Getting Data In

Has anyone indexed Azure Devops audit log?

las
Contributor

Hi.

It seems Microsoft has exposed the audit log for Azure DevOps, https://docs.microsoft.com/en-us/rest/api/azure/devops/audit/audit%20log/query?view=azure-devops-res...
Has anyone tried to index this log and how did you do it?

Kind regards
las

Tags (2)
0 Karma

jscraig2006
Communicator

Hi Ias,
Yes, you will need a PAT created in Azure Devops and use a Python script for the scripted input.

personal_access_token = '<access_token>'
organization_url = 'https://<azure_devops_url>/_apis/audit/auditlog?api-version=5.1-preview.1'
json_data = requests.get(organization_url, auth=('', personal_access_token)).json()

las
Contributor

Thank you for your answer, I was just curious if anybody had done it, and if it was done, if they found an add-on or created either a scripted- or modular-input

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...