Change log for AZURE_AD_AUDIT

Date Changes
2026-03-06 Enhancement:
- event.idm.read_only_udm.security_result.detection_fields: Newly mapped properties.authenticationAppDeviceDetails.operatingSystem (key: authenticationAppDeviceDetails_operatingSystem), properties.authenticationAppDeviceDetails.deviceId (key: authenticationAppDeviceDetails_deviceId), properties.authenticationAppDeviceDetails.clientApp (key: authenticationAppDeviceDetails_clientApp), properties.authenticationAppDeviceDetails.appVersion (key: authenticationAppDeviceDetails_appVersion) raw log fields with event.idm.read_only_udm.security_result.detection_fields UDM field.
- event.idm.read_only_udm.security_result.detection_fields: Newly mapped adminConfiguration (key: authAppPolicy_adminConfiguration_%{index}), authenticationEvaluation (key: authAppPolicy_authenticationEvaluation_%{index}), status (key: authAppPolicy_status_%{index}), policyName (key: authAppPolicy_policyName_%{index}) raw log fields from the properties.authenticationAppPolicyEvaluationDetails array with event.idm.read_only_udm.security_result.detection_fields UDM field.
- event.idm.read_only_udm.security_result.detection_fields: Newly mapped expirationRequirement (key: sessionLifetimePolicy_expirationRequirement_%{index}), detail (key: sessionLifetimePolicy_detail_%{index}) raw log fields from the properties.sessionLifetimePolicies array with event.idm.read_only_udm.security_result.detection_fields UDM field.
- event.idm.read_only_udm.security_result.detection_fields: Newly mapped id (key: auth_id_%{index}), detail (key: auth_detail_%{index}) raw log fields from the properties.authenticationContextClassReferences array with event.idm.read_only_udm.security_result.detection_fields UDM field.
- event.idm.read_only_udm.security_result.detection_fields: Newly mapped displayName (key: policy_displayName_%{index}), conditionsSatisfied (key: policy_conditionsSatisfied_%{index}), result (key: policy_result_%{index}), enforcedGrantControls (key: enforcedGrantControls_%{index}_%{i}), enforcedSessionControls (key: enforcedSessionControls_%{index}_%{i}), conditionsNotSatisfied (key: policy_conditionsNotSatisfied_%{index}), id (key: policy_id_%{index}) raw log fields from the properties.appliedConditionalAccessPolicies array with event.idm.read_only_udm.security_result.detection_fields UDM field.
- event.idm.read_only_udm.security_result.detection_fields: Newly mapped properties.riskLevelAggregated raw log field with event.idm.read_only_udm.security_result.detection_fields UDM field.
- event.idm.read_only_udm.additional.fields: Newly mapped properties.isThroughGlobalSecureAccess , properties.tokenProtectionStatusDetails.signInSessionStatus, properties.operationType raw log fields with event.idm.read_only_udm.additional.fields UDM field.
- event.idm.read_only_udm.principal.resource.attribute.labels: Newly mapped properties.initiatedBy.app.appId (key: App Id) raw log field with event.idm.read_only_udm.principal.resource.attribute.labels UDM field.
- Added a grok pattern to parse the new format of SYSLOG+JSON raw logs.
2026-03-03 Enhancement:
- event.idm.read_only_udm.additional.fields: Newly mapped properties.isThroughGlobalSecureAccess (key: isThroughGlobalSecureAccess), properties.signInIdentifierType (key: signInIdentifierType), properties.processingTimeInMilliseconds (key: processingTimeInMilliseconds), @version (key: prop_log_version), properties.isInteractive (key: properties_isInteractive), properties.appDisplayName (key: appDisplayName), name (key: event_name), properties.isTenantRestricted (key: isTenantRestricted), properties.agent.agentType (key: agentType), properties.agent.agentSubjectType (key: agentSubjectType), properties.mfaDetail.authMethod (key: prop_mfa_auth_method), properties.tokenProtectionStatusDetails.signinSessionStatus (key: signinSessionStatus), properties.tokenProtectionStatusDetails.signInSessionStatusCode (key: sign_in_session_status_code), properties.mfaDetail.authDetail (key: mfaAuthDetail) raw log fields with event.idm.read_only_udm.additional.fields UDM field.
- event.idm.read_only_udm.principal.resource.attribute.labels: Newly mapped properties.clientAppUsed (key: clientAppType) raw log field with event.idm.read_only_udm.principal.resource.attribute.labels UDM field.
- event.idm.read_only_udm.target.resource.attribute.labels: Newly mapped properties.appId (key: appId) raw log field with event.idm.read_only_udm.target.resource.attribute.labels UDM field.
- event.idm.read_only_udm.principal.asset.attribute.labels: Newly mapped properties.deviceDetail.isManaged (key: isManaged), properties.deviceDetail.isCompliant (key: isCompliant) raw log fields with event.idm.read_only_udm.principal.asset.attribute.labels UDM field.
- event.idm.read_only_udm.security_result.detection_fields: Newly mapped authenticationdetails.StatusSequence (key: statusSequence), authenticationdetails.authenticationMethodDetail (key: authenticationMethodDetail), authenticationdetails.RequestSequence (key: requestSequence), networkLocation.networkType (key: networkType), networkLocation.networkNames (key: networkName), authenticationRequirementPolicy.requirementProvider (key: requirementProvider), authenticationRequirementPolicy.detail (key: detail) raw log fields with event.idm.read_only_udm.security_result.detection_fields UDM field.
- event.idm.read_only_udm.target.resource.product_object_id: Newly mapped properties.resourceId raw log field with event.idm.read_only_udm.target.resource.product_object_id UDM field.
- event.idm.read_only_udm.target.user.userid: Newly mapped properties.signInIdentifier, properties.userPrincipalName, properties.alternateSignInName raw log fields with event.idm.read_only_udm.target.user.userid UDM field.
- event.idm.read_only_udm.security_result.description: Newly mapped properties.status.additionalDetails raw log field with event.idm.read_only_udm.security_result.description UDM field.
- event.idm.read_only_udm.principal.location.country_or_region: Newly mapped properties.location.countryOrRegion raw log field with event.idm.read_only_udm.principal.location.country_or_region UDM field.
- event.idm.read_only_udm.principal.location.city: Newly mapped properties.location.city raw log field with event.idm.read_only_udm.principal.location.city UDM field.
- event.idm.read_only_udm.principal.location.state: Newly mapped properties.location.state raw log field with event.idm.read_only_udm.principal.location.state UDM field.
- event.idm.read_only_udm.principal.location.region_latitude: Newly mapped properties.location.geoCoordinates.latitude raw log field with event.idm.read_only_udm.principal.location.region_latitude UDM field.
- event.idm.read_only_udm.principal.location.region_longitude: Newly mapped properties.location.geoCoordinates.longitude raw log field with event.idm.read_only_udm.principal.location.region_longitude UDM field.
- event.idm.read_only_udm.security_result.threat_name: Newly mapped properties.riskDetail raw log field with event.idm.read_only_udm.security_result.threat_name UDM field.
- event.idm.read_only_udm.metadata.collected_timestamp: Newly mapped logcollector_timestamp raw log field with event.idm.read_only_udm.metadata.collected_timestamp UDM field.
2026-02-20 Enhancement:
- event.idm.read_only_udm.metadata.event_timestamp: Newly mapped properties.activityDateTime and time raw log field(s) with event.idm.read_only_udm.metadata.event_timestamp UDM field.
- event.idm.read_only_udm.principal.user.userid: Newly mapped properties.initiatedBy.Id raw log field with event.idm.read_only_udm.principal.user.userid UDM field.
- event.idm.read_only_udm.principal.user.email_addresses: Newly mapped properties.sourceIdentity.details.UserPrincipalName raw log field with event.idm.read_only_udm.principal.user.email_addresses UDM field.
- event.idm.read_only_udm.principal.user.user_display_name: Newly mapped properties.sourceIdentity.details.DisplayName and properties.sourceIdentity.Name raw log field(s) with event.idm.read_only_udm.principal.user.user_display_name UDM field.
- event.idm.read_only_udm.principal.application: Newly mapped properties.servicePrincipal.Name raw log field with event.idm.read_only_udm.principal.application UDM field.
- event.idm.read_only_udm.principal.asset.product_object_id: Newly mapped properties.sourceSystem.Id raw log field(s) with event.idm.read_only_udm.principal.asset.product_object_id UDM field.
- event.idm.read_only_udm.principal.user.product_object_id: Newly mapped properties.sourceIdentity.Id and properties.sourceIdentity.details.id raw log field(s) with event.idm.read_only_udm.principal.user.product_object_id UDM field.
- event.idm.read_only_udm.principal.user.attribute.roles.name: Newly mapped properties.sourceIdentity.details.odatatype and properties.sourceIdentity.identityType raw log field(s) with event.idm.read_only_udm.principal.user.attribute.roles.name UDM field.
- event.idm.read_only_udm.target.user.product_object_id: Newly mapped properties.targetIdentity.Id raw log field with event.idm.read_only_udm.target.user.product_object_id UDM field.
- event.idm.read_only_udm.target.user.user_display_name: Newly mapped properties.targetIdentity.Name raw log field with event.idm.read_only_udm.target.user.user_display_name UDM field.
- event.idm.read_only_udm.target.user.attribute.roles.name: Newly mapped properties.targetIdentity.identityType raw log field with event.idm.read_only_udm.target.user.attribute.roles.name UDM field.
- event.idm.read_only_udm.target.asset.product_object_id: Newly mapped properties.targetSystem.Id raw log field with event.idm.read_only_udm.target.asset.product_object_id UDM field.
- event.idm.read_only_udm.security_result.summary: Newly mapped properties.provisioningStatusInfo.Status raw log field with event.idm.read_only_udm.security_result.summary UDM field.
- event.idm.read_only_udm.security_result.description: Newly mapped properties.provisioningStatusInfo.errorInformation raw log field with event.idm.read_only_udm.security_result.description UDM field.
- event.idm.read_only_udm.principal.asset.attribute.labels: Newly mapped properties.sourceSystem.Name and properties.servicePrincipal.Id raw log fields with event.idm.read_only_udm.principal.asset.attribute.labels UDM field.
- event.idm.read_only_udm.additional.fields: Newly mapped properties.action with key properties_action, properties.changeId with key changeId, properties.cycleId with key cycleId, properties.jobId with key jobId, properties.initiatedBy.Name with key initiatedBy_Name, properties.initiatedBy.Type with key initiatedBy_Type, properties.provisioningAction with key provisioningAction, and properties.tenantId and tenantId raw log field(s) with key TenantId.
- event.idm.read_only_udm.target.asset.attribute.labels: Newly mapped properties.targetSystem.Name with key targetSystem_Name, properties.targetSystem.details.ApplicationId with key targetSystem_ApplicationId, properties.targetSystem.details.ServicePrincipalDisplayName with key targetSystem_ServicePrincipalDisplayName, and properties.targetSystem.details.ServicePrincipalId raw log field(s) with event.idm.read_only_udm.target.asset.attribute.labels UDM field.
- event.idm.read_only_udm.security_result.detection_fields: Newly mapped properties.statusInfo.Status raw log field with key Status, and resultType raw log field with key resultType with event.idm.read_only_udm.security_result.detection_fields UDM field.
2026-01-29 Enhancement:
- event.idm.read_only_udm.security_result.severity_details: Newly mapped level raw log field with event.idm.read_only_udm.security_result.severity_details UDM field.
- event.idm.read_only_udm.security_result.severity: Newly mapped level raw log field with event.idm.read_only_udm.security_result.severity UDM field.
- event.idm.read_only_udm.additional.fields: Newly mapped properties.initiatedBy.app.agentType, properties.category, properties.correlationId, targetResources.agentType raw log field with event.idm.read_only_udm.additional.fields UDM field.
- event.idm.read_only_udm.intermediary.application: Newly mapped properties.loggedByService raw log field with event.idm.read_only_udm.intermediary.application UDM field.
- event.idm.read_only_udm.security_result.summary: Newly mapped properties.result raw log field with event.idm.read_only_udm.security_result.summary UDM field.
- event.idm.read_only_udm.security_result.action: Newly mapped properties.result raw log field with event.idm.read_only_udm.security_result.action UDM field.
- event.idm.read_only_udm.principal.user.product_object_id: Newly mapped properties.initiatedBy.app.servicePrincipalId raw log field with event.idm.read_only_udm.principal.user.product_object_id UDM field.
- event.idm.read_only_udm.intermediary: Newly mapped intermediary raw log field with event.idm.read_only_udm.intermediary UDM field.
- event.idm.read_only_udm.metadata.product_log_id: Newly mapped properties.id raw log field with event.idm.read_only_udm.metadata.product_log_id UDM field.
- event.idm.read_only_udm.principal.application: Newly mapped properties.initiatedBy.app.displayName raw log field with event.idm.read_only_udm.principal.application UDM field.
- Renamed from properties.targetResources to targetResources.
- Renamed from properties.additionalDetails to additionalDetails.
- Added gsub to replace \event\ with \eventValue\ in the raw message.
2025-12-12 Enhancement:
- Modified conditional check to parse new format of logs.
- event.idm.read_only_udm.security_result.severity: Changed the conditional logic for mapping this field. The previous logic based on the Level raw field is now only applied if event.idm.read_only_udm.security_result.severity_details is empty.
- Modified the timestamp handling to only convert _time if a timestamp has not already been successfully extracted.
- event.idm.read_only_udm.metadata.event_timestamp: Newly mapped ActivityDateTime raw log field to event.idm.read_only_udm.metadata.event_timestamp UDM field only if _time field is empty.
2025-11-27 Enhancement:
- event.idm.read_only_udm.principal.application: Removed mapping of Identity from event.idm.read_only_udm.principal.application UDM field, as this application should be associated with the resource principal.
- event.idm.read_only_udm.principal.resource.attribute.labels: Newly mapped Identity raw log field to event.idm.read_only_udm.principal.resource.attribute.labels UDM field.
- event.idm.read_only_udm.principal.user.user_display_name: Removed mapping of InitiatedBy.app.displayName from event.idm.read_only_udm.principal.user.user_display_name UDM field, as this is a display name it should be associated with the application principal.
- event.idm.read_only_udm.principal.application: Newly mapped InitiatedBy.app.displayName raw log field to event.idm.read_only_udm.principal.application UDM field.
- event.idm.read_only_udm.principal.user.email_addresses: Newly mapped InitiatedBy.user.userPrincipalName raw log field to event.idm.read_only_udm.principal.user.email_addresses UDM field.
- event.idm.read_only_udm.principal.user.user_display_name: Newly mapped InitiatedBy.user.displayName raw log field to event.idm.read_only_udm.principal.user.user_display_name UDM field.
- event.idm.read_only_udm.principal.user.userid: Newly mapped InitiatedBy.user.id raw log field to event.idm.read_only_udm.principal.user.userid UDM field.
- event.idm.read_only_udm.principal.ip: Newly mapped InitiatedBy.user.ipAddress raw log field to event.idm.read_only_udm.principal.ip UDM field.
- event.idm.read_only_udm.principal.asset.ip: Newly mapped InitiatedBy.user.ipAddress raw log field to event.idm.read_only_udm.principal.asset.ip UDM field.
2025-11-20 Enhancement:
- event.idm.read_only_udm.target.user.user_display_name: Newly mapped properties.TargetDisplayNames.0 raw log field. with event.idm.read_only_udm.target.user.user_display_name.
- event.idm.read_only_udm.target.resource.product_object_id: Newly mapped properties.TargetObjectIds.0 raw log field with event.idm.read_only_udm.target.resource.product_object_id.
- event.idm.read_only_udm.principal.application: Newly mapped properties.Actor.ApplicationName raw log field with event.idm.read_only_udm.principal.application.
- event.idm.read_only_udm.principal.resource.product_object_id: Newly mapped properties.Actor.Application raw log field with event.idm.read_only_udm.principal.resource.product_object_id.
- event.idm.read_only_udm.principal.user.product_object_id: Newly mapped properties.Actor.ObjectId raw log field with event.idm.read_only_udm.principal.user.product_object_id.
- event.idm.read_only_udm.principal.user.email_addresses: Newly mapped properties.Actor.UPN raw log field with event.idm.read_only_udm.principal.user.email_addresses.
- event.idm.read_only_udm.metadata.product_log_id: Newly mapped properties.AuditEventId raw log field with event.idm.read_only_udm.metadata.product_log_id.
- event.idm.read_only_udm.metadata.description: Newly mapped resultDescription raw log field with event.idm.read_only_udm.metadata.description.
- event.idm.read_only_udm.additional.fields: Newly mapped properties.CorrelationId,properties.RelationId,properties.Category,properties.AdditionalDetails,properties.ActivityType,properties.ActivityResultStatus,properties.ActivityDate,identity raw log field with event.idm.read_only_udm.additional.fields.
- event.idm.read_only_udm.security_result.action_details: Newly mapped resultType raw log field with event.idm.read_only_udm.security_result.action_details.
- event.idm.read_only_udm.principal.resource.attribute.labels: Newly mapped properties.Actor.PartnerTenantId,properties.Actor.Name,properties.Actor.IsDelegatedAdmin raw log field with event.idm.read_only_udm.principal.resource.attribute.labels.
- event.idm.read_only_udm.metadata.event_type: When has_target_resource is true then set event.idm.read_only_udm.metadata.event_type to USER_RESOURCE_ACCESS.
2025-11-05 Enhancement:
- Set event.idm.read_only_udm.metadata.event_type to USER_UNCATEGORIZED when principal_userid_present is true.
- Added support for JSON format wrapped in cribl_data.original_message field.
- event.idm.read_only_udm.metadata.event_timestamp: Newly mapped _time raw log field to event.idm.read_only_udm.metadata.event_timestamp UDM field.
- event.idm.read_only_udm.security_result.summary: Newly mapped AADOperationType raw log field to event.idm.read_only_udm.security_result.summary UDM field.
- event.idm.read_only_udm.metadata.product_deployment_id: Newly mapped AADTenantId raw log field to event.idm.read_only_udm.metadata.product_deployment_id UDM field.
- event.idm.read_only_udm.metadata.collected_timestamp: Newly mapped ActivityDateTime raw log field to event.idm.read_only_udm.metadata.collected_timestamp UDM field.
- event.idm.read_only_udm.security_result.category_details: Newly mapped Category raw log field to event.idm.read_only_udm.security_result.category_details UDM field.
- event.idm.read_only_udm.principal.user.product_object_id: Newly mapped CorrelationId raw log field to event.idm.read_only_udm.principal.user.product_object_id UDM field.
- event.idm.read_only_udm.metadata.product_log_id: Newly mapped Id raw log field to event.idm.read_only_udm.metadata.product_log_id UDM field.
- event.idm.read_only_udm.principal.application: Newly mapped Identity raw log field to event.idm.read_only_udm.principal.application UDM field.
- event.idm.read_only_udm.principal.user.user_display_name: Newly mapped InitiatedBy.app.displayName raw log field to event.idm.read_only_udm.principal.user.user_display_name UDM field.
- event.idm.read_only_udm.principal.user.userid: Newly mapped InitiatedBy.app.servicePrincipalId raw log field to event.idm.read_only_udm.principal.user.userid UDM field.
- event.idm.read_only_udm.security_result.severity: Newly mapped Level raw log field to event.idm.read_only_udm.security_result.severity UDM field.
- event.idm.read_only_udm.metadata.product_event_type: Newly mapped OperationName raw log field to event.idm.read_only_udm.metadata.product_event_type UDM field.
- event.idm.read_only_udm.metadata.product_version: Newly mapped OperationVersion raw log field to event.idm.read_only_udm.metadata.product_version UDM field.
- event.idm.read_only_udm.principal.resource.name: Newly mapped Resource raw log field to event.idm.read_only_udm.principal.resource.name UDM field.
- event.idm.read_only_udm.principal.resource.product_object_id: Newly mapped ResourceId raw log field to event.idm.read_only_udm.principal.resource.product_object_id UDM field.
- event.idm.read_only_udm.target.user.userid: Newly mapped TargetResources.id raw log field to event.idm.read_only_udm.target.user.userid UDM field.
- event.idm.read_only_udm.target.user.user_display_name: Newly mapped TargetResources.displayName raw log field to event.idm.read_only_udm.target.user.user_display_name UDM field.
- event.idm.read_only_udm.target.resource.type: Newly mapped TargetResources.type raw log field to event.idm.read_only_udm.target.resource.type UDM field.
- event.idm.read_only_udm.target.resource.attribute.labels: Newly mapped TargetResources.modifiedProperties.displayName and TargetResources.modifiedProperties.newValue raw log field to event.idm.read_only_udm.target.resource.attribute.labels UDM field.
- event.idm.read_only_udm.principal.resource.attribute.labels: Newly mapped ResourceGroup and TenantId raw log field to event.idm.read_only_udm.principal.resource.attribute.labels UDM field.
- event.idm.read_only_udm.security_result.description: Newly mapped Result raw log field to event.idm.read_only_udm.security_result.description UDM field.
- event.idm.read_only_udm.security_result.action: Newly mapped Result raw log field to event.idm.read_only_udm.security_result.action UDM field.
- event.idm.read_only_udm.principal.resource.type: Newly mapped Type raw log field to event.idm.read_only_udm.principal.resource.type UDM field.
- event.idm.read_only_udm.security_result.first_discovered_time: Newly mapped TimeGenerated raw log field to event.idm.read_only_udm.security_result.first_discovered_time UDM field.
- event.idm.read_only_udm.security_result.last_discovered_time: Newly mapped _TimeReceived raw log field to event.idm.read_only_udm.security_result.last_discovered_time UDM field.
- event.idm.read_only_udm.security_result.detection_fields: Newly mapped cribl_pipe, cribl_data.cribl_enrichment.cribl_source, cribl_data.cribl_enrichment.topic_name, SourceSystem and _Internal_WorkspaceResourceId raw log field to event.idm.read_only_udm.security_result.detection_fields UDM field.
- event.idm.read_only_udm.additional.fields: Newly mapped DurationMs, LoggedByService, ResultSignature, _ItemId and AdditionalDetails raw log field to event.idm.read_only_udm.additional.fields UDM field.
- event.idm.read_only_udm.metadata.description: Newly mapped ActivityDisplayName raw log field to event.idm.read_only_udm.metadata.description UDM field.
2025-11-03 Enhancement:
- Added a grok pattern on client_ip field to validate if it's a valid IP address before merging it into event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip.
2025-10-08 Enhancement:
- event.idm.read_only_udm.metadata.event_timestamp: Newly mapped record.time raw log field to event.idm.read_only_udm.metadata.event_timestamp.
- event.idm.read_only_udm.metadata.product_event_type: Newly mapped record.operationName raw log field to event.idm.read_only_udm.metadata.product_event_type.
- event.idm.read_only_udm.metadata.description: Newly mapped record.properties.message raw log field to event.idm.read_only_udm.metadata.description.
- event.idm.read_only_udm.principal.location.name: Newly mapped record.RoleLocation raw log field to event.idm.read_only_udm.principal.location.name.
- event.idm.read_only_udm.principal.ip: Newly mapped record.callerIpAddress raw log field to event.idm.read_only_udm.principal.ip.
- event.idm.read_only_udm.principal.asset.ip: Newly mapped record.callerIpAddress raw log field to event.idm.read_only_udm.principal.asset.ip.
- event.idm.read_only_udm.principal.user.userid: Newly mapped record.identity.authorization.evidence.principalId raw log field to event.idm.read_only_udm.principal.user.userid.
- event.idm.read_only_udm.principal.resource.resource_subtype: Newly mapped record.identity.authorization.evidence.principalType raw log field to event.idm.read_only_udm.principal.resource.resource_subtype.
- event.idm.read_only_udm.principal.user.attribute.roles.name: Newly mapped record.identity.authorization.evidence.role raw log field to event.idm.read_only_udm.principal.user.attribute.roles.name.
- event.idm.read_only_udm.target.resource.attribute.labels: Newly mapped record.identity.authorization.scope raw log field to event.idm.read_only_udm.target.resource.attribute.labels with key authorization_scope.
- event.idm.read_only_udm.security_result.category_details: Newly mapped record.category raw log field to event.idm.read_only_udm.security_result.category_details.
- event.idm.read_only_udm.security_result.category_details: Newly mapped record.properties.eventCategory raw log field to event.idm.read_only_udm.security_result.category_details (if different from record.category).
- event.idm.read_only_udm.security_result.summary: Newly mapped record.resultType raw log field to event.idm.read_only_udm.security_result.summary.
- event.idm.read_only_udm.security_result.description: Newly mapped record.resultSignature raw log field to event.idm.read_only_udm.security_result.description.
- event.idm.read_only_udm.security_result.severity_details: Newly mapped record.level raw log field to event.idm.read_only_udm.security_result.severity_details.
- event.idm.read_only_udm.security_result.action_details: Newly mapped record.identity.authorization.action raw log field to event.idm.read_only_udm.security_result.action_details.
- event.idm.read_only_udm.network.session_id: Newly mapped record.correlationId raw log field to event.idm.read_only_udm.network.session_id.
- event.idm.read_only_udm.additional.fields: Newly mapped the following raw log fields to event.idm.read_only_udm.additional.fields: record.resourceId (key: resourceId), record.ReleaseVersion (key: ReleaseVersion), record.Stamp (key: Stamp), record.tenantId (key: tenantId), record.identity.claims.appid (key: App Id), record.identity.claims.aud (key: claims_aud), record.identity.claims.iss (key: claims_iss), record.identity.claims.iat (key: claims_iat), record.identity.claims.nbf (key: claims_nbf), record.identity.claims.exp (key: claims_exp), record.identity.claims.appidacr (key: claims_appidacr), record.identity.claims.idtyp (key: claims_idtyp), record.identity.claims.nameidentifier (key: claims_nameidentifier), record.identity.claims.tenantid (key: claims_tenantid), record.identity.claims.ver (key: claims_ver), record.identity.claims.aio (key: claims_aio), record.identity.claims.rh (key: claims_rh), record.identity.claims.uti (key: claims_uti), record.identity.claims.xms_ftd (key: claims_xms_ftd), record.identity.claims.xms_idrel (key: claims_xms_idrel), record.identity.claims.xms_rd (key: claims_xms_rd), record.identity.claims.xms_tcdt (key: claims_xms_tcdt), record.durationMs (key: durationMs), record.identity.authorization.evidence.roleAssignmentId (key: roleAssignmentId), record.identity.authorization.evidence.roleDefinitionId (key: roleDefinitionId), record.identity.authorization.evidence.roleAssignmentScope (key: roleAssignmentScope), record.properties.eventCategory (key: eventCategory - if equal to record.category), record.properties.hierarchy (key: hierarchy), record.properties.statusCode (key: properties_statusCode), record.properties.serviceRequestId (key: properties_serviceRequestId).
- Set event.idm.read_only_udm.metadata.vendor_name to Microsoft.
- Set event.idm.read_only_udm.metadata.product_name to Azure AD Directory Audit.
- Conditionally set event.idm.read_only_udm.metadata.event_type to USER_UNCATEGORIZED, STATUS_UPDATE, or GENERIC_EVENT based on the presence of user or principal information.
- Conditionally set event.idm.read_only_udm.security_result.action to ALLOW or BLOCK based on record.resultType containing success or failure.
2025-07-03 Enhancement:
- Added a Grok pattern to support new pattern of JSON logs.
- event.idm.read_only_udm.target.resource.name: Newly mapped properties.resourceDisplayName raw log field with event.idm.read_only_udm.target.resource.name UDM field.
- event.idm.read_only_udm.additional.fields: Newly mapped resultSignature, properties.resourceOwnerTenantId, properties.appOwnerTenantId, properties.sessionId, properties.signInTokenProtectionStatus, properties.resourceServicePrincipalId, properties.appServicePrincipalId, properties.authenticationProtocol, properties.incomingTokenType, properties.authenticationStrengths, properties.uniqueTokenIdentifier, properties.authenticationProcessingDetails, properties.homeTenantId, properties.resourceTenantId, properties.clientCredentialType and durationMs raw log fields with event.idm.read_only_udm.additional.fields UDM field.
- event.idm.read_only_udm.metadata.event_type: Set event.idm.read_only_udm.metadata.event_type to STATUS_UPDATE when event.idm.read_only_udm.metadata.event_type is GENERIC_EVENT and principal_ip_present is true.
2025-04-16 Enhancement:
- event.idm.read_only_udm.target.user.userid: Removed mapping of identity from event.idm.read_only_udm.target.user.userid UDM field.
- event.idm.read_only_udm.principal.user.user_display_name: Removed mapping of user_name from event.idm.read_only_udm.principal.user.user_display_name UDM field.
- If principal_ip_present is true AND activityDisplayName is Validate user authentication and principal_userid_present is true, then set event.idm.read_only_udm.metadata.event_type to USER_UNCATEGORIZED.
- If principal_ip_present is true AND activityDisplayName is Validate user authentication has_target_hostname is true, set event.idm.read_only_udm.metadata.event_type to NETWORK_CONNECTION.
- Added a condition has_target_hostname is true when event.idm.read_only_udm.target.hostname is mapped.
2025-03-20 Enhancement:
- Mapped temp_display_name to target.hostname and target.asset.hostname.
- When modifiedProperties.displayName equals AppId then mapped modifiedProperties.newvalue to target.process.pid.
2025-02-19 Enhancement:
- Mapped initiatedBy.user.displayName to about.user.user_display_name.
2024-11-28 Enhancement:
- Mapped properties.deviceDetail.displayName to principal.asset.hardware.model.
- Mapped properties.authenticationDetails.authenticationMethod, properties.authenticationDetails.authenticationStepDateTime, properties.authenticationDetails.authenticationStepRequirement, properties.authenticationDetails.authenticationStepResultDetail, and properties.authenticationDetails.succeeded to security_result.detection_fields.
- Mapped properties.userAgent to network.http.user_agent.
- Mapped properties.deviceDetail.deviceId to principal.asset.asset_id and principal.asset_id.
- Mapped properties.deviceDetail.trustType to additional.fields.
- Mapped properties.deviceDetail.browser to principal.resource.attribute.labels.
- Mapped properties.deviceDetail.operatingSystem to principal.platform_version.
2024-09-04 Enhancement:
- When activityDisplayName is Add member to group, then mapped objectId to target.group.product_object_id.
- When activityDisplayName is Add member to group, then mapped DisplayName to target.group.group_display_name.
2024-07-30 Enhancement:
- When principal.user.userid or target.user.userid is present, mapped only metadata.event_type to USER_CHANGE_PERMISSIONS.
2024-06-26 Enhancement:
- Mapped delta between targetResources.modifiedProperties.newValue and targetResources.modifiedProperties.oldValue to additional.fields.
2024-06-10 Enhancement:
- When initiatedBy.user.ipAddress is having an IP, then set principal_ip_present to true.
- Added a condition to set metadata.event_type to USER_DELETION only when principal_ip_present is true.
2024-06-03 Enhancement:
- Added a JSON block to parse unparsed logs.
- Added a conditional check for event_type USER_DELETION.
2024-05-20 Bug-Fix:
- Modified the mapping of the targetResource.
- Mapped first iteration of the targetResource to target and the following iteration of targetResource to about.
- Changed key name of loggedByService field to loggedByService from log_Service.
- Changed mapping of resourceId from target.resource.id to additional_fields.
- When targetResources.type = Application, Policy, Role, Directory, RoleAssignment, Request, Provider, Other, then mapped targetResources.displayName to noun.resource.name; targetResources.id to noun.resource.product_object_id; noun.resource.resource_type = UNSPECIFIED and targetResource.type to noun.resource.resource_subtype.
- When targetResources.type = User, then mapped targetResources.displayName to noun.resource.name; targetResources.id to noun.resource.product_object_id; noun.resource.resource_type = UNSPECIFIED; targetResource.type to noun.resource.resource_subtype; targetResources.displayName to noun.user.user_display_name; targetResources.id to noun.user.product_object_id; targetResources.userPrincipalName to noun.user.userid.
- When targetResources.type = ServicePrincipal, then mapped targetResources.displayName to noun.resource.name, targetResources.id to noun.resource.product_object_id, noun.resource.resource_type = SERVICE_ACCOUNT, targetResource.type to noun.resource.resource_subtype, targetResources.displayName to noun.user.user_display_name, targetResources.id to noun.user.product_object_id and targetResources.userPrincipalName to noun.user.userid.
- When targetResources.type = Group, then mapped targetResources.displayName to noun.resource.name, targetResources.id to noun.resource.product_object_id, noun.resource.resource_type = UNSPECIFIED , targetResource.type to noun.resource.resource_subtype, targetResources.displayName to noun.group.group_display_name, targetResources.id to noun.group.product_object_id, and groupType to noun.group.attribute.labels.
2024-05-17 Enhancement:
- Mapped initiatedBy.user.id to principal.user.product_object_id.
- Mapped initiatedBy.user.userPrincipalName to principal.user.userid.
2024-03-18 Enhancement:
- Displayed targetResources.modifiedProperties.displayname, targetResources.modifiedProperties.newValue and targetResources.modifiedProperties.oldValue fields even when value is null.
- Mapped callerIpAddress to principal.ip.
2024-03-12 Bug-Fix:
- Synced mappings of Azure Monitor envelope format log mappings to Microsoft Graph API format logs.
- Mapped target.resource.resource_type based on targetResources.type.
- Mapped targetResources.type to target.resource.type.
2024-03-04 Enhancement:
- Mapped user_principal_name from initiatedBy.user.userPrincipalName to principal.resource.attribute.labels.
- Mapped domain from initiatedBy.user.userPrincipalName to principal.administrative_domain.
- Mapped loggedByService and properties.loggedByService to additional.fields.
- Changed mapping of initiatedBy.user.id from principal.user.product_object_id to principal.user.userid.
- Mapped tgt_user_principal_name from target.userPrincipalName to target.resource.attribute.labels.
- Mapped domain from target.userPrincipalName to target.administrative_domain.
- Mapped category to additional.fields.
- When additionalDetails[n].key is AppId, then mapped additionalDetails[n].value to target.process.pid.
- When additionalDetails[n].key is User-Agent, then mapped additionalDetails[n].value to network.http.user_agent and network.http.parsed_user_agent.
- Mapped metadata.event_type based on loggedByService, category and activityDisplayName.
- Mapped targetResources.modifiedProperties.displayname, targetResources.modifiedProperties.newValue and targetResources.modifiedProperties.oldValue to additional.fields.
2024-02-21 Enhancement:
- Added conditional check if principal.user.userid is present before setting metadata.event_type to USER_CREATION.
- Changed mapping of initiatedBy.user.id from principal.user.userid to principal.user.product_object_id.
- Changed mapping of initiatedBy.app.servicePrincipalId from principal.user.userid to principal.user.product_object_id.
- Changed mapping of initiatedBy.app.servicePrincipalName from principal.user.user_display_name to principal.user.userid.
- Changed mapping of properties.initiatedBy.user.id from principal.user.userid to principal.user.product_object_id.
- Changed mapping of properties.initiatedBy.app.servicePrincipalId from principal.user.userid to principal.user.product_object_id.
- Changed mapping of properties.initiatedBy.app.servicePrincipalName from principal.user.user_display_name to principal.user.userid.
- If targetResourceType value is similar to User or ServicePrincipal, then changed mapping of target.id from target.user.userid to target.user.product_object_id.
- If targetResourceType value is similar to User or ServicePrincipal, then mapped target.userPrincipalName to target.user.userid.
- If targetResourceType value is similar to User or ServicePrincipal, then mapped target.displayName to target.user.user_display_name.
2024-02-12 Enhancement:
- Added conditional check for modifiedProperty.displayName, modifiedProperty.newValue, and modifiedProperty.oldValue.
- When targetResource.id is User or ServicePrincipal, then mapped it to target.user.userid.
2024-01-08 Bug-Fix:
- Added a Grok pattern to validate email values before mapping them to principal.user.email_addresses and target.user.email_addresses.
2023-12-19 Enhancement:
- Mapped targetResource.modifiedProperties.newValue, targetResource.modifiedProperties.oldValue, and targetResource.modifiedProperties.displayName to additional.fields.
2023-11-23 - Mapped targetResources.0.modifiedProperties.newValue/oldValue fields to event.idm.read_only_udm.additional.fields.
- Added ip_address format check to initiatedBy.user.ipAddress prior mapping to udm.
2023-10-16 Enhancement: Modified the following mappings:
- Changed metadata.event_type from USER_UNCATEGORIZED to USER_RESOURCE_ACCESS where target.type is not user'.
- Changed mapping of target.id from principal.user.userid, to principal.user.group_or_identifiers where target.type is not user'.
- Mapped the field which has been mapped to target.resource.id to target.resource.product_object_id as well because target.resource.id is deprecated.
2023-08-03 Enhancement: Modified the following mappings:
- Changed metadata.event_type from USER_UNCATEGORIZED to USER_CREATION where activityDisplayName is Add user.
- Changed mapping of activityDisplayName from metadata.description, to metadata.product_event_type'.
- Mapped appropriate metadata.event_type where activityDisplayName is Add member to group, Add owner to group.
- All fields under targetResources should be part of the UDM target.user. fields.
- target.user.userid mapped against the correct id under targetResource.
- For activityDisplayName as Add member to role outside of PIM (permanent) in activityDisplayName mapped target.user.xxx when resource type is User'.
- For activityDisplayName as Add Member to Role mapped Role.WellKnownObjectName to target.resource.attribute.roles.name.
2023-07-24 Enhancement: Mapped targetResources.modifiedProperties.newValue to target.user.title when targetResources.modifiedProperties.displayName value contains Role.DisplayName.
2023-05-25 Bug-fix: Changed mapping from target.resource.attribute.labels.value to target.user.userid when targetResources.modifiedProperties.displayName equals mailNickname.
2023-05-05 Enhancement: Modified the following mappings-
- Changed mapping from target.resource.attribute.labels.value to target.user.product_object_id when targetResources.modifiedProperties.displayName equals objectId.
- Changed mapping from target.resource.attribute.labels.value to target.user.user_display_name when targetResources.modifiedProperties.displayName equals displayName.
- Changed mapping from target.resource.attribute.labels.value to target.user.first_name when targetResources.modifiedProperties.displayName equals givenName.
- Changed mapping from target.resource.attribute.labels.value to target.user.title when targetResources.modifiedProperties.displayName equals jobTitle.
- Changed mapping from target.resource.attribute.labels.value to target.user.email_addresses when targetResources.modifiedProperties.displayName equals mail.
- Changed mapping from target.resource.attribute.labels.value to target.user.last_name when targetResources.modifiedProperties.displayName equals surname.
- Changed mapping from target.resource.attribute.labels.value to target.user.department when targetResources.modifiedProperties.displayName equals department.
- Changed mapping from target.resource.attribute.labels.value to target.user.office_address.name when targetResources.modifiedProperties.displayName equals physicalDeliveryOfficeName.
- Changed mapping from target.resource.attribute.labels.value to target.user.employee_id when targetResources.modifiedProperties.displayName equals employeeId.
- Changed mapping from target.resource.attribute.labels.value to target.user.phone_numbers when targetResources.modifiedProperties.displayName equals mobile.
2023-04-18 Enhancement:
- initiatedBy.user.userPrincipalName mapped to principal.user.user_display_name or principal.user.userid or principal.user.email_addresses.
- targetResources.type mapped to target.resource.attribute.labels.
2023-04-12 Enhancement -
- Mapped initiatedBy.user.userPrincipalName to principal.user.email_addresses and event_type to USER_UNCATEGORIZED.
when initiatedBy.user.userPrincipalName is not null.
- If targetResources.modifiedProperties.displayName is userPrincipalName than mapped it to principal.user.email_addresses.
- Mapped event_type to USER_UNCATEGORIZED when activityDisplayName is in [Issue an id_token to the application, Set Company Information].
2023-02-20 Bug-Fix -
- Mapped multiple IP addresses coming under key additionalDetails.ClientIpAddress to principal.ip.
- Mapped metadata.event_type as USER_UNCATEGORIZED when activityDisplayName equals Delete user and initiatedBy.user.userPrincipalName field is not present.
2023-02-02 Enhancement - Mapped the following when activityDisplayName equals Delete user :
- Mapped event_type to USER_DELETION.
- Mapped initiatedBy.user.userPrincipalName to principal.user.userid.
2022-11-24 Enhancement -
- Mapped modifiedProperties.newValue to target.resource.attribute.labels.
- Mapped modifiedProperties.oldValue to src.resource.attribute.labels.
2022-11-07 Enhancement -
- Mapped target.modifiedProperties.TargetId.DeviceId to event.idm.read_only_udm.target.asset.asset_id.
2022-09-16 Enhancement -
- Mapped properties.initiatedBy.user.ipAddress to principal.ip.
- Mapped properties.initiatedBy.user.userPrincipalName to principal.user.userid.
- Mapped properties.resultReason to security_result.description.
- Mapped identity to target.user.userid.
- Mapped operationName to metadata.product_event_type.
- Mapped metadata.event_type to USER_UNCATEGORIZED where properties.activityDisplayName is Get resource properties of a tenant.
- Mapped category and properties.category to security_result.category_details.
- Mapped resultDescription to metadata.description.
- Mapped resultType to security_result.rule_id.
2022-06-20 Enhancement - Enhanced the parser to parse the logs with category : AuditLogs and SignInLogs by adding following mappings :
- Mapped the field properties.id to metadata.product_log_id.
- Mapped the field properties.loggedByService to target.application.
- Mapped the field Level to security_result.severity and security_result.severity_details.
- Mapped the field properties.result to security_result.summary and security_result.action.
- Mapped the field properties.operationType to security_result.action_details.
- Mapped the field properties.activityDisplayName to metadata.description.
- Mapped the field properties.category to metadata.product_event_type.
- Mapped the field properties.resultReason to security_result.description.
- Mapped the field properties.initiatedBy.app.displayName to principal.application.
- Mapped the field properties.ipAddress to principal.ip.
- Mapped the field properties.initiatedBy.app.servicePrincipalId to principal.user.userid.
- Mapped the field properties.initiatedBy.app.servicePrincipalName to principal.user.user_display_name.
- Mapped the field properties.appId and properties.initiatedBy.app.appId to principal.resource.attribute.labels.
- Mapped the field properties.location.city to principal.location.city.
- Mapped the field properties.location.state to principal.location.state.
- Mapped the field properties.location.countryOrRegion to principal.location.country_or_region.
- Mapped the field properties.location.geoCoordinates.latitude to principal.location.region_latitude.
- Mapped the field properties.location.geoCoordinates.longitude to principal.location.region_longitude.
- Mapped the fields properties.targetResources.modifiedProperties to target.user.attribute.labels.
- Mapped the field targetResources.displayName to target.user.user_display_name.
- Mapped the field targetResources.id to target.user.userid.
- Mapped the fields properties.additionalDetails, properties.riskDetail, properties.riskEventTypes, properties.riskEventTypes_v2, properties.riskLevelAggregated, properties.riskLevelDuringSignIn, properties.riskState, properties.conditionalAccessStatus, tenantId to additional.fields.
- Mapped the field operationVersion to metadata.product_version.
- Mapped the field properties.appliedConditionalAccessPolicies.displayName to about.user.user_display_name.
- Mapped the field properties.appliedConditionalAccessPolicies..id to about.user.userid.
- Mapped the field properties.appliedConditionalAccessPolicies.result to about.labels.