Edit

DiscoveryBookshelfAuditLogs

Audit logs for Microsoft Discovery bookshelf operations including knowledge base creation, updates, and deletions. Used to track user actions and changes to bookshelf resources.

Table attributes

Attribute Value
Resource types microsoft.discovery/bookshelves
Categories Audit
Solutions LogManagement
Basic log Yes
Ingestion-time DCR support No
Lake-only ingestion Yes
Sample Queries Yes

Columns

Column Type Description
_BilledSize real The record size in bytes
Category string The log category of the event.
_IsBillable string Specifies whether ingesting the data is billable. When _IsBillable is false ingestion isn't billed to your Azure account
ObjectId string The object identifier of the principal that performed the operation.
OperationName string The name of the operation that triggered the audit event, including the controller and action name.
_ResourceId string A unique identifier for the resource that the record is associated with
SourceSystem string The type of agent the event was collected by. For example, OpsManager for Windows agent, either direct connect or Operations Manager, Linux for all Linux agents, or Azure for Azure Diagnostics
_SubscriptionId string A unique identifier for the subscription that the record is associated with
Tenant string The Discovery tenant identifier associated with the bookshelf.
TenantId string The Log Analytics workspace ID
TimeGenerated datetime Timestamp when the log entry was ingested.
Type string The name of the table