Edit

CloudHsmHardwareOperationAuditLogs

This table contains hardware operations performed on your Azure Cloud HSM resource's HSM partitions. They can be used to monitor events and configure necessary alerts on your Cloud HSM resource.

Table attributes

Attribute Value
Resource types microsoft.hardwaresecuritymodules/cloudhsmclusters
Categories Azure Resources, Audit
Solutions LogManagement
Basic log No
Ingestion-time DCR support No
Lake-only ingestion Yes
Sample Queries -

Columns

Column Type Description
AdditionalInfo dynamic Additional structured information about the command.
AuditLogType string Type of audit log entry generated by the HSM.
_BilledSize real The record size in bytes
BinaryLogData string Encoded binary data associated with the log entry.
BinarySignature string Binary signature generated for a single batch of signed logs associated with the same correlation ID.
ClusterType string Cluster type of the Cloud HSM resource.
CommandType string Type of command executed on the HSM.
CorrelationId string Unique correlation ID used to track the requests that are part of a single signed logs batch.
FirmwareVersion string Firmware version running on the HSM.
HsmInstance string HSM instance identifier within the Cloud HSM cluster.
HSMSerialNumber string Serial number of the HSM device.
_IsBillable string Specifies whether ingesting the data is billable. When _IsBillable is false ingestion isn't billed to your Azure account
Location string Azure region where the Cloud HSM cluster is deployed.
Opcode string Operation code in HEX string format.
OperationName string Name of the operation performed.
OperationVersion string Version of the operation.
PartitionId string Partition identifier associated with the HSM operation.
RebootCounter string Counter indicating the number of HSM reboots.
_ResourceId string A unique identifier for the resource that the record is associated with
ResultDescription string Detailed description of the operation result.
ResultType string Result of the operation.
SequenceNumber string Sequence number associated with the HSM operation.
SessionHandle string Handle identifying the session.
SessionType string Type of session used for the operation.
SourceSystem string The type of agent the event was collected by. For example, OpsManager for Windows agent, either direct connect or Operations Manager, Linux for all Linux agents, or Azure for Azure Diagnostics
_SubscriptionId string A unique identifier for the subscription that the record is associated with
TenantId string The Log Analytics workspace ID
TimeGenerated datetime Timestamp (UTC) when the HSM operation was logged.
Type string The name of the table
UserID string Identifier of the user initiating the command.