Azure Monitor Logs reference - AuditLogs (2024)

AADOperationTypestringType of the operation. Possible values areAddUpdateDelete andOther.AADTenantIdstringID of the ADD tenantActivityDateTimedatetimeDate and time the activity was performed in UTC.ActivityDisplayNamestringActivity name or the operation name. Examples include Create User and Add member to group. For full list see Azure AD activity list.AdditionalDetailsdynamicIndicates additional details on the activity._BilledSizerealThe record size in bytesCategorystringCurrently Audit is the only supported value.CorrelationIdstringOptional GUID that's passed by the client. Can help correlate client-side operations with server-side operations and is useful when tracking logs that span services.DurationMslongProperty is not used and can be ignored.IdstringGUID that uniquely identifies the activity.IdentitystringIdentity from the token that was presented when the request was made. The identity can be a user account system account or service principal.InitiatedBydynamicUser or app initiated the activity._IsBillablestringSpecifies whether ingesting the data is billable. When _IsBillable is false ingestion isn't billed to your Azure accountLevelstringMessage type. This is currently always Informational.LocationstringLocation of the datacenter.LoggedByServicestringService that initiated the activity (For example: Self-service Password Management Core Directory B2C Invited Users Microsoft Identity Manager Privileged Identity Management.OperationNamestringName of the operation.OperationVersionstringREST API version that's requested by the client.ResourcestringResourceGroupstringResourceIdstringResourceProviderstringResultstringResult of the activity. Possible values are: success failure timeout unknownFutureValue.ResultDescriptionstringAdditional description of the result.ResultReasonstringDescribes cause of failure or timeout results.ResultSignaturestringProperty is not used and can be ignored.ResultTypestringResult of the operation. Possible values are Success and Failure.SourceSystemstringThe type of agent the event was collected by. For example, OpsManager for Windows agent, either direct connect or Operations Manager, Linux for all Linux agents, or Azure for Azure DiagnosticsTargetResourcesdynamicIndicates information on which resource was changed due to the activity. Target Resource Type can be User Device Directory App Role Group Policy or Other.TimeGenerateddatetimeDate and time the record was created.TypestringThe name of the table
Azure Monitor Logs reference - AuditLogs (2024)
Top Articles
Latest Posts
Article information

Author: Tuan Roob DDS

Last Updated:

Views: 6042

Rating: 4.1 / 5 (62 voted)

Reviews: 85% of readers found this page helpful

Author information

Name: Tuan Roob DDS

Birthday: 1999-11-20

Address: Suite 592 642 Pfannerstill Island, South Keila, LA 74970-3076

Phone: +9617721773649

Job: Marketing Producer

Hobby: Skydiving, Flag Football, Knitting, Running, Lego building, Hunting, Juggling

Introduction: My name is Tuan Roob DDS, I am a friendly, good, energetic, faithful, fantastic, gentle, enchanting person who loves writing and wants to share my knowledge and understanding with you.