Skip to main content

CollectorsCloud Collectors Administration Guide

Azure Supported Sources via Event Hub

Verify the KQL query via Azure ALA UI. Do not restrict the KQL query to a certain time frame because the time frame is automatically added to the query suffix for each sync that the connector performs.

The following table displays audit source API and security events supported by the Azure Event Hub Cloud Collector for each service.

Service/ Module Covered

Supported Event Types

Notes

To forward the Azure Monitor events to an EventHub which will then be used by Azure Event Hub Cloud Collector to collect the events, see https://docs.microsoft.com/en-us/azure/azure-monitor/overview.

The following data is collected by the Azure monitor:

  • Application monitoring data: Data about the performance and functionality of the code you have written, regardless of its platform.

  • Guest OS monitoring data: Data about the operating system on which your application is running. This could be running in Azure, another cloud, or on-premises.

  • Azure resource monitoring data: Data about the operation of an Azure resource.

  • Azure subscription monitoring data: Data about the operation and management of an Azure subscription, as well as data about the health and operation of Azure itself.

  • Azure tenant monitoring data: Data about the operation of tenant-level Azure services, such as Azure Active Directory.

  • Web Application Firewall

For more information on the events collected by the Azure Monitor, see: https://learn.microsoft.com/en-us/azure/azure-monitor/overview#data-sources

Subscription Monitoring

Included as part of the Azure Monitor data collected (see above)

IIS

Included as part of the Azure Monitor data collected (see above)

See: https://docs.microsoft.com/en-us/azure/azure-monitor/platform/data-sources-iis-logs

Azure SQL DB

SQL DB events

See: https://docs.microsoft.com/en-us/azure/sql-database/sql-database-auditing

Web Application Firewall (WAF)

Included as part of the Azure Monitor data collected (see above)

For more information on the WAF data collected, see https://learn.microsoft.com/en-us/azure/web-application-firewall/ag/ag-overview#monitoring