收集 Microsoft Entra ID 目錄稽核 (原稱 Azure Active Directory) 記錄
剖析器版本:28.0
本文說明如何設定 Google Security Operations 資訊提供,以收集 Microsoft Entra ID (原稱「Azure Active Directory」) 目錄稽核記錄。您可以透過兩種方法設定擷取作業:Azure Event Hub (建議) 或第三方 API。
Entra ID 目錄稽核記錄會擷取租戶內所做的變更,包括使用者和群組管理、應用程式更新、目錄角色變更和政策修改。
事前準備
請確認您已完成下列事前準備事項:
- Google SecOps 執行個體。
- Microsoft Azure 入口網站的特殊權限存取權。
- Microsoft Entra ID 中的安全管理員或全域管理員角色 (診斷設定需要此角色)。
方法 1:Azure 事件中樞 (建議)
這個方法會透過已啟用擷取的 Azure Event Hub 串流 Entra ID 稽核記錄,並將資料寫入 Azure Blob 儲存體。接著,Google SecOps 會使用 Azure Blob 儲存體 V2 來源類型,從 Blob 儲存體擷取記錄。
設定 Azure 儲存體帳戶
建立儲存空間帳戶
- 在 Azure 入口網站中,搜尋「儲存體帳戶」。
- 點選「+ 建立」。
請提供下列設定詳細資料:
設定 值 訂閱項目 選取 Azure 訂閱項目 資源群組 選取現有資料庫或建立新資料庫 儲存體帳戶名稱 輸入不重複的名稱 (例如 secopsauditlogs)區域 選取最接近 Event Hub 命名空間的區域 效能 標準 (建議) 備援功能 LRS (本地備援儲存體) 或 GRS (異地備援儲存體) 按一下「Review + create」。
查看總覽,然後按一下「建立」。
等待部署作業完成。
取得儲存空間帳戶憑證
- 前往您建立的「儲存空間帳戶」。
- 在左側導覽中,選取「Security + networking」(安全性 + 網路) 下方的「Access keys」(存取金鑰)。
- 按一下「顯示金鑰」。
- 複製並儲存下列項目:
- 儲存體帳戶名稱
- 按鍵 1或按鍵 2:共用存取金鑰。
建立事件中樞命名空間和事件中樞
建立 Event Hubs 命名空間
- 在 Azure 入口網站中,搜尋 Event Hubs。
- 點選「+ 建立」。
請提供下列設定詳細資料:
設定 值 訂閱項目 選取 Azure 訂閱項目 資源群組 選取與儲存空間帳戶相同的資源群組 命名空間名稱 輸入不重複的名稱 (例如 secops-entraid-audit)位置 選取與儲存空間帳戶相同的區域 定價方案 標準 (Event Hub Capture 必填) 按一下「檢查並建立」,然後按一下「建立」。
等待部署作業完成。
建立事件中樞
- 前往您建立的 Event Hub 命名空間。
- 按一下頂端的「+ Event Hub」。
- 請提供下列設定詳細資料:
- 「Name」(名稱):輸入名稱 (例如
entraid-audit-logs)。 - 分區數量:2 (預設值,如要提高總處理量,請增加分區數量)。
- 清除政策:刪除。
- 保留時間 (小時):24 (最低,如需彈性可增加)。
- 「Name」(名稱):輸入名稱 (例如
- 按一下「檢查並建立」,然後按一下「建立」。
啟用 Event Hub Capture
- 前往您建立的 Event Hub (位於命名空間內)。
- 在左側導覽面板中,選取「擷取」。
- 將「擷取」設為「開啟」。
請提供下列設定詳細資料:
設定 值 時間範圍 (分鐘) 5 (或更低,以達到近乎即時的延遲) 大小視窗 (MB) 300 擷取供應商 Azure Blob 儲存體 Azure 訂閱項目 選取訂閱方案 儲存空間帳戶 選取您建立的儲存空間帳戶 Blob 容器 建立或選取容器 (例如 entraid-audit-capture)按一下 [儲存]。
設定 Entra ID 診斷設定
- 以至少安全性管理員身分登入 Microsoft Entra 系統管理中心。
- 依序前往「Entra ID」>「監視與健康狀態」>「診斷設定」。
- 按一下「新增診斷設定」。
- 請提供下列設定詳細資料:
- 診斷設定名稱:輸入描述性名稱 (例如
audit-logs-to-eventhub)。 - 在「記錄」專區,選取「AuditLogs」。
- 在「目的地詳細資料」部分,選取「將資料串流至事件中樞」。
- 「Subscription」(訂閱項目):選取包含 Event Hub 命名空間的訂閱項目。
- 事件中樞命名空間:選取您建立的命名空間 (例如
secops-entraid-audit)。 - 事件中樞名稱:選取您建立的事件中樞 (例如
entraid-audit-logs)。 - 事件中樞政策名稱:選取「RootManageSharedAccessKey」。
- 診斷設定名稱:輸入描述性名稱 (例如
按一下 [儲存]。
設定動態饋給
在 Google SecOps 平台中,有兩種不同的進入點可設定動態饋給:
- 依序點選「SIEM 設定」>「動態消息」>「新增動態消息」
- 依序點選「內容中心」「內容包」「開始使用」
在 Google SecOps 中設定資訊提供,擷取 Entra ID 稽核記錄
- 依序前往「SIEM 設定」>「動態饋給」。
- 按一下「新增動態消息」。
- 在下一個頁面中,按一下「設定單一動態饋給」。
- 在「動態饋給名稱」欄位中輸入動態饋給名稱 (例如
Entra ID Audit Logs - Event Hub)。 - 選取「Microsoft Azure Blob Storage V2」做為「來源類型」。
- 選取「Azure AD 目錄稽核」做為「記錄類型」。
- 點選「下一步」。
指定下列輸入參數的值:
- Azure URI:輸入 Blob 服務端點網址和擷取容器路徑:
https://<storage-account>.blob.core.windows.net/entraid-audit-capture/將
<storage-account>替換為 Azure 儲存空間帳戶名稱。- 來源刪除選項:根據偏好選取刪除選項:
- 永不:轉移後一律不刪除任何檔案。
- 刪除已轉移的檔案:成功轉移檔案後刪除檔案。
- 刪除已轉移的檔案和空白目錄:成功轉移後刪除檔案和空白目錄。
- 檔案存在時間上限:納入在過去天數內修改的檔案。預設值為 180 天。
- 共用金鑰:輸入儲存空間帳戶的共用存取金鑰值。
- 資產命名空間:資產命名空間。
- 擷取標籤:要套用至這個動態饋給事件的標籤。
點選「建立動態饋給」。
建立動態消息後,記錄可能需要 5 到 10 分鐘才會開始顯示在 Google SecOps 中。
如要進一步瞭解如何為這個產品系列中的不同記錄類型設定多個動態饋給,請參閱「依產品設定動態饋給」。
如要進一步瞭解 Google Security Operations 動態消息,請參閱 Google Security Operations 動態消息說明文件。如要瞭解各動態饋給類型的規定,請參閱「依類型設定動態饋給」。如果在建立動態饋給時遇到問題,請與 Google Security Operations 支援團隊聯絡。
設定 Azure 儲存空間防火牆 (如已啟用)
如果 Azure 儲存體帳戶使用防火牆,您必須新增 Google SecOps IP 範圍。
- 在 Azure 入口網站中,前往「儲存體帳戶」。
- 選取「Security + networking」(安全性 + 網路) 下方的「Networking」(網路)。
- 在「防火牆和虛擬網路」下方,選取「從所選虛擬網路和 IP 位址啟用」。
- 在「防火牆」部分的「位址範圍」下方,按一下「+ 新增 IP 範圍」。
- 以 CIDR 標記法新增每個 Google SecOps IP 範圍。
- 請參閱 IP 位址許可清單說明文件。
- 或者使用 Feed Management API,以程式輔助方式擷取這些 ID。
- 按一下 [儲存]。
方法 2:第三方 API
這個方法會使用 Microsoft Graph API,直接從 Microsoft 租戶擷取 Entra ID 目錄稽核記錄。
設定 IP 許可清單
建立動態饋給前,請務必在 Microsoft Azure 網路設定或條件存取政策中,將 Google SecOps IP 範圍加入允許清單。
取得 Google SecOps IP 範圍
- 依序前往「SIEM 設定」>「動態饋給」。
- 按一下「新增動態消息」。
- 請注意動態饋給建立介面中顯示的 IP 範圍。
- 或者,您也可以使用 Feed Management API,透過程式擷取 IP 範圍。
設定工作負載身分的條件式存取權 (如有需要)
如果貴機構使用條件存取政策,限制存取位置:
- 在 Microsoft Entra 系統管理中心,依序前往「Protection」(保護) >「Conditional Access」(條件式存取) >「Named locations」(具名位置)。
- 按一下「+ 新增地點」。
- 請提供下列設定詳細資料:
- 「Name」(名稱):輸入
Google SecOps IP Ranges。 - 標示為信任地點:視您的安全政策而定。
- IP 範圍:以 CIDR 標記法新增每個 Google SecOps IP 範圍。
- 「Name」(名稱):輸入
- 點選「建立」。
- 前往「條件存取」>「原則」。
- 如要為工作負載身分套用任何政策,請為名為
Google SecOps IP Ranges的位置或特定服務主體設定排除條件。
設定 Microsoft Entra 應用程式註冊
建立應用程式註冊
- 登入 Microsoft Entra 系統管理中心或 Azure 入口網站。
- 依序前往「身分識別」>「應用程式」>「應用程式註冊」。
- 按一下 [新增註冊]。
- 請提供下列設定詳細資料:
- 名稱:輸入描述性名稱 (例如
Google SecOps Audit Logs Integration)。 - 支援的帳戶類型:選取「Accounts in this organizational directory only (Single tenant)」。
- 重新導向 URI:留空 (服務主體驗證不需要)。
- 名稱:輸入描述性名稱 (例如
- 按一下「註冊」。
- 註冊完成後,請複製並儲存下列值:
- 應用程式 (用戶端) ID
- 目錄 (租戶) ID
設定 API 權限
- 在應用程式註冊中,前往「API permissions」。
- 按一下「新增權限」。
- 依序選取「Microsoft Graph」>「應用程式權限」。
- 搜尋並選取下列權限:
- AuditLog.Read.All - 讀取目錄稽核記錄時必須具備這項權限。
- Directory.Read.All - Microsoft Graph API 需要此權限才能存取稽核記錄。
- 按一下「Add permissions」。
- 按一下「Grant admin consent for [Your Organization]」。
確認「狀態」欄顯示所有權限的「已授予 [貴機構]」。
| 權限 | 類型 | 說明 |
|---|---|---|
| AuditLog.Read.All | 應用程式 | 讀取所有稽核記錄資料 |
| Directory.Read.All | 應用程式 | 讀取目錄資料 (存取 API 時必須具備這項權限) |
建立用戶端密鑰
- 在應用程式註冊中,前往「Certificates & secrets」。
- 按一下 [新增用戶端密碼]。
請提供下列設定詳細資料:
- 說明:輸入描述性名稱 (例如
Google SecOps Feed)。 - 到期:選取到期時間。
- 說明:輸入描述性名稱 (例如
按一下「新增」。
立即複製用戶端密鑰的「值」。
重要事項:密鑰值只會顯示一次,離開這個頁面後就無法擷取。如果遺失該值,就必須建立新的用戶端密鑰。
設定動態饋給
在 Google SecOps 平台中,有兩種不同的進入點可設定動態饋給:
- 依序點選「SIEM 設定」>「動態消息」>「新增動態消息」
- 內容中心 > 內容套件 > 開始使用 ### 在 Google SecOps 中設定動態饋給,以便擷取 Entra ID 稽核記錄
- 依序前往「SIEM 設定」>「動態饋給」。
- 按一下「新增動態消息」。
- 在下一個頁面中,按一下「設定單一動態饋給」。
- 在「動態饋給名稱」欄位中輸入動態饋給名稱 (例如
Entra ID Directory Audit Logs)。 - 選取「第三方 API」做為「來源類型」。
- 選取「Azure AD 目錄稽核」做為「記錄類型」。
- 點選「下一步」。
指定下列輸入參數的值:
- OAuth 用戶端 ID:輸入應用程式註冊時的應用程式 (用戶端) ID。
- OAuth 用戶端密鑰:輸入您先前複製的用戶端密鑰值。
- 租戶 ID:輸入應用程式註冊中的目錄 (租戶) ID,格式為 UUID (例如
0fc279f9-fe30-41be-97d3-abe1d7681418)。 - API 完整路徑:輸入 Microsoft Graph REST API 端點網址:
graph.microsoft.com/v1.0/auditLogs/directoryAudits- API 驗證端點:輸入 Microsoft Active Directory 驗證端點:
login.microsoftonline.com- 資產命名空間:資產命名空間。
- 擷取標籤:要套用至這個動態饋給事件的標籤。
點選「建立動態饋給」。
如要進一步瞭解如何為這個產品系列中的不同記錄類型設定多個動態饋給,請參閱「依產品設定動態饋給」。
如要進一步瞭解 Google Security Operations 動態消息,請參閱 Google Security Operations 動態消息說明文件。如要瞭解各動態饋給類型的規定,請參閱「依類型設定動態饋給」。如果在建立動態饋給時遇到問題,請與 Google Security Operations 支援團隊聯絡。
地區端點
如要在主權雲端中部署 Microsoft Entra ID,請使用適當的區域端點:
| 雲端環境 | API 完整路徑 | API 驗證端點 |
|---|---|---|
| 全球 | graph.microsoft.com/v1.0/auditLogs/directoryAudits |
login.microsoftonline.com |
| 美國政府 L4 | graph.microsoft.us/v1.0/auditLogs/directoryAudits |
login.microsoftonline.us |
| 美國政府 L5 (國防部) | dod-graph.microsoft.us/v1.0/auditLogs/directoryAudits |
login.microsoftonline.us |
| 中國 (21Vianet) | microsoftgraph.chinacloudapi.cn/v1.0/auditLogs/directoryAudits |
login.chinacloudapi.cn |
UDM 對應表
| 記錄欄位 | UDM 對應 | 邏輯 |
|---|---|---|
grouptypelabel |
about.group.attribute.labels |
已合併 |
targetResourceType |
about.group.attribute.labels |
已對應:Group → grouptypelabel |
target.displayName |
about.group.group_display_name |
直接對應 |
target.id |
about.group.product_object_id |
直接對應 |
resultField |
about.labels |
已合併 |
target.displayName |
about.resource.name |
直接對應 |
target.id |
about.resource.product_object_id |
直接對應 |
targetResourceType |
about.resource.resource_subtype |
直接對應 |
target.id |
about.user.product_object_id |
直接對應 |
initiatedBy.user.displayName |
about.user.user_display_name |
直接對應 |
policies.displayName |
about.user.user_display_name |
直接對應 |
target.displayName |
about.user.user_display_name |
直接對應 |
policies.id |
about.user.userid |
直接對應 |
userPrincipalName |
about.user.userid |
直接對應 |
AdditionalDetail_label |
additional.fields |
已合併 |
ReleaseVersion_label |
additional.fields |
已合併 |
Stamp_label |
additional.fields |
已合併 |
_field |
additional.fields |
已合併 |
add_about_field |
additional.fields |
已合併 |
add_about_label |
additional.fields |
已合併 |
additional_applicationFilter |
additional.fields |
已合併 |
additional_applicationFilter_new |
additional.fields |
已合併 |
additional_builtInControls |
additional.fields |
已合併 |
additional_builtInControls_new |
additional.fields |
已合併 |
additional_category |
additional.fields |
已合併 |
additional_clientAppTypes |
additional.fields |
已合併 |
additional_clientAppTypes_new |
additional.fields |
已合併 |
additional_createdDateTime_new |
additional.fields |
已合併 |
additional_createdDateTime_old |
additional.fields |
已合併 |
additional_customAuthenticationFactors |
additional.fields |
已合併 |
additional_customAuthenticationFactors_new |
additional.fields |
已合併 |
additional_displayName |
additional.fields |
已合併 |
additional_displayName_new |
additional.fields |
已合併 |
additional_displayname |
additional.fields |
已合併 |
additional_excludeApplications |
additional.fields |
已合併 |
additional_excludeApplications_new |
additional.fields |
已合併 |
additional_excludeGroups |
additional.fields |
已合併 |
additional_excludeGroups_new |
additional.fields |
已合併 |
additional_excludeLocations |
additional.fields |
已合併 |
additional_excludeLocations_new |
additional.fields |
已合併 |
additional_excludePlatform |
additional.fields |
已合併 |
additional_excludePlatforms_new |
additional.fields |
已合併 |
additional_excludeUsers |
additional.fields |
已合併 |
additional_excludeUsers_new |
additional.fields |
已合併 |
additional_fields |
additional.fields |
已合併 |
additional_id |
additional.fields |
已合併 |
additional_id_new |
additional.fields |
已合併 |
additional_includeApplications |
additional.fields |
已合併 |
additional_includeApplications_new |
additional.fields |
已合併 |
additional_includeAuthenticationContextClassReferences |
additional.fields |
已合併 |
additional_includeAuthenticationContextClassReferences_new |
additional.fields |
已合併 |
additional_includeGroups |
additional.fields |
已合併 |
additional_includeGroups_new |
additional.fields |
已合併 |
additional_includeLocations |
additional.fields |
已合併 |
additional_includeLocations_new |
additional.fields |
已合併 |
additional_includePlatform |
additional.fields |
已合併 |
additional_includePlatforms_new |
additional.fields |
已合併 |
additional_includeRoles |
additional.fields |
已合併 |
additional_includeRoles_new |
additional.fields |
已合併 |
additional_includeUserActions |
additional.fields |
已合併 |
additional_includeUserActions_new |
additional.fields |
已合併 |
additional_includeUsers |
additional.fields |
已合併 |
additional_includeUsers_new |
additional.fields |
已合併 |
additional_includeuserRiskLevel |
additional.fields |
已合併 |
additional_label |
additional.fields |
已合併 |
additional_loggedByService |
additional.fields |
已合併 |
additional_modifiedDateTime_new |
additional.fields |
已合併 |
additional_modifiedDateTime_old |
additional.fields |
已合併 |
additional_newValue |
additional.fields |
已合併 |
additional_oldValue |
additional.fields |
已合併 |
additional_old_operator |
additional.fields |
已合併 |
additional_operator |
additional.fields |
已合併 |
additional_resourceId |
additional.fields |
已合併 |
additional_servicePrincipalRiskLevels |
additional.fields |
已合併 |
additional_servicePrincipalRiskLevels_new |
additional.fields |
已合併 |
additional_signInRiskLevels |
additional.fields |
已合併 |
additional_signInRiskLevels_new |
additional.fields |
已合併 |
additional_state |
additional.fields |
已合併 |
additional_state_new |
additional.fields |
已合併 |
additional_termsOfUses |
additional.fields |
已合併 |
additional_termsOfUses_new |
additional.fields |
已合併 |
additional_userRiskLevels_new |
additional.fields |
已合併 |
agentSubjectType_label |
additional.fields |
已合併 |
agentType_label |
additional.fields |
已合併 |
agent_type_label |
additional.fields |
已合併 |
aio_label |
additional.fields |
已合併 |
appDisplayName_label |
additional.fields |
已合併 |
appId_label |
additional.fields |
已合併 |
app_owner_tenant_id_label |
additional.fields |
已合併 |
app_service_principal_id_label |
additional.fields |
已合併 |
appidacr_label |
additional.fields |
已合併 |
aud_label |
additional.fields |
已合併 |
authentication_processing_details_label |
additional.fields |
已合併 |
authentication_protocol_label |
additional.fields |
已合併 |
authentication_strengths_label |
additional.fields |
已合併 |
changed_applicationFilter_label |
additional.fields |
已合併 |
changed_builtInControls_new |
additional.fields |
已合併 |
changed_clientAppTypes_label |
additional.fields |
已合併 |
changed_createdDateTime_label |
additional.fields |
已合併 |
changed_customAuthenticationFactors_new |
additional.fields |
已合併 |
changed_displayName_label |
additional.fields |
已合併 |
changed_excludeApplications_new |
additional.fields |
已合併 |
changed_excludeGroups_new |
additional.fields |
已合併 |
changed_excludeLocations_new |
additional.fields |
已合併 |
changed_excludePlatforms_new |
additional.fields |
已合併 |
changed_excludeUsers_new |
additional.fields |
已合併 |
changed_id_label |
additional.fields |
已合併 |
changed_includeApplications_label |
additional.fields |
已合併 |
changed_includeAuthenticationContextClassReferences_new |
additional.fields |
已合併 |
changed_includeGroups_new |
additional.fields |
已合併 |
changed_includeLocations_label |
additional.fields |
已合併 |
changed_includePlatforms_new |
additional.fields |
已合併 |
changed_includeRoles_new |
additional.fields |
已合併 |
changed_includeUserActions_new |
additional.fields |
已合併 |
changed_includeUsers_new |
additional.fields |
已合併 |
changed_modifiedDateTime_label |
additional.fields |
已合併 |
changed_operator_label |
additional.fields |
已合併 |
changed_servicePrincipalRiskLevels_new |
additional.fields |
已合併 |
changed_signInRiskLevels_new |
additional.fields |
已合併 |
changed_state_label |
additional.fields |
已合併 |
changed_termsOfUses_new |
additional.fields |
已合併 |
changed_userRiskLevels_new |
additional.fields |
已合併 |
claims_tenantid_label |
additional.fields |
已合併 |
client_credential_type_label |
additional.fields |
已合併 |
durationMs_label |
additional.fields |
已合併 |
duration_ms_label |
additional.fields |
已合併 |
eventCategory_label |
additional.fields |
已合併 |
event_name_label |
additional.fields |
已合併 |
exp_label |
additional.fields |
已合併 |
hierarchy_label |
additional.fields |
已合併 |
home_tenant_id_label |
additional.fields |
已合併 |
iat_label |
additional.fields |
已合併 |
identity_label |
additional.fields |
已合併 |
idtyp_label |
additional.fields |
已合併 |
incoming_token_type_label |
additional.fields |
已合併 |
initiatedBy_label |
additional.fields |
已合併 |
initiatedBy_type_label |
additional.fields |
已合併 |
isTenantRestricted_label |
additional.fields |
已合併 |
isThroughGlobalSecureAccess_label |
additional.fields |
已合併 |
iss_label |
additional.fields |
已合併 |
map_field |
additional.fields |
已合併 |
mfaAuthDetail_label |
additional.fields |
已合併 |
mfa_auth_method_label |
additional.fields |
已合併 |
modified_property_displayname |
additional.fields |
已對應:userPrincipalName → old_value_label、userPrincipalName → new_value_label |
nameidentifier_label |
additional.fields |
已合併 |
nbf_label |
additional.fields |
已合併 |
new_value_label |
additional.fields |
已合併 |
old_clientAppTypes |
additional.fields |
已對應:new_clientAppTypes → changed_clientAppTypes_label |
old_createdDateTime |
additional.fields |
已對應:new_createdDateTime → changed_createdDateTime_label |
old_displayName_value |
additional.fields |
已對應:new_displayName_value → changed_displayName_label |
old_grantControls |
additional.fields |
已對應:new_grantControls → changed_operator_label |
old_id_value |
additional.fields |
已對應:new_id_value → changed_id_label |
old_includeLocations |
additional.fields |
已對應:new_includeLocations → changed_includeLocations_label |
old_include_applications |
additional.fields |
已對應:new_include_applications → changed_includeApplications_label、`new_include_appli... |
old_modifiedDateTime |
additional.fields |
已對應:new_modifiedDateTime → changed_modifiedDateTime_label |
old_state_value |
additional.fields |
已對應:new_state_value → changed_state_label |
old_value_label |
additional.fields |
已合併 |
operationType_label |
additional.fields |
已合併 |
originalRequestId_label |
additional.fields |
已合併 |
prop_isInteractive_label |
additional.fields |
已合併 |
prop_log_version_label |
additional.fields |
已合併 |
prop_processingTimeInMilliseconds_label |
additional.fields |
已合併 |
prop_signInIdentifierType_label |
additional.fields |
已合併 |
properties_category_label |
additional.fields |
已合併 |
properties_correlationId_label |
additional.fields |
已合併 |
provisioningAction_label |
additional.fields |
已合併 |
removed_builtInControls_label |
additional.fields |
已合併 |
removed_customAuthenticationFactors_label |
additional.fields |
已合併 |
removed_excludeApplications_label |
additional.fields |
已合併 |
removed_excludeGroups_label |
additional.fields |
已合併 |
removed_excludeLocations_label |
additional.fields |
已合併 |
removed_excludeUsers_label |
additional.fields |
已合併 |
removed_includeAuthenticationContextClassReferences_label |
additional.fields |
已合併 |
removed_includeGroups_label |
additional.fields |
已合併 |
removed_includePlatform_label |
additional.fields |
已合併 |
removed_includeRoles_label |
additional.fields |
已合併 |
removed_includeUserActions_label |
additional.fields |
已合併 |
removed_includeUsers_label |
additional.fields |
已合併 |
removed_includeuserRiskLevel_label |
additional.fields |
已合併 |
removed_servicePrincipalRiskLevels_label |
additional.fields |
已合併 |
removed_signInRiskLevels_label |
additional.fields |
已合併 |
removed_termsOfUses_label |
additional.fields |
已合併 |
resourceId_label |
additional.fields |
已合併 |
resource_owner_tenant_id_label |
additional.fields |
已合併 |
resource_service_principal_id_label |
additional.fields |
已合併 |
resource_tenant_id_label |
additional.fields |
已合併 |
result_signature_label |
additional.fields |
已合併 |
rh_label |
additional.fields |
已合併 |
riskEventType_label |
additional.fields |
已合併 |
roleAssignmentId_label |
additional.fields |
已合併 |
roleAssignmentScope_label |
additional.fields |
已合併 |
roleDefinitionId_label |
additional.fields |
已合併 |
serviceRequestId_label |
additional.fields |
已合併 |
session_id_label |
additional.fields |
已合併 |
signInEventTypes_label |
additional.fields |
已合併 |
sign_in_token_protection_status_label |
additional.fields |
已合併 |
signin_session_status_label |
additional.fields |
已合併 |
statusCode_label |
additional.fields |
已合併 |
targetResourceType |
additional.fields |
已對應:"Device", "User", "Directory", "Application", "Group", "ServicePrincipal", "Role" ... |
targetResources_agentType_label |
additional.fields |
已合併 |
tenantId_Label |
additional.fields |
已合併 |
tenantId_label |
additional.fields |
已合併 |
tenant_id_label |
additional.fields |
已合併 |
tokenIssuerType_label |
additional.fields |
已合併 |
token_protection_type_label |
additional.fields |
已合併 |
trustType_label |
additional.fields |
已合併 |
unique_token_identifier_label |
additional.fields |
已合併 |
uti_label |
additional.fields |
已合併 |
ver_label |
additional.fields |
已合併 |
xms_ftd_label |
additional.fields |
已合併 |
xms_idrel_label |
additional.fields |
已合併 |
xms_rd_label |
additional.fields |
已合併 |
xms_tcdt_label |
additional.fields |
已合併 |
operationName |
extensions.auth.type |
已對應:Sign-in activity → SSO |
target_userid_present |
extensions.auth.type |
已對應:true → MACHINE |
logged_by_service |
intermediary.application |
直接對應 |
ActivityDisplayName |
metadata.description |
直接對應 |
record_properties_message |
metadata.description |
當 record_properties_message != `` 時對應 |
resultDescription |
metadata.description |
直接對應 |
ActivityDateTime |
metadata.event_timestamp |
已剖析為 yyyy-MM-ddTHH:mm:ss.SSSSSSSZ |
TimeGenerated |
metadata.event_timestamp |
已剖析為 yyyy-MM-ddTHH:mm:ss.SSSSSSSZ |
_TimeReceived |
metadata.event_timestamp |
已剖析為 yyyy-MM-ddTHH:mm:ss.SSSSSSSZ |
logcollector_timestamp |
metadata.event_timestamp |
已剖析為 ISO8601 |
properties.activityDateTime |
metadata.event_timestamp |
已剖析為 ISO8601 |
record.time |
metadata.event_timestamp |
已剖析為 ISO8601 |
time |
metadata.event_timestamp |
已剖析為 ISO8601 |
time_1 |
metadata.event_timestamp |
已剖析為 UNIX |
when |
metadata.event_timestamp |
已剖析為 ISO8601 |
activityDisplayName |
metadata.event_type |
對應值 (共 96 個,例如 Admin deleted security info → USER_DELETION、「Add applicat... |
category |
metadata.event_type |
對應值 (共 98 個,例如 AdministrativeUnit → USER_RESOURCE_CREATION、「Administrati... |
eventType |
metadata.event_type |
已對應:USER_UNCATEGORIZED → USER_RESOURCE_ACCESS |
has_principal |
metadata.event_type |
已對應:true → STATUS_UPDATE |
has_target_hostname |
metadata.event_type |
已對應:true → NETWORK_CONNECTION |
has_target_resource |
metadata.event_type |
已對應:true → USER_RESOURCE_ACCESS |
has_user |
metadata.event_type |
已對應:true → USER_UNCATEGORIZED |
loggedByService |
metadata.event_type |
對應值 (共 31 個,例如 Application proxy → SERVICE_CREATION、Application proxy ... |
operationName |
metadata.event_type |
已對應:Sign-in activity → USER_LOGIN |
principal_ip_present |
metadata.event_type |
對應值 (共 7 個,例如 true → USER_UNCATEGORIZED、true → NETWORK_CONNECTION、`... |
principal_userid_present |
metadata.event_type |
對應值 (共 6 個,例如 false → USER_RESOURCE_ACCESS、true → USER_UNCATEGORIZED... |
target_userid_present |
metadata.event_type |
對應:true → USER_CHANGE_PERMISSIONS、true → USER_CREATION、true → USER_LOGIN |
AADTenantId |
metadata.product_deployment_id |
直接對應 |
OperationName |
metadata.product_event_type |
直接對應 |
activityDisplayName |
metadata.product_event_type |
直接對應 |
operationName |
metadata.product_event_type |
直接對應 |
record_operationName |
metadata.product_event_type |
當 record_operationName != `` 時對應 |
Id |
metadata.product_log_id |
直接對應 |
id |
metadata.product_log_id |
直接對應 |
properties.AuditEventId |
metadata.product_log_id |
直接對應 |
properties_id |
metadata.product_log_id |
直接對應 |
OperationVersion |
metadata.product_version |
直接對應 |
operationVersion |
metadata.product_version |
直接對應 |
kv.value |
network.http.parsed_user_agent |
直接對應 |
properties.userAgent |
network.http.parsed_user_agent |
直接對應 |
kv.value |
network.http.user_agent |
直接對應 |
properties.userAgent |
network.http.user_agent |
直接對應 |
correlationId |
network.session_id |
直接對應 |
record_correlationId |
network.session_id |
當 record_correlationId != `` 時對應 |
domain |
principal.administrative_domain |
直接對應 |
InitiatedBy.app.displayName |
principal.application |
直接對應 |
clientAppUsed |
principal.application |
直接對應 |
initiatedBy.app.displayName |
principal.application |
直接對應 |
properties.Actor.ApplicationName |
principal.application |
直接對應 |
properties.servicePrincipal.Name |
principal.application |
直接對應 |
properties.servicePrincipalName |
principal.application |
直接對應 |
properties_initiatedBy_app_displayName |
principal.application |
直接對應 |
properties.deviceDetail.deviceId |
principal.asset.asset_id |
直接對應 |
isCompliant_label |
principal.asset.attribute.labels |
已合併 |
isManaged_label |
principal.asset.attribute.labels |
已合併 |
service_principal_id_label |
principal.asset.attribute.labels |
已合併 |
sourceSystem_label |
principal.asset.attribute.labels |
已合併 |
hardware |
principal.asset.hardware |
已合併 |
ip |
principal.asset.ip |
已合併 |
ip_addr |
principal.asset.ip |
已合併 |
ip_address |
principal.asset.ip |
已合併 |
ip_value |
principal.asset.ip |
已合併 |
principal_ip |
principal.asset.ip |
已合併 |
properties.sourceSystem.Id |
principal.asset.product_object_id |
直接對應 |
properties.deviceDetail.deviceId |
principal.asset_id |
直接對應 |
principal_hostname |
principal.hostname |
直接對應 |
ip |
principal.ip |
已合併 |
ip_addr |
principal.ip |
已合併 |
ip_address |
principal.ip |
已合併 |
ip_value |
principal.ip |
已合併 |
principal_ip |
principal.ip |
已合併 |
location.city |
principal.location.city |
已重新命名/對應 |
prop_loc_city |
principal.location.city |
直接對應 |
location.countryOrRegion |
principal.location.country_or_region |
已重新命名/對應 |
prop_loc_countryOrRegion |
principal.location.country_or_region |
直接對應 |
record_RoleLocation |
principal.location.name |
當 record_RoleLocation != `` 時對應 |
location.geoCoordinates.latitude |
principal.location.region_latitude |
已重新命名/對應 |
prop_loc_latitude |
principal.location.region_latitude |
直接對應 |
location.geoCoordinates.longitude |
principal.location.region_longitude |
已重新命名/對應 |
prop_loc_longitude |
principal.location.region_longitude |
直接對應 |
location.state |
principal.location.state |
已重新命名/對應 |
prop_loc_state |
principal.location.state |
直接對應 |
properties.deviceDetail.operatingSystem |
principal.platform_version |
直接對應 |
Identity_label |
principal.resource.attribute.labels |
已合併 |
_field |
principal.resource.attribute.labels |
已合併 |
activityDisplayName |
principal.resource.attribute.labels |
對應項目:「Add user」、「Update StsRefreshTokenValidFrom Timestamp」、「Disable account」、「Enable... |
app_id |
principal.resource.attribute.labels |
已合併 |
browser_label |
principal.resource.attribute.labels |
已合併 |
key |
principal.resource.attribute.labels |
已對應:"IsDelegatedAdmin", "Actor_Name", "PartnerTenantId" → map_field、`"resource_grou... |
map_field |
principal.resource.attribute.labels |
已合併 |
prop_clientAppType_label |
principal.resource.attribute.labels |
已合併 |
properties_initiatedBy_app_appId_label |
principal.resource.attribute.labels |
已合併 |
user_principal_name_label |
principal.resource.attribute.labels |
已合併 |
Resource |
principal.resource.name |
直接對應 |
ResourceId |
principal.resource.product_object_id |
直接對應 |
properties.Actor.Application |
principal.resource.product_object_id |
直接對應 |
record_identity_evidence_authorization_principalType |
principal.resource.resource_subtype |
當 record_identity_evidence_authorization_principalType != `` 時對應 |
Type |
principal.resource.type |
已對應:(?i)AuditLogs → AUDIT_LOG |
role |
principal.user.attribute.roles |
已合併 |
role_label |
principal.user.attribute.roles |
已合併 |
user_role |
principal.user.attribute.roles |
已合併 |
InitiatedBy.user.userPrincipalName |
principal.user.email_addresses |
已合併 |
activityDisplayName |
principal.user.email_addresses |
對應項目:「Add user」、「Update StsRefreshTokenValidFrom Timestamp」、「Disable account」、「Enable... |
email |
principal.user.email_addresses |
已合併 |
initiatedBy.user.userPrincipalName |
principal.user.email_addresses |
已合併 |
properties.sourceIdentity.details.UserPrincipalName |
principal.user.email_addresses |
已合併 |
properties_Actor_UPN |
principal.user.email_addresses |
已合併 |
CorrelationId |
principal.user.product_object_id |
直接對應 |
initiatedBy.app.servicePrincipalId |
principal.user.product_object_id |
直接對應 |
initiatedBy.user.id |
principal.user.product_object_id |
直接對應 |
properties.Actor.ObjectId |
principal.user.product_object_id |
直接對應 |
properties.servicePrincipalId |
principal.user.product_object_id |
直接對應 |
properties.sourceIdentity.Id |
principal.user.product_object_id |
直接對應 |
properties.sourceIdentity.details.id |
principal.user.product_object_id |
直接對應 |
properties_initiatedBy_app_servicePrincipalId |
principal.user.product_object_id |
直接對應 |
InitiatedBy.user.displayName |
principal.user.user_display_name |
直接對應 |
initiatedBy.user.displayName |
principal.user.user_display_name |
直接對應 |
initiatedBy.user.userPrincipalName |
principal.user.user_display_name |
直接對應 |
properties.sourceIdentity.Name |
principal.user.user_display_name |
直接對應 |
properties.sourceIdentity.details.DisplayName |
principal.user.user_display_name |
直接對應 |
user_name |
principal.user.user_display_name |
直接對應 |
InitiatedBy.app.servicePrincipalId |
principal.user.userid |
直接對應 |
InitiatedBy.user.id |
principal.user.userid |
直接對應 |
initiatedBy.app.servicePrincipalName |
principal.user.userid |
直接對應 |
initiatedBy.user.userPrincipalName |
principal.user.userid |
直接對應 |
properties.initiatedBy.Id |
principal.user.userid |
直接對應 |
record_identity_evidence_authorization_principalId |
principal.user.userid |
當 record_identity_evidence_authorization_principalId != `` 時對應 |
sec_result |
security_result |
已合併 |
Result |
security_result.action |
已對應:(?i)success → security_result_action_allow、(?i)failure → `security_result_act... |
action |
security_result.action |
已合併 |
operationName |
security_result.action |
已對應:Sign-in activity → action |
result |
security_result.action |
已對應:(?i)success → security_result_action_allow、(?i)failure → `security_result_act... |
resultType |
security_result.action |
已對應:0 → action |
security_result_action |
security_result.action |
已合併 |
security_result_action_allow |
security_result.action |
已合併 |
security_result_action_block |
security_result.action |
已合併 |
operationType |
security_result.action_details |
直接對應 |
resultType |
security_result.action_details |
直接對應 |
Category |
security_result.category |
已合併 |
operationName |
security_result.category |
已對應:Sign-in activity → Category |
Category |
security_result.category_details |
已對應:(?i)Device → Category |
properties_category |
security_result.category_details |
已合併 |
sec_result_category_details |
security_result.category_details |
已合併 |
Result |
security_result.description |
直接對應 |
properties.provisioningStatusInfo.errorInformation |
security_result.description |
直接對應 |
properties_status_additionalDetails |
security_result.description |
直接對應 |
resultDescription |
security_result.description |
直接對應 |
resultReason |
security_result.description |
直接對應 |
_field |
security_result.detection_fields |
已合併 |
auth_app_device_app_version_label |
security_result.detection_fields |
已合併 |
auth_app_device_client_app_label |
security_result.detection_fields |
已合併 |
auth_app_device_id_label |
security_result.detection_fields |
已合併 |
auth_app_device_os_label |
security_result.detection_fields |
已合併 |
auth_app_policy_adminConfiguration_label |
security_result.detection_fields |
已合併 |
auth_app_policy_authenticationEvaluation_label |
security_result.detection_fields |
已合併 |
auth_app_policy_policyName_label |
security_result.detection_fields |
已合併 |
auth_app_policy_status_label |
security_result.detection_fields |
已合併 |
auth_detail_label |
security_result.detection_fields |
已合併 |
auth_id_label |
security_result.detection_fields |
已合併 |
auth_proc_det_label |
security_result.detection_fields |
已合併 |
auth_req_label |
security_result.detection_fields |
已合併 |
caa_label |
security_result.detection_fields |
已合併 |
detection_authenticationMethod |
security_result.detection_fields |
已合併 |
detection_authenticationMethodDetail |
security_result.detection_fields |
已合併 |
detection_authenticationStepDateTime |
security_result.detection_fields |
已合併 |
detection_authenticationStepRequirement |
security_result.detection_fields |
已合併 |
detection_authenticationStepResultDetail |
security_result.detection_fields |
已合併 |
detection_detail |
security_result.detection_fields |
已合併 |
detection_networkName |
security_result.detection_fields |
已合併 |
detection_networkType |
security_result.detection_fields |
已合併 |
detection_requestSequence |
security_result.detection_fields |
已合併 |
detection_requirementProvider |
security_result.detection_fields |
已合併 |
detection_statusSequence |
security_result.detection_fields |
已合併 |
detection_succeeded |
security_result.detection_fields |
已合併 |
enforcedGrantControls_label |
security_result.detection_fields |
已合併 |
enforcedSessionControls_label |
security_result.detection_fields |
已合併 |
key |
security_result.detection_fields |
已對應:"cribl_source", "topic_name", "source_system", "internal_workspace_resource_id" → ... |
policy_conditionsNotSatisfied_label |
security_result.detection_fields |
已合併 |
policy_conditionsSatisfied_label |
security_result.detection_fields |
已合併 |
policy_displayName_label |
security_result.detection_fields |
已合併 |
policy_id_label |
security_result.detection_fields |
已合併 |
policy_result_label |
security_result.detection_fields |
已合併 |
resultType_label |
security_result.detection_fields |
已合併 |
riskLevelAggregated_label |
security_result.detection_fields |
已合併 |
session_lifetime_policy_detail_label |
security_result.detection_fields |
已合併 |
session_lifetime_policy_expirationRequirement_label |
security_result.detection_fields |
已合併 |
statusInfo_label |
security_result.detection_fields |
已合併 |
value_label |
security_result.detection_fields |
已合併 |
operationName |
security_result.priority |
已對應:Sign-in activity → MEDIUM_PRIORITY |
riskLevelDuringSignIn |
security_result.priority |
已對應:medium → MEDIUM_PRIORITY |
resultType |
security_result.rule_id |
直接對應 |
kv.value |
security_result.rule_name |
直接對應 |
Level |
security_result.severity |
對應值 (共 5 個,例如 "0", "1", "2" → CRITICAL、3 → ERROR、4 → HIGH) |
level |
security_result.severity |
已對應:(?i)informational/info → INFORMATIONAL |
operationName |
security_result.severity |
已對應:Sign-in activity → ERROR |
Level |
security_result.severity_details |
直接對應 |
level |
security_result.severity_details |
直接對應 |
AADOperationType |
security_result.summary |
直接對應 |
operationName |
security_result.summary |
已對應:Sign-in activity → Successful login occurred、Sign-in activity → `Failed login... |
properties.provisioningStatusInfo.Status |
security_result.summary |
直接對應 |
result |
security_result.summary |
直接對應 |
result1 |
security_result.summary |
直接對應 |
resultType |
security_result.summary |
已對應:0 → Successful login occurred |
prop_riskDetail |
security_result.threat_name |
直接對應 |
modified_properties_old_value_label |
src.resource.attribute.labels |
已合併 |
targetResourceType |
src.resource.attribute.labels |
已對應:"Device", "User", "Directory", "Application", "Group", "ServicePrincipal", "Role" ... |
target_domain |
target.administrative_domain |
直接對應 |
appDisplayName |
target.application |
直接對應 |
modifiedProperties.newValue |
target.asset.asset_id |
直接對應 |
targetSystem_ApplicationId_label |
target.asset.attribute.labels |
已合併 |
targetSystem_ServicePrincipalDisplayName_label |
target.asset.attribute.labels |
已合併 |
targetSystem_label |
target.asset.attribute.labels |
已合併 |
target_service_principal_label |
target.asset.attribute.labels |
已合併 |
kv.value |
target.asset.hostname |
直接對應 |
temp_display_name |
target.asset.hostname |
直接對應 |
properties.targetSystem.Id |
target.asset.product_object_id |
直接對應 |
grouptypelabel |
target.group.attribute.labels |
已合併 |
index |
target.group.attribute.labels |
已對應:0 → grouptypelabel |
targetResourceType |
target.group.attribute.labels |
已對應:Group → grouptypelabel |
modifiedProperties.newValue |
target.group.group_display_name |
直接對應 |
target.displayName |
target.group.group_display_name |
直接對應 |
modifiedProperties.newValue |
target.group.product_object_id |
直接對應 |
target.id |
target.group.product_object_id |
直接對應 |
kv.value |
target.hostname |
直接對應 |
temp_display_name |
target.hostname |
直接對應 |
target_ip |
target.ip |
已合併 |
kv.value |
target.process.pid |
直接對應 |
modified_properties_new_value_label_value |
target.process.pid |
直接對應 |
appId_label |
target.resource.attribute.labels |
已合併 |
app_id_label |
target.resource.attribute.labels |
已合併 |
authorization_scope_label |
target.resource.attribute.labels |
已合併 |
modifiedPropertie_label |
target.resource.attribute.labels |
已合併 |
modifiedProperty_name_label |
target.resource.attribute.labels |
已合併 |
modifiedProperty_new_value_label |
target.resource.attribute.labels |
已合併 |
modifiedProperty_old_value_label |
target.resource.attribute.labels |
已合併 |
modified_properties_new_value_label |
target.resource.attribute.labels |
已合併 |
newValue_label |
target.resource.attribute.labels |
已合併 |
targetResourceType |
target.resource.attribute.labels |
已對應:"Device", "User", "Directory", "Application", "Group", "ServicePrincipal", "Role" ... |
target_Name_label |
target.resource.attribute.labels |
已合併 |
target_resource_display_name_label |
target.resource.attribute.labels |
已合併 |
target_resource_id_label |
target.resource.attribute.labels |
已合併 |
type_label |
target.resource.attribute.labels |
已合併 |
role |
target.resource.attribute.roles |
已合併 |
targetResourceType |
target.resource.attribute.roles |
已對應:"Device", "User", "Directory", "Application", "Group", "ServicePrincipal", "Role" ... |
properties.resourceDisplayName |
target.resource.name |
直接對應 |
resourceDisplayName |
target.resource.name |
直接對應 |
temp_display_name |
target.resource.name |
直接對應 |
id |
target.resource.product_object_id |
直接對應 |
prop_resourceId |
target.resource.product_object_id |
直接對應 |
properties.TargetObjectIds.0 |
target.resource.product_object_id |
直接對應 |
targetResourceType |
target.resource.resource_subtype |
直接對應 |
activityDisplayName |
target.resource.type |
對應值 (共 38 個,例如 Add agreement → SETTING、「刪除協議」、「永久刪除... |
category |
target.resource.type |
對應值 (共 18 個,例如 Agreement → SETTING、ApplicationManagement → SETTING 等) |
loggedByService |
target.resource.type |
已對應:Core Directory → SETTING |
principal_ip_present |
target.resource.type |
已對應:true → SETTING |
type |
target.resource.type |
已對應:Device → DEVICE |
kv.value |
target.url |
直接對應 |
user_attribute_labels |
target.user.attribute.labels |
已合併 |
role |
target.user.attribute.roles |
已合併 |
modifiedProperties.newValue |
target.user.department |
已合併 |
targetResourceType |
target.user.department |
已對應:"Device", "User", "Directory", "Application", "Group", "ServicePrincipal", "Role" ... |
activityDisplayName |
target.user.email_addresses |
已對應:Add member to role outside of PIM (permanent) → target.userPrincipalName |
kv.value |
target.user.email_addresses |
已合併 |
modifiedProperties.newValue |
target.user.email_addresses |
已合併 |
targer_user_principal_name |
target.user.email_addresses |
已對應:(^.*@.*$) → target.userPrincipalName |
target.userPrincipalName |
target.user.email_addresses |
已合併 |
targetResourceType |
target.user.email_addresses |
對應:User → target.userPrincipalName、`"Device", "User", "Directory", "Application", ... |
target_email |
target.user.email_addresses |
已合併 |
temp_display_name |
target.user.email_addresses |
已對應:(^.*@.*$) → temp_display_name |
modifiedProperties.newValue |
target.user.employee_id |
直接對應 |
modifiedProperties.newValue |
target.user.first_name |
直接對應 |
modifiedProperties.newValue |
target.user.last_name |
直接對應 |
modifiedProperties.newValue |
target.user.office_address.name |
直接對應 |
kv.value |
target.user.phone_numbers |
已合併 |
modifiedProperties.newValue |
target.user.phone_numbers |
已合併 |
mp.newValue |
target.user.phone_numbers |
已合併 |
targetResourceType |
target.user.phone_numbers |
已對應:"Device", "User", "Directory", "Application", "Group", "ServicePrincipal", "Role" ... |
modifiedProperties.newValue |
target.user.product_object_id |
直接對應 |
properties.targetIdentity.Id |
target.user.product_object_id |
直接對應 |
target.id |
target.user.product_object_id |
直接對應 |
userId |
target.user.product_object_id |
直接對應 |
modifiedProperties.newValue |
target.user.title |
直接對應 |
TargetResource_displayName |
target.user.user_display_name |
直接對應 |
identity |
target.user.user_display_name |
直接對應 |
modifiedProperties.newValue |
target.user.user_display_name |
直接對應 |
mp.newValue |
target.user.user_display_name |
直接對應 |
properties.TargetDisplayNames.0 |
target.user.user_display_name |
直接對應 |
properties.targetIdentity.Name |
target.user.user_display_name |
直接對應 |
properties.userDisplayName |
target.user.user_display_name |
直接對應 |
target.displayName |
target.user.user_display_name |
直接對應 |
target_user_name |
target.user.user_display_name |
直接對應 |
userPrincipalName |
target.user.user_display_name |
直接對應 |
TargetResource_id |
target.user.userid |
直接對應 |
identity |
target.user.userid |
直接對應 |
kv.value |
target.user.userid |
直接對應 |
modifiedProperties.newValue |
target.user.userid |
直接對應 |
prop_alternateSignInName |
target.user.userid |
直接對應 |
prop_signInIdentifier |
target.user.userid |
直接對應 |
prop_userPrincipalName |
target.user.userid |
直接對應 |
userPrincipalName |
target.user.userid |
直接對應 |
DATA:target_domain |
target.userPrincipalName |
直接對應 |
DATA:tgt_user_principal_name |
target.userPrincipalName |
直接對應 |
| 不適用 | extensions.auth.type |
常數:SSO |
| 不適用 | metadata.event_type |
常數:USER_LOGIN |
| 不適用 | metadata.product_name |
常數:Azure AD Directory Audit |
| 不適用 | metadata.vendor_name |
常數:Microsoft |
| 不適用 | network.http.parsed_user_agent |
常數:parseduseragent |
| 不適用 | principal.resource.type |
常數:AUDIT_LOG |
| 不適用 | security_result.priority |
常數:MEDIUM_PRIORITY |
| 不適用 | security_result.severity |
常數:INFORMATIONAL |
| 不適用 | security_result.summary |
常數:Successful login occurred |
| 不適用 | target.resource.type |
常數:DEVICE |
變更記錄
還有其他問題嗎?向社群成員和 Google SecOps 專業人員尋求答案。