cloud

The Cloud object contains information about a cloud or Software-as-a-Service account or similar construct, such as AWS Account ID, regions, organizations, folders, compartments, tenants, etc.

Attributes

CaptionNameTypeDescription
Account account Account[] The account object describes details about the account that was the source or target of the activity.
Cloud Partition cloud_partition String The canonical cloud partition name to which the region is assigned (e.g. AWS Partitions: aws, aws-cn, aws-us-gov).
Organization org Organization[] Organization and org unit relevant to the event or object.
Project ID project_uid String The unique identifier of a Cloud project.

🚧 WARNING: DEPRECATED

Project ID has been deprecated since 1.4.0. Use the account.uid attribute instead.

Provider provider String The unique name of the Cloud services provider, such as AWS, MS Azure, GCP, etc.
Raw Data raw_data JSON Group:context
The event data as received from the event source.
Record ID record_id String Group:primary
Unique identifier for the object
Region region String The name of the cloud region, as defined by the cloud provider.
Unmapped unmapped Unmapped[] Data from the source that was not mapped into the schema.
Network Zone zone String The availability zone in the cloud region, as defined by the cloud provider.

Relationships

Cloud shown in context

Inbound Relationships

These objects and events reference Cloud in their attributes:

Outbound Relationships

Cloud references the following objects and events in its attributes:

This page describes ocsf-1.4.0