# Filebeat Azure module

**URL:** <https://discuss.elastic.co/t/filebeat-azure-module/256771>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 26, 2020, 12:44pm UTC](https://discuss.elastic.co/t/filebeat-azure-module/256771 "2020-11-26T12:44:03Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Marco0101](https://avatars.discourse-cdn.com/v4/letter/m/e36b37/32.png) [@Marco0101](https://discuss.elastic.co/u/Marco0101)\
**Post date:** [November 26, 2020, 12:44pm UTC](https://discuss.elastic.co/t/filebeat-azure-module/256771/1 "2020-11-26T12:44:04Z")

</div>

Hi, i would like to know if the activitylogs - auditlogs can only be used for Azure AD audit events or that it is also possible to use it for keyvault audit logging also. Because we built an eventhub and pass the keyvault audit logs to the activity - auditlogs in filebeat and the messages are picked up from the eventhub but we do not receive any data in Elastic.

> **[Azure module | Filebeat Reference \[7.9\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-azure.html#_module_configuration_2)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 24, 2020, 2:44pm UTC](https://discuss.elastic.co/t/filebeat-azure-module/256771/2 "2020-12-24T14:44:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

---

<div class="post-metadata">

**Author:** ![MarianaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marianad/32/42687_2.png) [@MarianaD](https://discuss.elastic.co/u/MarianaD)\
**Post date:** [January 11, 2021, 1:05pm UTC](https://discuss.elastic.co/t/filebeat-azure-module/256771/3 "2021-01-11T13:05:41Z")

</div>

hi @Marco0101, those messages are most likely filtered out as we expect only activity and AD logs.  
A workaround for now is just using the `azure-eventhub` input and creating similar pipelines as the ones used for the azure module and applying them to your events.
