Sign in logs and Azure groups

%3CLINGO-SUB%20id%3D%22lingo-sub-1241880%22%20slang%3D%22en-US%22%3ESign%20in%20logs%20and%20Azure%20groups%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1241880%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20everyone%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI'm%20still%20new%20to%20Azure%20Log%20Analytics%2C%20my%20aim%20is%20to%20use%20a%20KQL%20query%20to%20retrieve%20some%20sign-in%20logs%20and%20filter%20them%20by%20including%20only%20members%20of%20a%20specific%20Azure%20AD%20Group.%3C%2FP%3E%3CP%3EWhen%20using%20%22SigninLogs%22%20I%20can't%20identify%20a%20field%20for%20group%20membership.%20I'm%20thinking%20about%20using%20the%20%22identity%22%20field%20to%20correlate%20users%20with%20groups%20but%20I'm%20still%20not%20able%20to%20find%20a%20way%20to%20that.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDo%20you%20have%20some%20similar%20experience%20to%20share%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20for%20your%20help%3C%2FP%3E%3CP%3EAlex%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1241880%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20Group%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%20Log%20Analytics%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EQuery%20Language%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Occasional Contributor

Hello everyone,

 

I'm still new to Azure Log Analytics, my aim is to use a KQL query to retrieve some sign-in logs and filter them by including only members of a specific Azure AD Group.

When using "SigninLogs" I can't identify a field for group membership. I'm thinking about using the "identity" field to correlate users with groups but I'm still not able to find a way to that.

 

Do you have some similar experience to share?

 

Thanks for your help

Alex

0 Replies