feat(audit-log-stream): azure support

This commit is contained in:
x032205
2025-09-08 23:26:17 -04:00
parent 56ad42a305
commit a2550b1d04
28 changed files with 500 additions and 10 deletions

View File

@@ -45,6 +45,116 @@ Infisical Audit Log Streaming enables you to transmit your organization's audit
## Example Providers
<AccordionGroup>
<Accordion title="Azure">
Infisical offers a dedicated **Azure** provider to stream your audit logs, enabling seamless integration with services like Microsoft Sentinel.
<Warning>
After setting up all Azure resources, it may take 10-20 minutes for logs to begin streaming.
</Warning>
<Steps>
<Step title="Create a Data Collection Endpoint">
Navigate to [Data Collection Endpoints](https://portal.azure.com/#view/HubsExtension/BrowseResource.ReactView/resourceType/microsoft.insights%2Fdatacollectionendpoints) and click **Create**.
![azure create dce](/images/platform/audit-log-streams/azure-create-dce.png)
Configure your Data Collection Endpoint by providing an **Endpoint Name**, **Subscription**, and a **Resource group**. Then click **Review + Create**.
![azure configure dce](/images/platform/audit-log-streams/azure-configure-dce.png)
After creation, it may take a few minutes for the Data Collection Endpoint to appear. Once visible, click on it and copy the **Logs Ingestion** URL. You will need this URL in later steps.
![azure dce url](/images/platform/audit-log-streams/azure-dce-url.png)
</Step>
<Step title="Create a Log Analytics Workspace">
<Info>
If you already have a Log Analytics Workspace, you may skip this step.
</Info>
Navigate to [Log Analytics Workspaces](https://portal.azure.com/#browse/Microsoft.OperationalInsights%2Fworkspaces) and click **Create**.
![azure create law](/images/platform/audit-log-streams/azure-create-law.png)
Configure your Log Analytics Workspace by providing a **Subscription**, **Resource group**, and a **Name**. Then click **Review + Create**.
![azure configure law](/images/platform/audit-log-streams/azure-configure-law.png)
Once the workspace is deployed, click **Go to resource** to access it.
![azure go to resource](/images/platform/audit-log-streams/azure-go-to-resource.png)
</Step>
<Step title="Create a Custom Log Table">
Within your Log Analytics Workspace, navigate to **Tables** and click **Create**. Select **New custom log (DCR-based)** from the dropdown.
![azure new table](/images/platform/audit-log-streams/azure-new-table.png)
Configure the Custom Log Table: Provide a **Table name** (e.g., `InfisicalLogs`), select the **Data collection endpoint** created in Step 1, and create a new **Data collection rule** as illustrated in the image below. Then, click **Next**.
![azure configure table](/images/platform/audit-log-streams/azure-configure-table.png)
On the **Schema and transformation** page, you'll be prompted to upload a **Log Sample**. Create a `.json` file with the following content and upload it:
```json
{
"id": "00000000-0000-0000-0000-000000000000",
"actor": "user",
"actorMetadata": {
"email": "user@example.com",
"userId": "00000000-0000-0000-0000-000000000000",
"username": "user@example.com"
},
"ipAddress": "0.0.0.0",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36",
"userAgentType": "web",
"eventType": "get-secrets",
"eventMetadata": {},
"projectName": "MyProject",
"orgId": "00000000-0000-0000-0000-000000000000",
"projectId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2025-01-01T00:00:00.000Z"
}
```
Optionally, you can add **Transformations** to further destructure the data. For example, to extract actor email and userId:
```
source
| extend
ActorEmail = tostring(actorMetadata.email),
ActorUserId = tostring(actorMetadata.userId)
```
On the final step, click **Create**.
<Warning>
It may take a few minutes for your Custom Log Table to be created and appear under Tables.
</Warning>
</Step>
<Step title="Obtain Data Collection Rule Immutable ID">
After creating your Data Collection Rule, you'll need its **Immutable ID**.
Navigate to [Data collection rules](https://portal.azure.com/#view/HubsExtension/BrowseResource.ReactView/resourceType/microsoft.insights%2Fdatacollectionrules). Click on your newly created DCR and copy its **Immutable ID** for the next step.
![azure dcr](/images/platform/audit-log-streams/azure-dcr.png)
</Step>
<Step title="Create Audit Log Stream on Infisical">
In Infisical, create a new audit log stream and select the **Azure** provider. Input the following details:
- **Tenant ID**: Your Tenant ID
- **Client ID**: The Client ID of an App Registration
- **Client Secret**: The Client Secret of an App Registration
- **Data Collection Endpoint URL**: Obtained from Step 1
- **Data Collection Rule Immutable ID**: Obtained from Step 4
- **Custom Log Table Name**: Defined in Step 3
![azure create als](/images/platform/audit-log-streams/azure-create-als.png)
<Warning>
The App Registration used for authentication must have the **Monitoring Metrics Publisher** role assigned on the **Data Collection Rule** created in Step 3. [See Microsoft Guide](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/tutorial-logs-ingestion-portal#assign-permissions-to-the-dcr).
</Warning>
</Step>
</Steps>
</Accordion>
<Accordion title="Better Stack">
You can stream to Better Stack using a **Custom** log stream.