Azure Activity
  • 08 Nov 2024
  • 1 Minute to read
  • Contributors
  • Dark
    Light

Azure Activity

  • Dark
    Light

Article summary

Azure Activity Logs provide a comprehensive record of actions capturing operations that impact resources, such as creating, updating, or deleting. They cover various categories, including administrative actions, service health events, alert triggers, and policy compliance checks.

Integration Method: API
Tables: Detection, Compliance, Entity Management
Events: Administrative, Alerts, Policy changes, Security

Azure Configuration

Step 1. Create an App registration

Step 2. Register the application

A screenshot of a computer  Description automatically generated

Step 3. Add a client Secret

Step 4. Locate the Tenant ID - Find the Tenant ID on the application’s Overview page.

A screenshot of a computer  Description automatically generated

Step 5. Configure Permissions - Set up the following permissions:

Permission Name

Type

AccessReview.Read.All

Delegated

AccessReview.Read.All

Application

AuditLog.Read.All

Delegated

AuditLog.Read.All

Application

User.Read

Delegated

DataBee Configuration

  1. Login to the DataBee console and navigate to the Data > Data Sources tab

A screenshot of a computer  Description automatically generated

  1. Click on Add New Source

A screenshot of a computer  Description automatically generated

  1. Search for Azure Activity and select it

A screenshot of a computer  Description automatically generated

  1. Select API Ingest

  2. Enter basic contact information in the dialog box and click Next

  3. In the detailed configuration boxes, ensure the following fields are filled

    • Authorization Method: OAuth2

    • Client Key: Paste the client key generated in the Microsoft console

    • Secret Key: Paste the client secret generated in the Microsoft console

    • API URL: https://management.azure.com/subscriptions/<subscriptionId>/providers/Microsoft.Insights/eventtypes/management/values?&api-version=2015-04-01

    • Token URL:  https://login.microsoftonline.com/<tenant_id>/oauth2/v2.0/token

Replace the <tenant_id> and <subscriptionId> placeholders with your tenant information

A screenshot of a computer  Description automatically generated

  1. Click Submit


Was this article helpful?

Changing your password will log you out immediately. Use the new password to log back in.
First name must have atleast 2 characters. Numbers and special characters are not allowed.
Last name must have atleast 1 characters. Numbers and special characters are not allowed.
Enter a valid email
Enter a valid password
Your profile has been successfully updated.
ESC

Eddy AI, facilitating knowledge discovery through conversational intelligence