Databucket

databucket

The databucket object is a basic container that holds data, typically organized through the use of data partitions.

Attributes

CaptionNameTypeDescription
Agent Listagent_listAgent[]

A list of agent objects associated with a device, endpoint, or resource.

API DetailsapiAPI[]

Group:context
Describes details about a typical API (Application Programming Interface) call.

CloudcloudCloud[]

Group:primary
Describes details about the Cloud environment where the event was originally created or logged.

Cloud Partitioncloud_partitionString

The canonical cloud partition name to which the region is assigned (e.g. AWS Partitions: aws, aws-cn, aws-us-gov).

Created Timecreated_timeTimestamp

The time when the databucket was known to have been created.

CriticalitycriticalityString

The criticality of the resource as defined by the event source.

DatadataJSON

Additional data describing the resource.

Data Classificationdata_classificationData Classification[]

Group:context
The Data Classification object includes information about data classification levels and data category types.

🚧 WARNING: DEPRECATED

Data Classification has been deprecated since 1.4.0. Use the attribute data_classifications instead

Data Classificationdata_classificationsData Classification[]

Group:context
A list of Data Classification objects, that include information about data classification levels and data category types, indentified by a classifier.

DescriptiondescString

The description of the databucket.

Encryption Detailsencryption_detailsEncryption Details[]

The encryption details of the databucket. Should be populated if the databucket is encrypted.

FilefileFile[]

Entity:FILE
Details about the file/object within a databucket.

GroupgroupGroup[]

The name of the related resource group.

GroupsgroupsGroup[]

The group names to which the databucket belongs.

HostnamehostnameHostname

Entity:HOSTNAME
The fully qualified name of the resource.

IP AddressipIP Address

Entity:IP_ADDRESS
The IP address of the resource, in either IPv4 or IPv6 format.

Back Ups Configuredis_backed_upBoolean

Indicates whether the device or resource has a backup enabled, such as an automated snapshot or a cloud backup. For example, this is indicated by the cloudBackupEnabled value within JAMF Pro mobile devices or the registration of an AWS ARN with the AWS Backup service.

Encryptedis_encryptedBoolean

Indicates if the databucket is encrypted.

Publicis_publicBoolean

Indicates if the databucket is publicly accessible.

LabelslabelsString[]

The list of labels associated to the resource.

Modified Timemodified_timeTimestamp

The most recent time when any changes, updates, or modifications were made within the databucket.

NamenameString

The databucket name.

NamespacenamespaceString

The namespace is useful when similar entities exist that you need to keep separate.

OwnerownerUser[]

Entity:USER
The identity of the service or user account that owns the resource.

Raw Dataraw_dataJSON

Group:context
The event data as received from the event source.

Record IDrecord_idString

Group:primary
Unique identifier for the object

RegionregionString

The cloud region of the resource.

SizesizeLong

The size of the databucket in bytes.

TagstagsKey:Value object[]

The list of tags; {key:value} pairs associated to the resource.

TypetypeString

The databucket type.

Type IDtype_idInteger

The normalized identifier of the databucket type.

  • 0: Unknown (UNKNOWN)
  • 1: S3 (S3)
  • 2: Azure Blob (AZURE_BLOB)
  • 3: GCP Bucket (GCP_BUCKET)
  • 99: Other (OTHER)
Unique IDuidResource UID

Entity:RESOURCE_UID
The unique identifier of the databucket.

UnmappedunmappedUnmapped[]

Data from the source that was not mapped into the schema.

VersionversionString

The version of the resource. For example 1.2.3.

Relationships

Databucket shown in context

Inbound Relationships

These objects and events reference Databucket in their attributes:

Outbound Relationships

Databucket references the following objects and events in its attributes:

This page describes ocsf-1.4.0