We're interested in trying out the Azure module for Filebeat in order to fetch logs from an Azure event hub. The event hub will be fed diagnostics logs from Intune.
However we can see that the diagnostics settings for Intune has the following categories available to send to an Azure event hub:
AuditLogs
OperationalLogs
DeviceComplianceOrg
Does that mean that the Filebeat Azure module only has support for the Auditlogs and not the other two? If so, is there any way that you could recommend that we collect the logs with?
hi @victor.nilsson, I suggest having a look at any of the pipelines generated for the other filesets in the azure module like auditlogs and try to build a pipeline for these logs as well, assuming they share the azure platform logs common schema.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.