Enable inactive human identity logs on Azure in Cloud Identity Security

Requires a Cloud Posture Security, Cloud Runtime Security, or Cortex XSIAM Premium license.

To enable inactive human identity logs on the Microsoft Azure platform in Cloud Identity Security, you must first configure diagnostic settings for the SignInLog log types. These log types provide information regarding how long human identities have been signed in.

To configure the SignInLog log types, do the following:

  1. Open the Azure console.
  2. Navigate to the Diagnostic settings screen.
  3. In the Logs area, under Categories, select the following categories that are related to sign-in logs:
    • SigninLogs
    • NonInteractiveUserSigninLogs
    • ServicePrincipalSigninLogs
    • ManagedIdentitySigninLogs
    • ADFSSigninLogs
  4. Click Save.

Note

For more information, see Ingest logs from Microsoft Azure Event Hub.