changes.mady.by.user Juan Tomás Alonso Nieto
Saved on May 25, 2023
Saved on May 31, 2023
cloud.azure.aks.kube_controller_manager
cloud.azure.aks.kube_scheduler
cloud.azure.apimanagement.gatewaylogs
cloud.azure.appgateway.access_log
cloud.azure.appgateway.administrative
Field
Type
Extra fields
eventdate
timestamp
hostname
str
region
ccpNamespace
UnderlayName
operationName
category
UnderlayClass
properties__log
properties__stream
properties__containerID
properties__pod
Environment
Cloud
attrs
resourceId
hostchain
✓
tag
rawMessage
Field transformation
Source field name
callerIpAddress
ip4
isRequestSuccess
bool
location
Level
int4
correlationId
time
parsedate(time_str, ifthenelse(length(time_str) = 25, dateformat("YYYY-MM-DD[T]HH:mm:ssZZ", "UTC"), dateformat("YYYY-MM-DD[T]HH:mm:ss.SSSSSSS[Z]", "UTC")))
time_str
durationMs
properties__cache
properties__backendMethod
properties__backendResponseCode
properties__productId
properties__method
properties__apimSubscriptionId
properties__backendTime
properties__responseSize
properties__backendUrl
properties__clientTlsVersion
properties__userId
properties__url
properties__responseCode
properties__backendProtocol
properties__operationId
properties__clientProtocol
properties__apiRevision
properties__requestSize
properties__apiId
parsedate(time, ifthenelse(length(time) = 25, dateformat("YYYY-MM-DD[T]HH:mm:ssZZ", "UTC"), dateformat("YYYY-MM-DD[T]HH:mm:ss.SSSSSSS[Z]", "UTC")))
listenerName
ruleName
backendPoolName
backendSettingName
properties__instanceId
properties__clientIP
properties__clientPort
properties__httpMethod
properties__originalRequestUriWithArgs
properties__requestUri
properties__requestQuery
properties__userAgent
properties__httpStatus
properties__httpVersion
properties__receivedBytes
properties__sentBytes
properties__timeTaken
properties__transactionId
properties__sslEnabled
properties__sslCipher
properties__sslProtocol
properties__sslClientVerify
properties__sslClientCertificateFingerprint
properties__sslClientCertificateIssuerName
properties__serverRouted
properties__serverStatus
properties__serverResponseLatency
properties__originalHost
properties__host
at_devo_collector_version
at_entry_offset
at_enqueued_time
roleLocation
parsedate(time, dateformat("YYYY-MM-DD[T]HH:mm:ss.SSSSSSS[Z]", "UTC"))
resultType
resultSignature
identity__authorization__scope
identity__authorization__action
identity__authorization__evidence__role
identity__authorization__evidence__roleAssignmentScope
identity__authorization__evidence__roleAssignmentId
identity__authorization__evidence__roleDefinitionId
identity__authorization__evidence__principalId
identity__authorization__evidence__principalType
identity__claims__aud
identity__claims__iss
identity__claims__iat
identity__claims__nbf
identity__claims__exp
identity__claims__aio
identity__claims__appid
identity__claims__appidacr
identity__claims__groups
identity__claims__rh
identity__claims__uti
identity__claims__ver
identity__claims__xms_tcdt
identity__claims
json
level
properties__eventCategory
properties__entity
properties__message
properties__hierarchy
tenantId
cloud.azure.appgateway.firewall_log
cloud.azure.appgateway.policy
cloud.azure.appservice.access_audit
cloud.azure.appservice.administrative
cloud.azure.appservice.app
properties__clientIp
properties__ruleSetType
properties__ruleSetVersion
properties__ruleId
properties__ruleGroup
properties__action
properties__site
properties__details__message
properties__details__data
properties__details__file
properties__details__line
properties__hostname
properties__policyId
properties__policyScope
properties__policyScopeName
properties__isComplianceCheck
properties__resourceLocation
properties__ancestors
properties__policies
ResourceId
Category
OperationName
Properties_User
Properties_UserDisplayName
Properties_UserAddress
Properties_Protocol
properties__statusCode
properties__serviceRequestId
resource_id
operation_name
result_description
properties
properties_precise_date_time
properties_resource_id
properties_stacktrace
properties_level
properties_source
properties_message
properties_web_site_instance_id