Use Auditing to analyze audit logs and reports - Azure SQL Database & Azure Synapse Analytics (2024)

Edit

Share via

  • Article

Applies to: Use Auditing to analyze audit logs and reports - Azure SQL Database & Azure Synapse Analytics (1) Azure SQL Database Use Auditing to analyze audit logs and reports - Azure SQL Database & Azure Synapse Analytics (2) Azure Synapse Analytics

This article provides an overview of analyzing audit logs using Auditing for Azure SQL Database and Azure Synapse Analytics. You can use Auditing to analyze audit logs stored in:

  • Log Analytics
  • Event Hubs
  • Azure storage

Analyze logs using Log Analytics

If you chose to write audit logs to Log Analytics:

  1. Use the Azure portal.

  2. Go to the relevant database resource.

  3. At the top of the database's Auditing page, select View audit logs.

    Use Auditing to analyze audit logs and reports - Azure SQL Database & Azure Synapse Analytics (3)

You have two ways to view the logs:

  • Selecting Log Analytics at the top of the Audit records page opens the logs view in the Log Analytics workspace, where you can customize the time range and the search query.

    Use Auditing to analyze audit logs and reports - Azure SQL Database & Azure Synapse Analytics (4)

  • Selecting View dashboard at the top of the Audit records page opens a dashboard displaying audit logs information, where you can drill down into Security Insights or Access to Sensitive Data. This dashboard is designed to help you gain security insights for your data. You can also customize the time range and search query.

    Use Auditing to analyze audit logs and reports - Azure SQL Database & Azure Synapse Analytics (5)

    Use Auditing to analyze audit logs and reports - Azure SQL Database & Azure Synapse Analytics (6)

  • Alternatively, you can also access the audit logs from the Log Analytics menu. Open your Log Analytics workspace and under the General section, and select Logs. You can start with a simple query, such as: search "SQLSecurityAuditEvents" to view the audit logs. From here, you can also use Azure Monitor logs to run advanced searches on your audit log data. Azure Monitor logs gives you real-time operational insights using integrated search and custom dashboards to readily analyze millions of records across all your workloads and servers. For extra useful information about Azure Monitor logs search language and commands, see Azure Monitor logs search reference.

Analyze logs using Event Hubs

If you chose to write audit logs to Event Hubs:

  • To consume audit logs data from Event Hubs, you need to set up a stream to consume events and write them to a target. For more information, see Azure Event Hubs Documentation.
  • Audit logs in Event Hubs are captured in the body of Apache Avro events and stored using JSON formatting with UTF-8 encoding. To read the audit logs, you can use Avro Tools, Microsoft Fabric event streams, or similar tools that process this format.

Analyze logs using logs in an Azure storage account

If you chose to write audit logs to an Azure storage account, there are several methods you can use to view the logs:

  • Audit logs are aggregated in the account you chose during setup. You can explore audit logs by using a tool such as Azure Storage Explorer. In Azure storage, auditing logs are saved as a collection of blob files within a container named sqldbauditlogs. For more information about the hierarchy of the storage folders, naming conventions, and log format, see the SQL Database Audit Log Format.

    1. Use the Azure portal.

    2. Open the relevant database resource.

    3. At the top of the database's Auditing page, select View audit logs.

      Use Auditing to analyze audit logs and reports - Azure SQL Database & Azure Synapse Analytics (7)

      The Audit records page opens, and you're able to view the logs.

    4. You can view specific dates by selecting Filter at the top of the Audit records page.

    5. You can switch between audit records that were created by the server audit policy and the database audit policy by toggling Audit Source.

      Use Auditing to analyze audit logs and reports - Azure SQL Database & Azure Synapse Analytics (8)

  • Use the system function sys.fn_get_audit_file (T-SQL) to return the audit log data in tabular format. For more information on using this function, see sys.fn_get_audit_file.

  • Use Merge Audit Files in SQL Server Management Studio (starting with SSMS 17):

    1. From the SSMS menu, select File > Open > Merge Audit Files.

      Use Auditing to analyze audit logs and reports - Azure SQL Database & Azure Synapse Analytics (9)

    2. The Add Audit Files dialog box opens. Select one of the Add options to choose whether to merge audit files from a local disk or import them from Azure Storage. You're required to provide your Azure Storage details and account key.

    3. After all files to merge have been added, select OK to complete the merge operation.

    4. The merged file opens in SSMS, where you can view and analyze it, as well as export it to an XEL or CSV file, or to a table.

  • Use Power BI. You can view and analyze audit log data in Power BI. For more information and to access a downloadable template, see Analyze audit log data in Power BI.

  • Download log files from your Azure Storage blob container via the portal or by using a tool such as Azure Storage Explorer.

    • After you have downloaded a log file locally, double-click the file to open, view, and analyze the logs in SSMS.
    • You can also download multiple files simultaneously in Azure Storage Explorer. To do so, right-click a specific subfolder and select Save as to save in a local folder.
  • More methods:

    • After downloading several files or a subfolder that contains log files, you can merge them locally as described in the SSMS Merge Audit Files instructions described previously.
    • View blob auditing logs programmatically: Query Extended Events Files by using PowerShell.

See also

  • Auditing overview
  • Data Exposed episode What's New in Azure SQL Auditing
  • Auditing for SQL Managed Instance
  • Auditing for SQL Server

Feedback

Was this page helpful?

Use Auditing to analyze audit logs and reports - Azure SQL Database & Azure Synapse Analytics (2024)
Top Articles
Assessing Poll Validity | Bloustein Center for Survey Research
The Four Principles of Personal Finance
[PDF] (punctuation mark - used as punctuation in symbol sentences) YELLOW Character 8485 Fragezeichen 8485 vraagteken 8485 vraagteken - Free Download PDF
Metro By T Mobile Sign In
Att U Verse Outage Map
Wavmonopoly Reverb Calculator
Pleads Irksomely Crossword Clue
Unblocked Games6969: A World Of Unrestricted Gaming Fun - Unblocked Hub
Babylon (2022) Stream and Watch Online
Nlxf North Liberty
A Killer Paradox: how to watch, plot, cast and everything we know
Amrn Investors Hub
Best Restaurants Ventnor
Dekalb County Jail Fort Payne Alabama
Craigslist Cars Lansing Michigan
Craigslist Artesia Nm
Weapons Storehouse Nyt Crossword
Rubfinder
Express Employment Sign In
Just Breath Chords
Legitlocal.co Lawn Service Near Me
National Museum of the United States Army
412-690-0001
¿Cuándo se regalan flores amarillas y por qué se realiza este ritual en septiembre?
Splunk If Command
Paperlesspay Talx Ingram
Mytowerlearninghub
Ellie Zeiler Ass
Brimstone Sands Lost Easels
Erfahrungen mit r2 Bike
2009 Mercedes C300 Belt Diagram
Newadvent Org
Costco Gas Kingman Az
Devotion Showtimes Near Cinemark Sherman
Hca Florida Middleburg Emergency Reviews
Les 4 meilleures cartes SIM prépayées (2024) - NON sponsorisé
Camwhor*s Bypass 2022
Lions Roster Wiki
Amari Cooper Pfr
Gypsy Rose Blanchard's Mother's Brutal Crime Scene Photos Go Viral On Her 33rd Birthday
Atrium Orthopedic Urgent Care
Wral Nighttime Lottery
Honeybee: Classification, Morphology, Types, and Lifecycle
Boise Cascade Aktie (BCC) • US09739D1000
Mailing List Uva
7440 Dean Martin Dr Suite 204 Directions
Ixl Mililani High School
What is "Brrr skibidi dop dop / dom dom yes yes"? Memes, explanation, meaning, definition - Bedeutung Online
Madelyn Cline Surgeon
Salmon Fest 2023 Lineup
Cta Bus Tracker 77
Latest Posts
Article information

Author: Foster Heidenreich CPA

Last Updated:

Views: 5945

Rating: 4.6 / 5 (76 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Foster Heidenreich CPA

Birthday: 1995-01-14

Address: 55021 Usha Garden, North Larisa, DE 19209

Phone: +6812240846623

Job: Corporate Healthcare Strategist

Hobby: Singing, Listening to music, Rafting, LARPing, Gardening, Quilting, Rappelling

Introduction: My name is Foster Heidenreich CPA, I am a delightful, quaint, glorious, quaint, faithful, enchanting, fine person who loves writing and wants to share my knowledge and understanding with you.