azure-monitor-activity-log-event

Activity Log records contain caller claims, resource identifiers, operation details, and user-controlled status properties.

azurehigh service: azure:monitor emits CanReadData

Where it sits

locationAzure Monitor Activity Log event.{caller,claims,authorization,properties,httpRequest,resourceId,status}
location kindlog_field
data kindscredential oauth_token sensitive_data pii
emits edgeCanReadData
serviceAzure Monitor / Activity Log (azure:monitor)

Collection recipe

access moderead_api
operationActivity Logs - List
response pathvalue[]
encodingjson
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

Microsoft.Insights/eventtypes/values/read

References

move · open · esc close