PreAuthenticationDiscoveryLogs

Provides visibility into credential validation and discovery endpoint calls that occur before sign-in.

Table attributes

Attribute Value
Resource types -
Categories -
Solutions LogManagement
Basic table support Yes
Auxiliary / Lake table support Yes
DCR workspace transformation support No
Ingestion API support No
Sample Queries -

Columns

Column Type Description
AADTenantId string The AADTenantId GUID that's associated with the logs
ApplicationId string The ID of the application.
_BilledSize real The record size in bytes
CallerIpAddress string Provides the IP address of the caller.
Category string Category of the sign-in event.
CorrelationId string ID to provide sign-in trail.
ErrorNumber string The error number of the operation.
_IsBillable string Specifies whether ingesting the data is billable. When _IsBillable is false ingestion isn't billed to your Azure account
OperationName string For sign-ins, this value is always Sign-in activity.
OperationVersion string The REST API version that's requested by the client.
RequestId string The ID of the request.
RequestType string The type of the request.
ResourceGroup string Resource group for the logs.
ResultDescription string Provides the error description for the sign-in operation.
SourceSystem string The type of agent the event was collected by. For example, OpsManager for Windows agent, either direct connect or Operations Manager, Linux for all Linux agents, or Azure for Azure Diagnostics
TenantId string The Log Analytics workspace ID
TimeGenerated datetime The date and time of the event in UTC.
Type string The name of the table
UserAgent string The user agent of the client.
UserId string The ID of the user.