Activity log key fields
The key fields in the subscription/activity log schema are:
-
identity.claims: nested JSON with information about the identity that performed the action and its authentication method.-
identity.claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn: theUPNof the identity that performed the action. -
identity.claims.groups: the AzureAD groups of which the identity is a member. -
identity.claims.ipaddr: the IP address the identity authenticated from.
-
-
callerIpAddress: the IP address the action was performed from. -
resourceId: the unique resource identifier of the resource. TheresourceIdfollows the format:/SUBSCRIPTIONS/<SUBSCRIPTION_ID>/RESOURCEGROUPS/<RESOURCEGROUP_NAME>/PROVIDERS/<PROVIDER>/<RESOURCE_NAME>.The provider can for example be
/MICROSOFT.COMPUTE/VIRTUALMACHINESorMICROSOFT.STORAGE/STORAGEACCOUNTS. -
operationName: the name of the operation.Examples:
MICROSOFT.AUTHORIZATION/ROLEASSIGNMENTS/WRITEMICROSOFT.COMPUTE/VIRTUALMACHINES/WRITEMICROSOFT.COMPUTE/VIRTUALMACHINES/START/ACTIONMICROSOFT.COMPUTE/VIRTUALMACHINES/DELETEMICROSOFT.COMPUTE/DISKS/WRITEMICROSOFT.STORAGE/STORAGEACCOUNTS/LISTKEYS/ACTION- …
-
resultTypeandresultSignature(more verbose): the result of the operation. -
correlationId: an unique identifier that can be used to map the different events associated with a single operation.
View on GitHub