-
Notifications
You must be signed in to change notification settings - Fork 562
[New Data] Azure Graph Activity Logs #8555
Copy link
Copy link
Closed
Labels
New IntegrationIssue or pull request for creating a new integration package.Issue or pull request for creating a new integration package.Team:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]
Metadata
Metadata
Assignees
Labels
New IntegrationIssue or pull request for creating a new integration package.Issue or pull request for creating a new integration package.Team:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]
Type
Fields
Give feedbackNo fields configured for issues without a type.
Request
Please update the Azure audit logs to collect the Azure Graph Activity logs. These activity logs provide security focused users with detailed activity of users and accounts within Azure.
https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/microsoft-graph-activity-log-is-now-available-in-public-preview/ba-p/3848269
The Infosec team has access to the activity logs but at this time the Azure integration does not collect them. https://github.com/elastic/seceng/issues/6163