mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
18 lines
866 B
YAML
18 lines
866 B
YAML
name: Azure Audit
|
|
id: 62e2f93e-4e9c-4d38-bb2c-6d59c4565318
|
|
author: Patrick Bareiss, Splunk
|
|
source: mscs:azure:audit
|
|
sourcetype: mscs:azure:audit
|
|
separator: operationName.localizedValue
|
|
supported_TA:
|
|
name: Splunk Add-on for Microsoft Cloud Services
|
|
version: 5.2.2
|
|
url: https://splunkbase.splunk.com/app/3110
|
|
event_names:
|
|
- event_name: Azure Audit Create or Update an Azure Automation Runbook
|
|
data_source: data_sources/cloud/event_sources/Azure_Audit_Create_or_Update_an_Azure_Automation_Runbook.yml
|
|
- event_name: Azure Audit Create or Update an Azure Automation account
|
|
data_source: data_sources/cloud/event_sources/Azure_Audit_Create_or_Update_an_Azure_Automation_account.yml
|
|
- event_name: Azure Audit Create or Update an Azure Automation webhook
|
|
data_source: data_sources/cloud/event_sources/Azure_Audit_Create_or_Update_an_Azure_Automation_webhook.yml
|