Microsoft Azure Activity Logs
You can integrate Microsoft Azure Activity Logs with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
Azure Activity Logs product overview
The Microsoft Azure Activity Log is an Azure Monitor platform log that provides insight into subscription-level and management-group-level control-plane events in Azure. It records management operations such as creating, modifying, or deleting resources through Azure Resource Manager, along with role-based access control changes, service health notifications, and related platform events.
What we ingest
Sophos XDR collects the Azure Activity Log. The log can be delivered through Azure Event Hubs (the preferred path, for the fastest and highest throughput) or collected through the Azure Monitor REST API on a schedule. The following log categories are collected:
- Administrative: Create, update, delete, and action operations on resources, and role-based access control changes.
- Security: Security-related activity log events.
- Service and resource health: ServiceHealth and ResourceHealth notifications.
- Policy and operations: Policy, Recommendation, Alert, and Autoscale events.
Event and data types
We ingest the following event and data types from Azure Activity Logs:
- Activity log events: Control-plane operations across the Administrative, ServiceHealth, ResourceHealth, Alert, Recommendation, Policy, and Autoscale categories, including the operation, resource, caller, and result. Normalized to cloud audit telemetry.
- Security events: Activity log events in the Security category. Normalized to third-party security alert telemetry.
Data provided by this integration
Data provided by Azure Activity Logs gets normalized to the following schemas:
cloudauditthirdpartyalert
For more information about using schemas in Data Lake Search, see Schemas and logical types.