We've reorganized our documentation navigation structure to align directly with your operational workflows. See the release notes and the walkthrough video for more information.
Stay organized with collections
Save and categorize content based on your preferences.
Change log for AZURE_KEYVAULT_AUDIT
Date
Changes
2025-07-08
Enhancement:
- event.idm.read_only_udm.additional.fields: Newly mapped `loggingSourceName` raw log field with `event.idm.read_only_udm.additional.fields` UDM field.
- Added support to `has_principal` which is causing the issue to parser error.
2025-01-30
Enhancement:
- Added support for the new pattern of JSON logs.
2024-11-18
Enhancement:
- Added support for new pattern of JSON logs.
2024-10-29
Enhancement:
- Mapped "properties.isAddressAuthorized", "properties.isAccessPolicyMatch", and "properties.isRbacAuthorized" to "target.resource.attribute.labels".
- Mapped "properties.subnetId", and "properties.privateEndpointId" to "additional.fields".
2024-09-25
- Modified condition for "USER_UNCATEGORIZED" event_type.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2026-07-26 UTC."],[],[]]