Cloud platforms
Questions about AWS, Azure, and Google Cloud Platform.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Azure Activity Logs: mapping entities for Davis Events

michiel_otten
Champion

I’m currently ingesting Azure Activity Logs through the native Azure integration into the platform. The logs are arriving correctly, but I’m trying to trigger events based on entities such as azure.subscription.

The challenge I’m running into is within OpenPipeline: I can’t seem to find or map a valid dt.source_entity value from the incoming Azure Activity logs. Currently my Davis Events all trigger against the environment.

What I’m trying to achieve is something along the lines of:

  • Azure Activity Log arrives
  • Extract/map the Azure Subscription entity
  • Trigger events/workflows against that entity

Has anyone successfully implemented this mapping before?
If so:

  • Which field did you map to dt.source_entity? (if possible)
  • Are there any best practices for Azure Activity Log entity enrichment?

Any examples or guidance would be appreciated. Thanks!

#Performance matter!
0 REPLIES 0

Featured Posts