You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/reports-monitoring/concept-activity-logs-azure-monitor.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -24,7 +24,7 @@ With these integrations, you can enable rich visualizations, monitoring, and ale
24
24
The following logs can be integrated with one of many endpoints:
25
25
26
26
* The [**audit logs activity report**](concept-audit-logs.md) gives you access to the history of every task that's performed in your tenant.
27
-
* With the [**sign-in activity report**](concept-sign-ins.md), you can determine who performed the tasks that are reported in the audit logs.
27
+
* With the [**sign-in activity report**](concept-sign-ins.md), you can see when users attempt to sign in to your applications or troubleshoot sign-in errors.
28
28
* With the [**provisioning logs**](../app-provisioning/application-provisioning-log-analytics.md), you can monitor which users have been created, updated, and deleted in all your third-party applications.
29
29
* The [**risky users logs**](../identity-protection/howto-identity-protection-investigate-risk.md#risky-users) helps you monitor changes in user risk level and remediation activity.
30
30
* With the [**risk detections logs**](../identity-protection/howto-identity-protection-investigate-risk.md#risk-detections), you can monitor user's risk detections and analyze trends in risk activity detected in your organization.
@@ -61,7 +61,7 @@ If you don't plan on using a third-party SIEM tool, we recommend sending your Az
61
61
62
62
There's a cost for sending data to a Log Analytics workspace, archiving data in a storage account, or streaming logs to an event hub. The amount of data and the cost incurred can vary significantly depending on the tenant size, the number of policies in use, and even the time of day.
63
63
64
-
Because the size and cost for sending logs to and endpoint is difficult to predict, the most accurate way to determine your expected costs is to route your logs to and endpoint for day or two. With this snapshot, you can get an accurate prediction for your expected costs.
64
+
Because the size and cost for sending logs to an endpoint is difficult to predict, the most accurate way to determine your expected costs is to route your logs to an endpoint for day or two. With this snapshot, you can get an accurate prediction for your expected costs.
65
65
66
66
Other considerations for sending Azure AD logs to Azure Monitor are covered in the following Azure Monitor cost details articles:
Copy file name to clipboardExpand all lines: articles/active-directory/reports-monitoring/reports-faq.yml
+24-3Lines changed: 24 additions & 3 deletions
Original file line number
Diff line number
Diff line change
@@ -44,10 +44,25 @@ sections:
44
44
- name: Activity logs
45
45
questions:
46
46
- question: |
47
-
Do I need to be a Global Administrator to see the activity logs in the Azure portal or to get data through the API?
47
+
Do I need to be a Global Administrator to see the activity logs in the Azure portal?
48
48
answer: |
49
-
No, the [least privilege role](../roles/delegate-by-task.md) to view audit and sign-in logs is **Reports Reader**. Other roles include **Security Reader** and **Security Administrator** for the tenant. You can also access the reporting data through the portal or through the API if you're a Global Administrator.
50
-
49
+
No, the [least privilege role](../roles/delegate-by-task.md) to view audit and sign-in logs is **Reports Reader**. Other roles include **Security Reader** and **Security Administrator**.
50
+
51
+
- question: |
52
+
What logs can I integrate with Azure Monitor?
53
+
answer: |
54
+
Sign-in and audit logs are both available for routing through Azure Monitor. B2C-related audit events are currently not included. For more information, see [Azure AD activity log integrations](concept-activity-logs-azure-monitor.md) and the [Graph API activity log overview](/graph/api/resources/azure-ad-auditlog-overview)
55
+
56
+
- question: |
57
+
What SIEM tools are currently supported for integrating Azure AD activity logs?
58
+
answer: |
59
+
For a current list of the supported SIEM tools, see [Stream Azure monitoring data to an event hub for consumption by an external tool](../azure-monitor/essentials/stream-monitoring-data-event-hubs.md).
60
+
61
+
- question: |
62
+
Can I access the data from an event hub without using an external SIEM tool?
63
+
answer: |
64
+
Yes. To access the logs from your custom application, you can use the [Event Hubs API](../../event-hubs/event-hubs-dotnet-standard-getstarted-send.md).
65
+
51
66
- question: |
52
67
Can I get Microsoft 365 activity log information through the Azure portal?
53
68
answer: |
@@ -67,6 +82,12 @@ sections:
67
82
How long does Azure AD store activity logs? What is the data retention?
68
83
answer: |
69
84
Depending on your license, Azure AD stores activity logs for between 7 and 30 days. For more information, see [Azure Active Directory report retention policies](reference-reports-data-retention.md).
85
+
86
+
- question: |
87
+
What happens if an Administrator changes the retention period of a diagnostic setting?
88
+
answer: |
89
+
The new retention policy will be applied to logs collected after the change. Logs collected before the policy change will be unaffected. The Diagnostic settings storage retention feature is being deprecated. For details on this change, see [**Migrate from diagnostic settings storage retention to Azure Storage lifecycle management**](../../azure-monitor/essentials/migrate-to-azure-storage-lifecycle-policy.md).
90
+
70
91
- question: |
71
92
How can I find out if a user purchased a license or enabled a trial license for my tenant? I don't see this activity in the audit logs.
0 commit comments