Forum Discussion

Porter76's avatar
Porter76
Brass Contributor
Sep 14, 2023

How to monitor multiple Github orgs with Github Enterprise Audit logs Data connector

As stated in the subject, I am trying to figure out how I can monitor multiple organizations using the Github enterprise Audit log Data connector. 

 

Sending logs from an org to sentinel using the connector is very easy, you just generate a personal access token (PAT) and add it in the connector page along with the name of the org. My company currently has multiple orgs, and when I add another key for another Org, it starts sending logs for just the newly added org and ceases logs from the previous org.

 

Is it possible to monitor multiple Orgs with this Data Connector? Also worth mentioning for whatever reason I can't seem to find this connector in the content hub anymore

 

 

    • Sergei2435's avatar
      Sergei2435
      Brass Contributor
      Creating multiple workspaces might work if you have two or three organizations. I have a customer with over 20 organizations. It is clearly not the best solution for us.
    • Porter76's avatar
      Porter76
      Brass Contributor
      I was able to succesfully deploy the codeless connector, but the logs coming over are useless. They are missing vital information like what organization an action was taken in. It seems like im only seeing logs related to adding and removing members. This makes me think I may need to edit something that I missed. I was hoping for logs as robust as the connector in content hub.

Resources