Azure App Service Pack
This pack includes
Data normalization capabilities:
- Rules for parsing and modeling Azure App Service Resource Logs that are ingested via the Azure Event Hub data source on Cortex XSIAM.
- When configuring the Azure Event Hub data source, mark the following checkbox under the Enhanced Cloud Protection section:
Use audit logs in analytics- The ingested Azure app service resource logs can be queried in XQL Search using the
msft_azure_app_service_rawdataset.
Supported log categories
| Category | Category Display Name |
|---|---|
| AppServiceHTTPLogs | App Service HTTP Logs |
| AppServiceConsoleLogs | App Service Console Logs |
| AppServiceAppLogs | App Service App Logs |
| AppServiceIPSecAuditLogs | App Service IPSec Audit Logs |
| AppServicePlatformLogs | App Service Platform Logs |
| AppServiceAntivirusScanAuditLogs | App Service Antivirus Scan Audit Logs |
| AppServiceFileAuditLogs | App Service File Audit Logs |
| FunctionAppLogs | Function App Logs |
| AppServiceAuditLogs | App Service Audit Logs |
| WorkflowRuntime | Workflow Runtime |
| AppServiceEnvironmentPlatformLogs | App Service Environment Platform Logs |
