Cloud

cloud

The Cloud object contains information about a cloud or Software-as-a-Service account or similar construct, such as AWS Account ID, regions, organizations, folders, compartments, tenants, etc.

Attributes

CaptionNameTypeDescription
AccountaccountAccount[]The account object describes details about the account that was the source or target of the activity.
Cloud Partitioncloud_partitionStringThe canonical cloud partition name to which the region is assigned (e.g. AWS Partitions: aws, aws-cn, aws-us-gov).
OrganizationorgOrganization[]Organization and org unit relevant to the event or object.
Project IDproject_uidStringThe unique identifier of a Cloud project.

🚧 WARNING: DEPRECATED

Project ID has been deprecated since 1.4.0. Use the account.uid attribute instead.

ProviderproviderStringThe unique name of the Cloud services provider, such as AWS, MS Azure, GCP, etc.
Raw Dataraw_dataJSONGroup:context

The event data as received from the event source.
Record IDrecord_idStringGroup:primary

Unique identifier for the object
RegionregionStringThe name of the cloud region, as defined by the cloud provider.
UnmappedunmappedUnmapped[]Data from the source that was not mapped into the schema.
Cloud Availability ZonezoneStringThe availability zone in the cloud region, as defined by the cloud provider.

Relationships

Cloud shown in context

Inbound Relationships

These objects and events reference Cloud in their attributes:

Outbound Relationships

Cloud references the following objects and events in its attributes:

This page describes qdm-1.5.1+ocsf-1.6.0


Did this page help you?