Cloud platforms
PlannedAzure activity log
By Microsoft
Subscription-level control-plane operations from the Azure activity log.
What you can connect
Capabilities and availability
Each capability has its own setup and status. Review the details before enabling it for your organisation.
Log collection
PlannedSetup is not available yet
Polling Azure activity log directly is not available. Stream the activity log through an Event Hub and a small relay to the HTTP Event Collector source; events are stored as generic JSON. Entra ID and Microsoft 365 events are covered by the Microsoft 365 unified audit log source.
What to know before connecting
Polling Azure activity log directly is not available. Stream the activity log through an Event Hub and a small relay to the HTTP Event Collector source; events are stored as generic JSON. Entra ID and Microsoft 365 events are covered by the Microsoft 365 unified audit log source.
- A poller for Azure activity log with a parser that names the actor, action and resource fields.
Roadmap timing: No release date is committed. AWS CloudTrail, Microsoft 365 and Google Workspace audit collection are available.
More in Cloud platforms
Cloud platforms
AWS CloudTrail
Console sign-ins, IAM changes and every API call recorded by CloudTrail, pulled from the S3 bucket the trail writes to and parsed into named fields.
Cloud platforms
AWS IAM Identity Center
SAML 2.0 sign-in through AWS IAM Identity Center (formerly AWS SSO). SCIM user provisioning from Qorionix is not available.
Cloud platforms
Amazon GuardDuty
Imports GuardDuty findings — unauthorized API calls, compromised credentials, anomalous network behaviour — from a tenant's own AWS account into the Qorionix SIEM incident queue. Read-only: does not archive, suppress or resolve findings in AWS.