Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Keyword attribute/field not populating in latest version of AMA #125119

Open
Dhaval8951 opened this issue Dec 10, 2024 · 3 comments
Open

Keyword attribute/field not populating in latest version of AMA #125119

Dhaval8951 opened this issue Dec 10, 2024 · 3 comments

Comments

@Dhaval8951
Copy link

Hi Azure Team

Greetings !

I am writing this query regarding one field that should be generated by AMA Security Event Logs.
I have previously raised the query for same and that sounds the issue to the AMA which was later fix and I can see that documentation is also updated.

I have drafted this issue : #121325

The documentation updated I can see from below screenshot of this document: https://learn.microsoft.com/en-us/azure/azure-monitor/agents/data-sources-windows-events
image

I understand from above image that issue is fixed.
When I am generating Logs from AMA, The Keyword field for Success Audit or Failure Audit still not populating.
Could you please provide any specific configuration steps which required to be followed to have this field in AMA windows logs.

Any help / guidance would be greatly appreciated.

Regards,
Dhaval C.

@PesalaPavan
Copy link
Contributor

@Dhaval8951
Thanks for your feedback! We will investigate and update as appropriate.

@TPavanBalaji
Copy link
Contributor

@Dhaval8951
Thank you for bringing this to our attention.
I've delegated this to content author, who will review it and offer their insightful opinions.

@guywi-ms
Copy link
Contributor

#reassign: @rboucher

@prmerger-automator prmerger-automator bot assigned rboucher and unassigned guywi-ms Dec 18, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

6 participants
@rboucher @Dhaval8951 @guywi-ms @TPavanBalaji @PesalaPavan and others