Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Filebeat]Azure module - activity logs #13776

Merged
merged 24 commits into from
Oct 10, 2019
Merged
Show file tree
Hide file tree
Changes from 10 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
244 changes: 244 additions & 0 deletions filebeat/docs/fields.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ grouped in the following categories:
* <<exported-fields-apache>>
* <<exported-fields-auditd>>
* <<exported-fields-aws>>
* <<exported-fields-azure>>
* <<exported-fields-beat-common>>
* <<exported-fields-cef>>
* <<exported-fields-cef-module>>
Expand Down Expand Up @@ -1241,6 +1242,249 @@ type: keyword

--

[[exported-fields-azure]]
== azure fields

azure Module



[float]
=== azure




[float]
=== activitylogs

Fields for azure Activity logs.



[float]
=== identity

The canonical user ID of the owner of the source bucket.



*`azure.activitylogs.identity.claims.*`*::
+
--
Claims


type: object

--

[float]
=== authorization

Node allocatable pods



[float]
=== evidence

Node allocatable pods



*`azure.activitylogs.identity.authorization.evidence.roleAssignmentScope`*::
+
--
Role assignment scope


type: keyword

--

*`azure.activitylogs.identity.authorization.evidence.roleDefinitionId`*::
+
--
Role definition ID


type: keyword

--

*`azure.activitylogs.identity.authorization.evidence.role`*::
+
--
Role


type: keyword

--

*`azure.activitylogs.identity.authorization.evidence.roleAssignmentId`*::
+
--
Role assignment ID


type: keyword

--

*`azure.activitylogs.identity.authorization.evidence.principalId`*::
+
--
Principal ID


type: keyword

--

*`azure.activitylogs.identity.authorization.evidence.principalType`*::
+
--
Principal type


type: keyword

--

*`azure.activitylogs.identity.scope`*::
+
--
Scope


type: keyword

--

*`azure.activitylogs.identity.action`*::
+
--
Action


type: keyword

--

*`azure.activitylogs.correlationId`*::
+
--
Correlation ID


type: keyword

--

*`azure.activitylogs.resultType`*::
+
--
Result Type


type: keyword

--

*`azure.activitylogs.callerIpAddress`*::
+
--
Caller Ip address


type: keyword

--

*`azure.activitylogs.resourceID`*::
+
--
Resource ID


type: keyword

--

*`azure.activitylogs.level`*::
+
--
Level


type: keyword

--

*`azure.activitylogs.operationName`*::
+
--
Operation name


type: keyword

--

*`azure.activitylogs.resultSignature`*::
+
--
Result signature


type: keyword

--

*`azure.activitylogs.properties.*`*::
+
--
Properties


type: object

--

*`azure.activitylogs.location`*::
+
--
Location


type: keyword

--

*`azure.activitylogs.category`*::
+
--
Category


type: keyword

--

[float]
=== auditlogs

Fields for azure audit logs.


[float]
=== signinlogs

Fields for azure audit logs.


[[exported-fields-beat-common]]
== Beat fields

Expand Down
62 changes: 62 additions & 0 deletions filebeat/docs/modules/azure.asciidoc
Original file line number Diff line number Diff line change
@@ -0,0 +1,62 @@
////
This file is generated! See scripts/docs_collector.py
////

[[filebeat-module-azure]]
:modulename: azure
:has-dashboards: false

== azure module

beta[]

This is the azure module.

include::../include/what-happens.asciidoc[]

[float]
=== Compatibility

TODO: document with what versions of the software is this tested


include::../include/running-modules.asciidoc[]

[float]
=== Example dashboard

This module comes with a sample dashboard. For example:

TODO: include an image of a sample dashboard. If you do not include a dashboard,
remove this section and set `:has-dashboards: false` at the top of this file.

include::../include/configuring-intro.asciidoc[]

TODO: provide an example configuration

:fileset_ex: {fileset}

include::../include/config-option-intro.asciidoc[]

TODO: document the variables from each fileset. If you're describing a variable
that's common to other modules, you can reuse shared descriptions by including
the relevant file. For example:

[float]
==== `{fileset}` log fileset settings

include::../include/var-paths.asciidoc[]

:has-dashboards!:

:fileset_ex!:

:modulename!:


[float]
=== Fields

For a description of each field in the module, see the
<<exported-fields-azure,exported fields>> section.

2 changes: 2 additions & 0 deletions filebeat/docs/modules_list.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@ This file is generated! See scripts/docs_collector.py
* <<filebeat-module-apache>>
* <<filebeat-module-auditd>>
* <<filebeat-module-aws>>
* <<filebeat-module-azure>>
* <<filebeat-module-cef>>
* <<filebeat-module-cisco>>
* <<filebeat-module-coredns>>
Expand Down Expand Up @@ -44,6 +45,7 @@ include::modules-overview.asciidoc[]
include::modules/apache.asciidoc[]
include::modules/auditd.asciidoc[]
include::modules/aws.asciidoc[]
include::modules/azure.asciidoc[]
include::modules/cef.asciidoc[]
include::modules/cisco.asciidoc[]
include::modules/coredns.asciidoc[]
Expand Down
Loading