|
1 | 1 | name: Azure Active Directory Add owner to application
|
2 | 2 | id: e895ed56-7be4-4b3a-b782-ecd0f594ec4c
|
3 | 3 | version: 1
|
4 |
| -date: '2024-07-18' |
| 4 | +date: "2024-07-18" |
5 | 5 | author: Patrick Bareiss, Splunk
|
6 | 6 | description: Data source object for Azure Active Directory Add owner to application
|
7 | 7 | source: Azure AD
|
8 | 8 | sourcetype: azure:monitor:aad
|
9 | 9 | separator: operationName
|
10 | 10 | supported_TA:
|
11 |
| -- name: Splunk Add-on for Microsoft Cloud Services |
12 |
| - url: https://splunkbase.splunk.com/app/3110 |
13 |
| - version: 5.4.2 |
| 11 | + - name: Splunk Add-on for Microsoft Cloud Services |
| 12 | + url: https://splunkbase.splunk.com/app/3110 |
| 13 | + version: 5.4.3 |
14 | 14 | fields:
|
15 |
| -- _time |
16 |
| -- Level |
17 |
| -- callerIpAddress |
18 |
| -- category |
19 |
| -- correlationId |
20 |
| -- date_hour |
21 |
| -- date_mday |
22 |
| -- date_minute |
23 |
| -- date_month |
24 |
| -- date_second |
25 |
| -- date_wday |
26 |
| -- date_year |
27 |
| -- date_zone |
28 |
| -- durationMs |
29 |
| -- eventtype |
30 |
| -- host |
31 |
| -- index |
32 |
| -- linecount |
33 |
| -- operationName |
34 |
| -- operationVersion |
35 |
| -- properties.activityDateTime |
36 |
| -- properties.activityDisplayName |
37 |
| -- properties.additionalDetails{}.key |
38 |
| -- properties.additionalDetails{}.value |
39 |
| -- properties.category |
40 |
| -- properties.correlationId |
41 |
| -- properties.id |
42 |
| -- properties.initiatedBy.user.displayName |
43 |
| -- properties.initiatedBy.user.id |
44 |
| -- properties.initiatedBy.user.ipAddress |
45 |
| -- properties.initiatedBy.user.userPrincipalName |
46 |
| -- properties.loggedByService |
47 |
| -- properties.operationType |
48 |
| -- properties.result |
49 |
| -- properties.resultReason |
50 |
| -- properties.targetResources{}.displayName |
51 |
| -- properties.targetResources{}.id |
52 |
| -- properties.targetResources{}.modifiedProperties{}.displayName |
53 |
| -- properties.targetResources{}.modifiedProperties{}.newValue |
54 |
| -- properties.targetResources{}.modifiedProperties{}.oldValue |
55 |
| -- properties.targetResources{}.type |
56 |
| -- properties.targetResources{}.userPrincipalName |
57 |
| -- properties.userAgent |
58 |
| -- punct |
59 |
| -- resourceId |
60 |
| -- resultSignature |
61 |
| -- source |
62 |
| -- sourcetype |
63 |
| -- splunk_server |
64 |
| -- tag |
65 |
| -- tag::eventtype |
66 |
| -- tenantId |
67 |
| -- time |
68 |
| -- timeendpos |
69 |
| -- timestartpos |
70 |
| -example_log: '{"time": "2023-06-20T15:54:13.2420879Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam", |
| 15 | + - _time |
| 16 | + - Level |
| 17 | + - callerIpAddress |
| 18 | + - category |
| 19 | + - correlationId |
| 20 | + - date_hour |
| 21 | + - date_mday |
| 22 | + - date_minute |
| 23 | + - date_month |
| 24 | + - date_second |
| 25 | + - date_wday |
| 26 | + - date_year |
| 27 | + - date_zone |
| 28 | + - durationMs |
| 29 | + - eventtype |
| 30 | + - host |
| 31 | + - index |
| 32 | + - linecount |
| 33 | + - operationName |
| 34 | + - operationVersion |
| 35 | + - properties.activityDateTime |
| 36 | + - properties.activityDisplayName |
| 37 | + - properties.additionalDetails{}.key |
| 38 | + - properties.additionalDetails{}.value |
| 39 | + - properties.category |
| 40 | + - properties.correlationId |
| 41 | + - properties.id |
| 42 | + - properties.initiatedBy.user.displayName |
| 43 | + - properties.initiatedBy.user.id |
| 44 | + - properties.initiatedBy.user.ipAddress |
| 45 | + - properties.initiatedBy.user.userPrincipalName |
| 46 | + - properties.loggedByService |
| 47 | + - properties.operationType |
| 48 | + - properties.result |
| 49 | + - properties.resultReason |
| 50 | + - properties.targetResources{}.displayName |
| 51 | + - properties.targetResources{}.id |
| 52 | + - properties.targetResources{}.modifiedProperties{}.displayName |
| 53 | + - properties.targetResources{}.modifiedProperties{}.newValue |
| 54 | + - properties.targetResources{}.modifiedProperties{}.oldValue |
| 55 | + - properties.targetResources{}.type |
| 56 | + - properties.targetResources{}.userPrincipalName |
| 57 | + - properties.userAgent |
| 58 | + - punct |
| 59 | + - resourceId |
| 60 | + - resultSignature |
| 61 | + - source |
| 62 | + - sourcetype |
| 63 | + - splunk_server |
| 64 | + - tag |
| 65 | + - tag::eventtype |
| 66 | + - tenantId |
| 67 | + - time |
| 68 | + - timeendpos |
| 69 | + - timestartpos |
| 70 | +example_log: |
| 71 | + '{"time": "2023-06-20T15:54:13.2420879Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam", |
71 | 72 | "operationName": "Add owner to application", "operationVersion": "1.0", "category":
|
72 | 73 | "AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
|
73 | 74 | "None", "durationMs": 0, "callerIpAddress": "20.190.135.43", "correlationId": "231de5d4-2156-433a-8163-48956bdaa040",
|
|
0 commit comments