mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
feat(audit-log-stream): azure support
This commit is contained in:
@@ -45,6 +45,116 @@ Infisical Audit Log Streaming enables you to transmit your organization's audit
|
||||
## Example Providers
|
||||
|
||||
<AccordionGroup>
|
||||
<Accordion title="Azure">
|
||||
Infisical offers a dedicated **Azure** provider to stream your audit logs, enabling seamless integration with services like Microsoft Sentinel.
|
||||
|
||||
<Warning>
|
||||
After setting up all Azure resources, it may take 10-20 minutes for logs to begin streaming.
|
||||
</Warning>
|
||||
|
||||
<Steps>
|
||||
<Step title="Create a Data Collection Endpoint">
|
||||
Navigate to [Data Collection Endpoints](https://portal.azure.com/#view/HubsExtension/BrowseResource.ReactView/resourceType/microsoft.insights%2Fdatacollectionendpoints) and click **Create**.
|
||||
|
||||

|
||||
|
||||
Configure your Data Collection Endpoint by providing an **Endpoint Name**, **Subscription**, and a **Resource group**. Then click **Review + Create**.
|
||||
|
||||

|
||||
|
||||
After creation, it may take a few minutes for the Data Collection Endpoint to appear. Once visible, click on it and copy the **Logs Ingestion** URL. You will need this URL in later steps.
|
||||
|
||||

|
||||
</Step>
|
||||
<Step title="Create a Log Analytics Workspace">
|
||||
<Info>
|
||||
If you already have a Log Analytics Workspace, you may skip this step.
|
||||
</Info>
|
||||
|
||||
Navigate to [Log Analytics Workspaces](https://portal.azure.com/#browse/Microsoft.OperationalInsights%2Fworkspaces) and click **Create**.
|
||||
|
||||

|
||||
|
||||
Configure your Log Analytics Workspace by providing a **Subscription**, **Resource group**, and a **Name**. Then click **Review + Create**.
|
||||
|
||||

|
||||
|
||||
Once the workspace is deployed, click **Go to resource** to access it.
|
||||
|
||||

|
||||
</Step>
|
||||
<Step title="Create a Custom Log Table">
|
||||
Within your Log Analytics Workspace, navigate to **Tables** and click **Create**. Select **New custom log (DCR-based)** from the dropdown.
|
||||
|
||||

|
||||
|
||||
Configure the Custom Log Table: Provide a **Table name** (e.g., `InfisicalLogs`), select the **Data collection endpoint** created in Step 1, and create a new **Data collection rule** as illustrated in the image below. Then, click **Next**.
|
||||
|
||||

|
||||
|
||||
On the **Schema and transformation** page, you'll be prompted to upload a **Log Sample**. Create a `.json` file with the following content and upload it:
|
||||
|
||||
```json
|
||||
{
|
||||
"id": "00000000-0000-0000-0000-000000000000",
|
||||
"actor": "user",
|
||||
"actorMetadata": {
|
||||
"email": "user@example.com",
|
||||
"userId": "00000000-0000-0000-0000-000000000000",
|
||||
"username": "user@example.com"
|
||||
},
|
||||
"ipAddress": "0.0.0.0",
|
||||
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36",
|
||||
"userAgentType": "web",
|
||||
"eventType": "get-secrets",
|
||||
"eventMetadata": {},
|
||||
"projectName": "MyProject",
|
||||
"orgId": "00000000-0000-0000-0000-000000000000",
|
||||
"projectId": "00000000-0000-0000-0000-000000000000",
|
||||
"TimeGenerated": "2025-01-01T00:00:00.000Z"
|
||||
}
|
||||
```
|
||||
|
||||
Optionally, you can add **Transformations** to further destructure the data. For example, to extract actor email and userId:
|
||||
|
||||
```
|
||||
source
|
||||
| extend
|
||||
ActorEmail = tostring(actorMetadata.email),
|
||||
ActorUserId = tostring(actorMetadata.userId)
|
||||
```
|
||||
|
||||
On the final step, click **Create**.
|
||||
|
||||
<Warning>
|
||||
It may take a few minutes for your Custom Log Table to be created and appear under Tables.
|
||||
</Warning>
|
||||
</Step>
|
||||
<Step title="Obtain Data Collection Rule Immutable ID">
|
||||
After creating your Data Collection Rule, you'll need its **Immutable ID**.
|
||||
|
||||
Navigate to [Data collection rules](https://portal.azure.com/#view/HubsExtension/BrowseResource.ReactView/resourceType/microsoft.insights%2Fdatacollectionrules). Click on your newly created DCR and copy its **Immutable ID** for the next step.
|
||||
|
||||

|
||||
</Step>
|
||||
<Step title="Create Audit Log Stream on Infisical">
|
||||
In Infisical, create a new audit log stream and select the **Azure** provider. Input the following details:
|
||||
|
||||
- **Tenant ID**: Your Tenant ID
|
||||
- **Client ID**: The Client ID of an App Registration
|
||||
- **Client Secret**: The Client Secret of an App Registration
|
||||
- **Data Collection Endpoint URL**: Obtained from Step 1
|
||||
- **Data Collection Rule Immutable ID**: Obtained from Step 4
|
||||
- **Custom Log Table Name**: Defined in Step 3
|
||||
|
||||

|
||||
|
||||
<Warning>
|
||||
The App Registration used for authentication must have the **Monitoring Metrics Publisher** role assigned on the **Data Collection Rule** created in Step 3. [See Microsoft Guide](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/tutorial-logs-ingestion-portal#assign-permissions-to-the-dcr).
|
||||
</Warning>
|
||||
</Step>
|
||||
</Steps>
|
||||
</Accordion>
|
||||
<Accordion title="Better Stack">
|
||||
You can stream to Better Stack using a **Custom** log stream.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user