Solution: BeyondTrustPMCloud
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
| Attribute | Value |
|---|---|
| Publisher | BeyondTrust |
| Support Tier | Partner |
| Support Link | https://www.beyondtrust.com/ |
| Categories | domains |
| Version | 3.0.0 |
| Author | BeyondTrust - mysupport@beyondtrust.com |
| First Published | 2025-10-31 |
| Last Updated | 2026-02-27 |
| Solution Folder | BeyondTrustPMCloud |
| Marketplace | Azure Marketplace · Popularity: ⚪ Very Low (0%) |
The BeyondTrust PM Cloud solution provides a data connector to ingest activity audit logs and client event logs from BeyondTrust Privilege Management Cloud into Microsoft Sentinel.
Underlying Microsoft Technologies used:
This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:
a. Azure Monitor Logs Ingestion API
This solution provides 1 data connector(s):
This solution uses 2 table(s):
| Table | Used By Connectors | Used By Content |
|---|---|---|
BeyondTrustPM_ActivityAudits_CL |
BeyondTrust PM Cloud | Workbooks |
BeyondTrustPM_ClientEvents_CL |
BeyondTrust PM Cloud | Workbooks |
This solution includes 1 content item(s):
| Content Type | Count |
|---|---|
| Workbooks | 1 |
| Name | Tables Used |
|---|---|
| BeyondTrustPMCloud | BeyondTrustPM_ActivityAudits_CLBeyondTrustPM_ClientEvents_CL |
📄 Source: BeyondTrustPMCloud/README.md
The BeyondTrust PM Cloud solution provides comprehensive visibility into privilege management activities and endpoint security events from BeyondTrust Privilege Management Cloud.
Included Components: - Data Connectors: 1 - Workbooks: 1
Solution Overview\ Connector Attributes\ Data Tables\ Query Samples\ Prerequisites\ Installation\ Next Steps
| Connector attribute | Description |
|---|---|
| Azure function app code | https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/BeyondTrustPMCloud/Data%20Connectors |
| Log Analytics table(s) | BeyondTrustPM_ActivityAudits_CL BeyondTrustPM_ClientEvents_CL |
| Data collection rules support | Yes (Logs Ingestion API with DCRs) |
| Supported by | BeyondTrust |
The connector automatically creates two custom tables in your Log Analytics workspace during deployment:
BeyondTrustPM_ActivityAudits_CL (~40 columns) - Administrative activities, policy changes, user management, configuration auditsBeyondTrustPM_ClientEvents_CL (~50+ columns) - Endpoint security events in Elastic Common Schema (ECS) format with comprehensive host, user, file, and process contextThe data connector retrieves data from two primary API endpoints:
/v3/ActivityAudits/Details) - Administrative and configuration activities/v3/Events/FromStartDate) - Endpoint security events in ECS formatThe connector uses: - Authentication: OAuth 2.0 client credentials flow - Ingestion: Azure Monitor Logs Ingestion API with Data Collection Rules (DCRs) - Rate Limiting: Compliance with BeyondTrust API limits (1000 requests per 100 seconds) - State Management: Azure Table Storage for incremental data retrieval
BeyondTrustPM_ActivityAudits_CL
| sort by TimeGenerated desc
BeyondTrustPM_ClientEvents_CL
| sort by TimeGenerated desc
To integrate with BeyondTrust PM Cloud make sure you have the following:
[Content truncated...]
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.0.0 | 31-10-2025 | Initial Release |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊