NCBMBreakGlassAuditLogs

Security log events on Nexus Baremetal Machines to monitor and detect user access to the system.

Table attributes

Attribute Value
Resource types microsoft.networkcloud/baremetalmachines
Categories Azure Resources, Security
Solutions LogManagement
Basic log Yes
Ingestion-time transformation No
Sample Queries -

Columns

Column Type Description
_BilledSize real The record size in bytes
ClusterManagerName string Name of the ClusterManager managing the Nexus cluster.
ClusterName string Name of the on-prem Nexus cluster.
_IsBillable string Specifies whether ingesting the data is billable. When _IsBillable is false ingestion isn't billed to your Azure account
Location string Location of the Nexus Baremetal machine.
Log string The log message generated by the system during user access.
Message string The message parsed from the log on user access.
Mode string Mode of the operation by the user.
Node string Host name of the Baremetal Machine.
ProcessId int ID of the process emitting the log.
_ResourceId string A unique identifier for the resource that the record is associated with
SourceSystem string The type of agent the event was collected by. For example, OpsManager for Windows agent, either direct connect or Operations Manager, Linux for all Linux agents, or Azure for Azure Diagnostics
_SubscriptionId string A unique identifier for the subscription that the record is associated with
TenantId string The Log Analytics workspace ID
TimeGenerated datetime Timestamp (UTC) when the log was generated.
Type string The name of the table
User string User accessing the system.