AzureDevOpsAuditing

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index


Reference for AzureDevOpsAuditing table in Azure Monitor Logs.

Attribute Value
Category -
Basic Logs Eligible ✓ Yes (source)
Supports Transformations ✓ Yes (source)
Ingestion API Supported ✗ No
Azure Monitor Tables Reference View Documentation

Contents

Schema (28 columns)

Source: Azure Monitor documentation

Column Name Type Description
_BilledSize real The record size in bytes
_IsBillable string Specifies whether ingesting the data is billable. When _IsBillable is false ingestion isn't billed to your Azure account
ActivityId string Unique identifier for the action that occurred.
ActorClientId string When the action was performed by a managed identity or other service principal, this value represents the client ID of that principal. Otherwise, this value is 00000000-0000-0000-0000-000000000000. When this field is populated, ActorCUID and ActorUserId will both be 00000000-0000-0000-0000-000000000000.
ActorCUID string When the action was performed by a user, this value represents a consistently unique identifier for that actor. Otherwise, this value is 00000000-0000-0000-0000-000000000000. When this field, along with ActorUserId, is populated, ActorClientId will be 00000000-0000-0000-0000-000000000000.
ActorDisplayName string Display name of the user who initiated the auditing event to be logged.
ActorUPN string The actor's user principal name.
ActorUserId string When the action was performed by a user or Azure DevOps service, this value represents that actor's user identifier. Otherwise, this value is 00000000-0000-0000-0000-000000000000. When this field, along with ActorUserId, is populated, ActorClientId will be 00000000-0000-0000-0000-000000000000.
Area string Part of the Azure DevOps product where the auditing event occurred.
AuthenticationMechanism string Type of authentication used by the actor.
Category string Type of action that occurred when the auditing event was logged.
CategoryDisplayName string Type of action that occurred when the auditing event was logged.
CorrelationId string CorrelationId allows two or more auditing events to be grouped together. This happens when a single action causes a cascade of auditing entries. An example being project creation.
Data dynamic Additional data that's unique to the type of auditing event.
Details string Description of what happened.
Id string The identifier for the audit event, unique across services.
IpAddress string IP address where the event originated.
OperationName string The unique identifier for the type of auditing event that occurred. For example, Git.CreateRepo identifies the an auditing event for Git repository creation.
ProjectId string Unique identifier of the project that an auditing event occurred in. If not provided then the event isn't scoped to a particular project.
ProjectName string Friendly name of the project that an auditing event occurred in. If not provided then the event isn't scoped to a particular project.
ScopeDisplayName string User friendly name for the scope level that an auditing event occurred at.
ScopeId string The organization identifier.
ScopeType string The level (scope) that the event occurred.
SourceSystem string The type of agent the event was collected by. For example, OpsManager for Windows agent, either direct connect or Operations Manager, Linux for all Linux agents, or Azure for Azure Diagnostics
TenantId string The Log Analytics workspace ID
TimeGenerated datetime The time the auditing event occurred in UTC.
Type string The name of the table
UserAgent string The user agent from the request.

Schema References

Official Microsoft Learn documentation for field/column information:

Solutions (3)

This table is used by the following solutions:


Content Items Using This Table (38)

Analytic Rules (19)

In solution AzureDevOpsAuditing:

Analytic Rule Selection Criteria
Azure DevOps Administrator Group Monitoring
Azure DevOps Agent Pool Created Then Deleted
Azure DevOps Audit Detection for known malicious tooling
Azure DevOps Audit Stream Disabled
Azure DevOps Build Variable Modified by New User
Azure DevOps New Extension Added
Azure DevOps PAT used with Browser
Azure DevOps Personal Access Token (PAT) misuse
Azure DevOps Pipeline Created and Deleted on the Same Day
Azure DevOps Pipeline modified by a new user
Azure DevOps Pull Request Policy Bypassing - Historic allow list
Azure DevOps Retention Reduced
Azure DevOps Service Connection Abuse
Azure DevOps Service Connection Addition/Abuse - Historic allow list
Azure DevOps Variable Secret Not Secured
External Upstream Source Added to Azure DevOps Feed
NRT Azure DevOps Audit Stream Disabled
New Agent Added to Pool by New User or Added to a New OS Type
New PA, PCA, or PCAS added to Azure DevOps

Hunting Queries (17)

In solution AzureDevOpsAuditing:

Hunting Query Selection Criteria
Azure DevOps - Build Check Deleted
Azure DevOps - Build Deleted After Pipeline Modification
Azure DevOps - Internal Upstream Package Feed Added
Azure DevOps - New Agent Pool Created
Azure DevOps - New PAT Operation
Azure DevOps - New Package Feed Created
Azure DevOps - New Release Approver
Azure DevOps - New Release Pipeline Created
Azure DevOps - Variable Created and Deleted
Azure DevOps Display Name Changes
Azure DevOps Pull Request Policy Bypassing
Azure DevOps- Addtional Org Admin added
Azure DevOps- Guest users access enabled
Azure DevOps- Microsoft Entra ID Protection Conditional Access Disabled
Azure DevOps- Project visibility changed to public
Azure DevOps- Public project created
Azure DevOps- Public project enabled by admin

Workbooks (2)

In solution AzureSecurityBenchmark:

Workbook Selection Criteria
AzureSecurityBenchmark

In solution ContinuousDiagnostics&Mitigation:

Workbook Selection Criteria
ContinuousDiagnostics&Mitigation

Parsers Using This Table (1)

Other Parsers (1)

Parser Solution Selection Criteria
ADOAuditLogs AzureDevOpsAuditing

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index