Amazon GuardDuty

The QRadar® product data source type for Amazon GuardDuty collects Amazon GuardDuty alerts from the log group of the Amazon CloudWatch logs services.
The following table identifies the specifications for the Amazon GuardDuty Data source type:
Table 1. Amazon GuardDuty data source type specifications
Specification Value
Manufacturer Amazon
Data source type Amazon GuardDuty
Supported versions GuardDuty Schema Version 2.0
Connector type

Amazon Web Services


Event format JSON
Recorded event types


Automatically discovered? No
Includes identity? No
Includes custom properties? No
More information For more information, see the Amazon GuardDuty Documentation (

For information about adding a data source in the QRadar product, see Adding a data source.

If you are an IBM® QRadar user, see Terminology changes for QRadar customers.