Change log for AZURE_AD_SIGNIN

Date Changes
2026-04-20 Enhancement:
- event.idm.read_only_udm.target.user.userid: Removed mapping of properties.userId from event.idm.read_only_udm.target.user.userid UDM field since properties.userId represents the product object id of the user.
- event.idm.read_only_udm.target.user.product_object_id: Mapped properties.userId raw log field with event.idm.read_only_udm.target.user.product_object_id UDM field.
- event.idm.read_only_udm.principal.application: Removed mapping of properties.appDisplayName from event.idm.read_only_udm.principal.application UDM field since properties.appDisplayName represents the application name of the target resource.
- event.idm.read_only_udm.target.application: Mapped properties.appDisplayName raw log field with event.idm.read_only_udm.target.application UDM field.
- event.idm.read_only_udm.target.application: Removed mapping of resourceDisplayName from event.idm.read_only_udm.target.application UDM field since properties.resourceDisplayName represents the resource display name of the target resource.
- event.idm.read_only_udm.security_result.detection_fields: Mapped resourceDisplayName raw log field with event.idm.read_only_udm.security_result.detection_fields UDM field.
- event.idm.read_only_udm.security_result.detection_fields: Removed mapping of clientAppUsed from event.idm.read_only_udm.security_result.detection_fields UDM field in order to introduce more specific mapping.
- event.idm.read_only_udm.principal.application: Mapped clientAppUsed raw log field with event.idm.read_only_udm.principal.application UDM field.
- event.idm.read_only_udm.security_result.detection_fields: Removed mapping of deviceDetail.deviceId from event.idm.read_only_udm.security_result.detection_fields UDM field in order to introduce more specific mapping.
- event.idm.read_only_udm.principal.asset_id and event.idm.read_only_udm.principal.asset.asset_id: Mapped deviceDetail.deviceId raw log field with event.idm.read_only_udm.principal.asset_id and event.idm.read_only_udm.principal.asset.asset_id UDM field.
- event.idm.read_only_udm.security_result.detection_fields: Removed mapping of deviceDetail.isCompliant from event.idm.read_only_udm.security_result.detection_fields UDM field in order to introduce more specific mapping.
- event.idm.read_only_udm.principal.asset.attribute.labels: Mapped deviceDetail.isCompliant raw log field with event.idm.read_only_udm.principal.asset.attribute.labels UDM field.
- event.idm.read_only_udm.security_result.detection_fields: Removed mapping of deviceDetail.isManaged from event.idm.read_only_udm.security_result.detection_fields UDM field in order to introduce more specific mapping.
- event.idm.read_only_udm.principal.asset.attribute.labels: Mapped deviceDetail.isManaged raw log field with event.idm.read_only_udm.principal.asset.attribute.labels UDM field.
- event.idm.read_only_udm.security_result.detection_fields: Removed mapping of deviceDetail.trustType from event.idm.read_only_udm.security_result.detection_fields UDM field in order to introduce more specific mapping.
- event.idm.read_only_udm.principal.asset.attribute.labels: Mapped deviceDetail.trustType raw log field with event.idm.read_only_udm.principal.asset.attribute.labels UDM field.
- event.idm.read_only_udm.security_result.detection_fields: Removed mapping of properties.deviceDetail.browser from event.idm.read_only_udm.security_result.detection_fields UDM field in order to introduce more specific mapping.
- event.idm.read_only_udm.principal.asset.attribute.labels: Mapped properties.deviceDetail.browser raw log field with event.idm.read_only_udm.principal.asset.attribute.labels UDM field.
- event.idm.read_only_udm.security_result.detection_fields: Removed mapping of DeviceDetail.displayName from event.idm.read_only_udm.security_result.detection_fields UDM field since DeviceDetail.displayName consists of hostname details.
- event.idm.read_only_udm.principal.hostname and event.idm.read_only_udm.principal.asset.hostname: Mapped properties.deviceDetail.displayName raw log field with event.idm.read_only_udm.principal.hostname and event.idm.read_only_udm.principal.asset.hostname UDM field.
- event.idm.read_only_udm.security_result.detection_fields: Removed mapping of properties.appId from event.idm.read_only_udm.security_result.detection_fields UDM field since properties.appId consists of application id of the target resource.
- event.idm.read_only_udm.target.resource.product_object_id: Mapped properties.appId raw log field with event.idm.read_only_udm.target.resource.product_object_id UDM field.
- event.idm.read_only_udm.target.user.email_address: Newly mapped properties.userPrincipalName raw log field with event.idm.read_only_udm.target.user.email_address UDM field, if properties.userPrincipalName is an email address.
- event.idm.read_only_udm.target.user.userid: Newly mapped properties.userPrincipalName raw log field with event.idm.read_only_udm.target.user.userid UDM field, if properties.userPrincipalName is not an email address.
- event.idm.read_only_udm.principal.location.country_or_region: Newly mapped properties.location.countryOrRegion raw log field with event.idm.read_only_udm.principal.location.country_or_region UDM field.
- event.idm.read_only_udm.target.ip and event.idm.read_only_udm.target.asset.ip: Newly mapped ip_address_from_resource_provider raw log field with event.idm.read_only_udm.target.ip and event.idm.read_only_udm.target.asset.ip UDM field.
- event.idm.read_only_udm.target.url: Newly mapped properties.redirectUrl raw log field with event.idm.read_only_udm.target.url UDM field.
- event.idm.read_only_udm.principal.user.attribute.labels: Newly mapped properties.homeTenantName raw log field with event.idm.read_only_udm.principal.user.attribute.labels UDM field.
- event.idm.read_only_udm.security_result.detection_fields: Newly mapped properties.deviceDetail.operatingSystem, properties.originalTransferMethod, properties.authenticationProtocol raw log fields with event.idm.read_only_udm.security_result.detection_fields UDM field.
- event.idm.read_only_udm.principal.asset.attribute.labels: Newly mapped properties.federatedCredentialId, properties.servicePrincipalCredentialKeyId, properties.servicePrincipalCredentialThumbprint, properties.sourceAppClientId, properties.appServicePrincipalId, properties.signInIdentifier, properties.alternateSignInName, properties.riskLevelDuringSignIn, properties.riskEventTypes, properties.riskEventTypes_v2, properties.authenticationRequirementPolicies, properties.sessionLifetimePolicies, properties.authenticationStrengths raw log fields with event.idm.read_only_udm.principal.asset.attribute.labels UDM field.
- Added a grok pattern on properties.ipAddressFromResourceProvider to extract ip_address_from_resource_provider.
- Newly added JSON filter to parse DeviceDetail raw log field.
2026-02-12 Enhancement:
- event.idm.read_only_udm.security_result.rule_labels: Newly mapped properties.appliedConditionalAccessPolicies.conditionsSatisfied, properties.appliedConditionalAccessPolicies.conditionsNotSatisfied raw log field with event.idm.read_only_udm.security_result.rule_labels.
- Added a conditional check before mapping existing properties.appliedConditionalAccessPolicies.displayName, properties.appliedConditionalAccessPolicies.id, properties.appliedConditionalAccessPolicies.result, properties.appliedConditionalAccessPolicies.enforcedGrantControls, properties.appliedConditionalAccessPolicies.enforcedSessionControls for these raw log fields. Updated and corrected mappings for these raw log fields to parse these raw log fields in correct manner.
2026-01-28 Enhancement:
- event.idm.read_only_udm.metadata.event_timestamp: Removed mapping of TimeGenerated raw log field(s) from event.idm.read_only_udm.metadata.event_timestamp UDM field to avoid if/else-if logic conflicts with CreatedDateTime, ensuring both fields are captured independently when TimeGenerated is remapped to metadata.collected_timestamp.
- event.idm.read_only_udm.metadata.collected_timestamp: Mapped TimeGenerated raw log field(s) with event.idm.read_only_udm.metadata.collected_timestamp UDM field.
- event.idm.read_only_udm.additional.fields: Added prefix DeviceDetail_ to the keys for AuthenticationProcessingDetails raw log field.
- event.idm.read_only_udm.additional.fields: Updated the logic for AuthenticationContextClassReferences to parse as a JSON array instead of a single string, ensuring each key-value pair is individually extracted and searchable.
2026-01-22 Enhancement:
- event.idm.read_only_udm.additional.fields : Newly mapped authenticationRequirement, RiskEventTypes raw log field with event.idm.read_only_udm.additional.fields UDM field.
2025-12-19 Enhancement:
- event.idm.read_only_udm.network.http.response_code: Newly mapped Status.errorCode raw log field with event.idm.read_only_udm.network.http.response_code UDM field.
- event.idm.read_only_udm.security_result.summary: Newly mapped Status.failureReason raw log field with event.idm.read_only_udm.security_result.summary UDM field.
- event.idm.read_only_udm.security_result.detection_fields: Newly mapped cribl.cribl_data.cribl_enrichment.topic_name, cribl.cribl_data.cribl_enrichment.cribl_source, AlternateSignInName, SignInIdentifier, DeviceDetail.deviceId, DeviceDetail.trustType, TokenIssuerName, AADTenantId, authdetail.authenticationMethod, authdetail.authenticationMethodDetail, authdetail.authenticationStepDateTime, authdetail.authenticationStepRequirement, authdetail.authenticationStepResultDetail, networklocation.networkType, networklocation.networkNames raw log fields with event.idm.read_only_udm.security_result.detection_fields UDM field.
- event.idm.read_only_udm.security_result.action_details: Newly mapped authdetail.succeeded raw log field with event.idm.read_only_udm.security_result.action_details UDM field.
- event.idm.read_only_udm.security_result.action: Newly mapped authdetail.succeeded raw log field with event.idm.read_only_udm.security_result.action UDM field.
- Renamed raw field ClientAppUsed to clientAppUsed before JSON parsing to parse the field correctly.
- Removed PII data from the log file.
2025-12-10 Enhancement:
- event.idm.read_only_udm.additional.fields: Newly mapped Agent.agentType, AuthenticationContextClassReferences, AuthenticationProtocol, AuthenticationRequirement, ClientCredentialType, TimeGenerated, AuthenticationProcessingDetails raw log field(s) with event.idm.read_only_udm.additional.fields UDM field.
- event.idm.read_only_udm.security_result.detection_fields: Newly mapped IsInteractive, DeviceDetail.displayName, OperationVersion, AppOwnerTenantId, CrossTenantAccessType, IsTenantRestricted, IsThroughGlobalSecureAccess, Type, _TimeReceived, AuthenticationRequirementPolicies raw log field(s) with event.idm.read_only_udm.security_result.detection_fields UDM field.
- event.idm.read_only_udm.metadata.timestamp: Newly mapped CreatedDateTime raw log field with event.idm.read_only_udm.metadata.event_timestamp UDM field.
2025-07-01 Enhancement:
- Replaced values of new raw log field names to their corresponding old raw log field names to map data to UDM fields using existing mappings as follows:
-- RiskDetail -> riskDetail
-- RiskLevelAggregated -> riskLevelAggregated
-- RiskLevelDuringSignIn -> riskLevelDuringSignIn
-- RiskState -> riskState
-- ResourceDisplayName -> resourceDisplayName
-- ResourceId -> resourceId
-- ResultSignature -> resultSignature
- Added a condition check to process the ConditionalAccessPolicies raw log field only when it contains a string value it can enter into mappings of ConditionalAccessPolicies raw log field mapping to prevent parsing errors.
- Newly added for loop for ConditionalAccessPolicies , apc.enforcedSessionControls , and apc.enforcedGrantControls raw log field to parse its respective fields.
- event.idm.read_only_udm.security_result.rule_name : Newly mapped apc.displayName raw log field with event.idm.read_only_udm.security_result.rule_name UDM field.
- event.idm.read_only_udm.security_result.rule_id : Newly mapped apc.id raw log field with event.idm.read_only_udm.security_result.rule_id UDM field.
- event.idm.read_only_udm.security_result.rule_labels : Newly mapped apc.Result, apc.conditionsSatisfied, apc.conditionsNotSatisfied , apc.enforcedGrantControls , and apc.enforcedSessionControls raw log field with event.idm.read_only_udm.security_result.rule_labels UDM field.
- event.idm.read_only_udm.security_result.detection_fields : Newly mapped SourceSystem, SessionLifetimePolicies, SessionId, ResourceTenantId, ResourceOwnerTenantId, TokenProtectionStatusDetails.signInSessionStatusCode, TokenProtectionStatusDetails.signInSessionStatus, DeviceDetail.browser, DeviceDetail.operatingSystem raw log fields with event.idm.read_only_udm.security_result.detection_fields UDM field.
- event.idm.read_only_udm.principal.user.attribute.labels : Newly mapped ResourceServicePrincipalId raw log field with event.idm.read_only_udm.principal.user.attribute.labels UDM field.
- event.idm.read_only_udm.target.resource.attribute.labels : Newly mapped ResourceIdentity raw log field with event.idm.read_only_udm.target.resource.attribute.labels UDM field.
- event.idm.read_only_udm.additional.fields : Newly mapped Resource, ProcessingTimeInMilliseconds, OriginalTransferMethod, OriginalRequestId, Status.additionalDetails, RiskEventTypes_V2, IncomingTokenType raw log fields with event.idm.read_only_udm.additional.fields UDM field.
- event.idm.read_only_udm.principal.location.city : Newly mapped LocationDetails.city raw log field with event.idm.read_only_udm.principal.location.city UDM field.
- event.idm.read_only_udm.principal.location.country_or_region : Newly mapped LocationDetails.countryOrRegion raw log field with event.idm.read_only_udm.principal.location.country_or_region UDM field.
- event.idm.read_only_udm.principal.location.state : Newly mapped LocationDetails.state raw log field with event.idm.read_only_udm.principal.location.state UDM field.
- event.idm.read_only_udm.principal.location.region_coordinates.latitude : Newly mapped LocationDetails.geoCoordinates.latitude raw log field with event.idm.read_only_udm.principal.location.region_coordinates.latitude UDM field.
- event.idm.read_only_udm.principal.location.region_coordinates.longitude : Newly mapped LocationDetails.geoCoordinates.longitude raw log field with event.idm.read_only_udm.principal.location.region_coordinates.longitude UDM field.
2024-10-17 Enhancement:
- Mapped userDisplayName to principal.user.user_display_name.
- Mapped userPrincipalName to principal.user.email_addresses.
- Mapped appDisplayName to principal.application.
- Mapped ipAddress to principal.ip and principal.asset.ip.
- Mapped userId to principal.user.userid.
- Mapped resourceDisplayName to target.application.
- Mapped status.errorCode to network.http.response_code.
- Mapped failureReason to security_result.summary.
- Mapped deviceDetail.operatingSystem to principal.platform.
- Mapped appId, clientAppUsed, conditionalAccessStatus, deviceDetail.deviceId, deviceDetail.deviceName, deviceDetail.browser, deviceDetail.isCompliant, deviceDetail.isManaged, and deviceDetail.trustType to security_result.detection_fields.
- Mapped location.city to principal.location.city.
- Mapped location.state to principal.location.state.
- Mapped location.countryOrRegion to principal.location.country_or_region.
- Mapped location.geoCoordinates.latitude to principal.location.region_coordinates.latitude.
- Mapped location.geoCoordinates.longitude to principal.location.region_coordinates.longitude.
2024-07-18 Enhancement:
- Added support for JSON logs containing array of logs.
2024-05-07 - Newly created parser.