Elastic Agent Azure Logs Integration missing related.users #9145
Labels
bug
Something isn't working, use only for issues
Integration:azure
Azure Logs
Team:Cloud-Monitoring
Label for the Cloud Monitoring team
Uh oh!
There was an error while loading. Please reload this page.
Hello,
Just migrated from Filebeat azure module to Elastic Agent Azure Logs integration and I noticed some issues.
There seems to be no
related.users
field for the signin logs. THis is unfortunate, as this field is very usable to correlate data.The user.name filed is populated correctly for the
SignInLogs
but not for theServicePrincipalSignInLogs
. The field containing theServicePrincipalSignInUser
isazure.signinlogs.properties.service_principal_name
. The value of this field should be copied touser.name
and torelated.users
An example sanitized log:
The text was updated successfully, but these errors were encountered: