Skip to content

github.audit: Add Azure Eventhub input for streaming audit logs #13038

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 4 commits into from
Mar 11, 2025

Conversation

kcreddy
Copy link
Contributor

@kcreddy kcreddy commented Mar 10, 2025

Proposed commit message

Add support to collect audit logs using 
Azure Event Hub input.

Note

Followed guide from the linked issue to setup live data testing with Azure Eventhub input.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

How to test this PR locally

  1. Pipeline tests pass.
  2. Tested with live data. No parsing issues were detected as the event matches API response.

Related issues

Screenshots

Screenshot 2025-03-10 at 10 08 58 PM

@elastic-vault-github-plugin-prod

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@kcreddy kcreddy added Integration:github GitHub enhancement New feature or request Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] labels Mar 10, 2025
@kcreddy kcreddy self-assigned this Mar 10, 2025
@kcreddy kcreddy changed the title github.audit: Add Azure Eventhub input github.audit: Add Azure Eventhub input for streaming audit logs Mar 10, 2025
@kcreddy kcreddy marked this pull request as ready for review March 10, 2025 16:42
@kcreddy kcreddy requested a review from a team as a code owner March 10, 2025 16:42
@elasticmachine
Copy link

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@elasticmachine
Copy link

💚 Build Succeeded

History

cc @kcreddy

Copy link

@kcreddy kcreddy merged commit 11f67e7 into elastic:main Mar 11, 2025
7 checks passed
@elastic-vault-github-plugin-prod

Package github - 2.5.0 containing this change is available at https://epr.elastic.co/package/github/2.5.0/

flexitrev pushed a commit that referenced this pull request Mar 20, 2025
* Add base template

* add pipeline tests

* Update README

* update pr number
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request Integration:github GitHub Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]
Projects
None yet
Development

Successfully merging this pull request may close these issues.

[GitHub] Support Ingest of GitHub Audit Logs via Azure Event Hub Audit Log Streaming
3 participants