Mappings: AzureDevOpsAuditing
Input | Value |
---|---|
Vendor | Microsoft |
Product | Azure |
Log Format | JSON |
Event ID Regex Pattern | AzureDevOpsAuditing |
Output | Value |
---|---|
Vendor | Microsoft |
Product | Azure |
Record Type | Audit |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
action | operationName | |
cloud_provider | None | The static text Azure is populated in this schema field. |
cloud_service | properties.loggedByService | |
description | properties.Area | |
resource | resourceId | |
srcDevice_ip | callerIpAddress | |
timestamp | time | We expect the orginal record value of time is in the format yyyy-MM-dd'T'HH:mm:ss.SSSSSSSZ |
user_userId | properties.ActorUserId | |
user_username | properties.ActorUPN |