---
title: "Azure Activity Logs"
slug: "azure-activity-logs"
tags: ["Self Ingestion"]
updated: 2024-12-05T11:27:39Z
published: 2024-12-05T11:27:39Z
canonical: "docs.hunters.ai/azure-activity-logs"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hunters.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Azure Activity Logs

Self Service Ingestion

          

Connect this data source on your own, using the Hunters platform.

## Overview

**Table name:** `azure_activity`

Azure Activity Logs provide a record of management events for resources in an Azure subscription, including information about operations such as creating, updating, and deleting resources.

## Send data to Hunters

Hunters supports the ingestion of these logs using Azure Event Hub. Follow the steps below to complete the connection.

### STEP 1: Set up Azure Event Hub

Before setting up the connection on the Hunters platform, you'll need to set up and create an Azure Event Hub.

Follow [this guide](https://docs.hunters.ai/docs/connect-data-through-azure-event-hub) to complete the set up.

### STEP 2: Route logs to the Event Hub

1. In the Azure portal home screen, open the side menu and click **Monitor**. ![Azure Monitor](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/Entra%20ID%20-%20Monitor.jpg)
2. Now click **Activity log**. ![Entra ID.Monitor.Activity Log](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/Entra%20ID.Monitor.Activity%20Log.jpg)
3. Click **Export Activity Logs**. ![Entra ID.Monitor.Activity Log.Export.](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/Entra%20ID.Monitor.Activity%20Log.Export.jpg)

The Diagnostic Settings page opens.
4. Click **Add Diagnostic setting**. ![Entra ID.Monitor.Activity Log.Export.Add diagnostic](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/Entra%20ID.Monitor.Activity%20Log.Export.Add%20diagnostic.jpg)
5. Under **Logs**, check all of the boxes.
6. Under **Destination details**, check the **Stream to an Event Hub** option.
7. Fill in the requested details and give the diagnostic setting a name. ![Activity log.Diagnostic Settings. Event Hub](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/Activity%20log.Diagnostic%20Settings.%20Event%20Hub.jpg)
8. Click **Save**.

### STEP 3: Set up the connection on Hunters

          📘 Before you begin

          To complete this process you will need the information gathered when following [this guide](https://docs.hunters.ai/docs/connect-data-through-azure-event-hub).

**To connect logs to Hunters:**

1. Open the Hunters platform and navigate to **Data > Data Sources**.  

![Data sources1](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/Data%20sources%281%29.png)
2. Click **ADD DATA SOURCES**.  

![Add data source4](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/Add%20data%20source%284%29.png)
3. Locate the **Microsoft Azure** panel and click **Connect**.  

The Add Data Flows window opens.
4. Fill in the required Azure application details, as gathered [here](https://docs.hunters.ai/docs/connect-data-through-azure-event-hub) under **STEP 2**.  

![Connect Azure logs on Hunters](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/Connect%20Azure%20logs%20on%20Hunters.jpg)
5. Under the **Data Types** section, activate the data types you want to connect.
6. For each activated data type, fill in the required information, as gathered [here](https://docs.hunters.ai/docs/connect-data-through-azure-event-hub):
  1. Under STEP 1 - **Subscription ID**
  2. Under STEP 3 - **Resource group name** and **Event Hub namespace** and
  3. Under STEP 4 - **Event Hub name**.
7. OPTIONAL: Under the **Consumer group** field you can specify a specific Azure Event Hub consumer group, or leave this field empty to use the default consumer group.
8. Click **Test Connection** to make sure everything was set up correctly.
9. Once the connection is established, click **Submit**.

## Expected format

```
{ "RoleLocation": "East US 2", "ReleaseVersion": "6.2022.37.8+bcaa334.release_2022w37", "time": "2022-10-12T10:04:32.3057945Z", "resourceId": "/SUBSCRIPTIONS/ABCDE/RESOURCEGROUPS/RG-PF-STABLE-UAT-EASTUS2/PROVIDERS/MICROSOFT.STORAGE/STORAGEACCOUNTS/STPFSTABLEUATEASTUS2", "operationName": "MICROSOFT.STORAGE/STORAGEACCOUNTS/LISTKEYS/ACTION", "category": "Administrative", "resultType": "Start", "resultSignature": "Started.", "durationMs": "0", "callerIpAddress": "20.72.115.163", "correlationId": "61fd0b04-7e16-4557-9b9b-879c7aff66cd", "identity": {"authorization":{"scope":"/subscriptions/ABCDE/resourceGroups/rg-pf-stable-uat-eastus2/providers/Microsoft.Storage/storageAccounts/stpfstableuateastus2","action":"Microsoft.Storage/storageAccounts/listKeys/action","evidence":{"role":"Contributor","roleAssignmentScope":"/subscriptions/cc7775f1-a5e6-4245-9016-38f051da9812/resourceGroups/rg-pf-stable-uat-eastus2/providers/Microsoft.Storage/storageAccounts/stpfstableuateastus2","roleAssignmentId":"443fdc6f76a814f1c22e54ad3715b551","roleDefinitionId":"b24988ac618042a0ab8820f7382dd24c","principalId":"15cc7f09cebb4c829a9b7ed89cf655fe","principalType":"ServicePrincipal"}},"claims":{"aud":"https://management.azure.com/","iss":"https://sts.windows.net/b75dfea5-fdac-4a4f-bb0f-62bde8c36603/","iat":"1665568772","nbf":"1665568772","exp":"1665572672","aio":"E2ZgYDgY7dhvn3h0i71Od6pdSXUaAA==","appid":"a0575e55-f521-46b2-9f31-34eafb554194","appidacr":"1","http://schemas.microsoft.com/identity/claims/identityprovider":"https://sts.windows.net/b75dfea5-fdac-4a4f-bb0f-62bde8c36603/","idtyp":"app","http://schemas.microsoft.com/identity/claims/objectidentifier":"15cc7f09-cebb-4c82-9a9b-7ed89cf655fe","rh":"0.ATcApf5dt6z9T0q7D2K96MNmA0ZIf3kAutdPukPawfj2MBM3AAA.","http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier":"15cc7f09-cebb-4c82-9a9b-7ed89cf655fe","http://schemas.microsoft.com/identity/claims/tenantid":"b75dfea5-fdac-4a4f-bb0f-62bde8c36603","uti":"Bpx7PtzCEkinSydiHGQ3AA","ver":"1.0","xms_tcdt":"1565641049"}}, "level": "Information", "properties": {"eventCategory":"Administrative","entity":"/subscriptions/cc7775f1-a5e6-4245-9016-38f051da9812/resourceGroups/rg-pf-stable-uat-eastus2/providers/Microsoft.Storage/storageAccounts/stpfstableuateastus2","message":"Microsoft.Storage/storageAccounts/listKeys/action","hierarchy":"b75dfea5-fdac-4a4f-bb0f-62bde8c36603/cc7775f1-a5e6-4245-9016-38f051da9812"}, "tenantId": "ABCDE"}
```
