Enable inactive human identity logs on Azure in Cortex Cloud Identity Security - Configuration information for enabling inactive human identity logs on Azure. - Administrator Guide - Cortex CLOUD

Cortex Cloud Runtime Security Documentation

Product
Cortex Cloud Application Security > Cortex CLOUD
License
Cloud Runtime Security
Creation date
2024-12-24
Last date published
2026-06-16
Category
Administrator Guide
Abstract

Configuration information for enabling inactive human identity logs on Azure.

To enable inactive human identity logs on the Microsoft Azure platform in Cortex Cloud Identity Security, you must first configure diagnostic settings for the SignInLog log types. These log types provide information regarding how long human identities have been signed in.

To configure the SignInLog log types, do the following:

  1. Open the Azure console.

  2. Navigate to the Diagnostic settings screen.

  3. In the Logs area, under Categories, select the following categories that are related to sign-in logs:

    • SigninLogs

    • NonInteractiveUserSigninLogs

    • ServicePrincipalSigninLogs

    • ManagedIdentitySigninLogs

    • ADFSSigninLogs

  4. Click Save.

Note

For more information, see Ingest logs from Microsoft Azure Event Hub.