Skip to content

Filebeat module azure activitylogs does not populate azure.subscription.id on MICROSOFT.SECURITY/SECURITYCONTACTS/WRITE event #24392

@tehho

Description

@tehho

For confirmed bugs, please report:

  • Version: 7.11.1
  • Operating System: Docker
  • Discuss Forum URL: N/A
  • Steps to Reproduce:
  1. Setup a filebeat azure activitylog to a eventhub
  2. Change the contact email of the subscription.
  3. Note no log of subscription id in logs

Suggested fix:
Add grok to azure module to always try to get subscription id here https://github.com/elastic/beats/blob/master/x-pack/filebeat/module/azure/azure-shared-pipeline.yml.

Great product 👍

Metadata

Metadata

Assignees

Labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions