account.uid attribute instead.

ProviderproviderString

The unique name of the Cloud services provider, such as AWS, MS Azure, GCP, etc.

Raw Dataraw_dataJSON

Group:context
The event data as received from the event source.

Record IDrecord_idString

Group:primary
Unique identifier for the object

RegionregionString

The name of the cloud region, as defined by the cloud provider.

UnmappedunmappedUnmapped[]

Data from the source that was not mapped into the schema.

Network ZonezoneString

The availability zone in the cloud region, as defined by the cloud provider.

Relationships

Cloud shown in context

Inbound Relationships

These objects and events reference Cloud in their attributes:

Outbound Relationships

Cloud references the following objects and events in its attributes:

This page describes ocsf-1.4.0