Azure App Service Pack
This pack includes:
Data normalization capabilities:
- Rules for parsing and modeling Azure App Service Resource Logs that are ingested via the Azure Event Hub data source on Cortex XSIAM.
- When configuring the Azure Event Hub data source, mark the following checkbox under the Enhanced Cloud Protection section:
Use audit logs in analytics
- The ingested Azure app service resource logs can be queried in XQL Search using the
msft_azure_app_service_raw
dataset.
- When configuring the Azure Event Hub data source, mark the following checkbox under the Enhanced Cloud Protection section:
Supported log categories
Category | Category Display Name |
---|---|
AppServiceHTTPLogs | App Service HTTP Logs |
AppServiceConsoleLogs | App Service Console Logs |
AppServiceAppLogs | App Service App Logs |
AppServiceIPSecAuditLogs | App Service IPSec Audit Logs |
AppServicePlatformLogs | App Service Platform Logs |
AppServiceAntivirusScanAuditLogs | App Service Antivirus Scan Audit Logs |
AppServiceFileAuditLogs | App Service File Audit Logs |
FunctionAppLogs | Function App Logs |
AppServiceAuditLogs | App Service Audit Logs |
WorkflowRuntime | Workflow Runtime |
AppServiceEnvironmentPlatformLogs | App Service Environment Platform Logs |