Azure / Azure-Sentinel

Cloud-native SIEM for intelligent security analytics for your entire enterprise.
https://azure.microsoft.com/en-us/services/azure-sentinel/
MIT License
4.5k stars 2.96k forks source link

[Feature] Pulumi Cloud - Connector that pulls logs from API, ingest to Log Analytics #10944

Closed o-l-a-v closed 1 month ago

o-l-a-v commented 1 month ago

Is your feature request related to a problem? Please describe.

There's currently no ready made solution to ingest Pulumi Cloud logs into Log Analytics Workspace / Sentinel, as far as I know.

Pulumi Cloud only supports pushing logs to AWS S3 buckets, but has an API to pull logs from:

Describe the solution you'd like

Connector that pulls logs from Pulumi Cloud API, ingest to Log Analytics

Describe alternatives you've considered

Writing this integration myself.

Additional context

None.

v-sudkharat commented 1 month ago

Hi @o-l-a-v, Thanks for flagging this issue, we will investigate this issue and get back to you with some updates. Thanks!

o-l-a-v commented 1 month ago

One thing to note about the Pulumi API for fetching logs, that I became aware of after I created this feature request:

...This API is rate-limited and only intended for occasional use...

In a Reddit thread (https://www.reddit.com/r/AZURE/comments/1en0b8g) I was asked by Pulumi to create an issue in their GitHub repo:

v-sudkharat commented 1 month ago

Hi @o-l-a-v, Thank you for creating the feature request ticket with us. We are forwarding this requested with our PG team, so team can check on this feature request with Partner too. So, closing this request issue. If you still need support for this issue, feel free to re-open it any time. Thank you for your co-operation.

o-l-a-v commented 1 month ago

@v-sudkharat: Please don't close unless the feature request has been answered. No is an answer. Checking with "forwarding this requested with our PG team" is not an answer. It's not "Completed".

v-sudkharat commented 1 month ago

Hi @o-l-a-v, We understand your concern, but feature requests added to the team's queue are prioritized based on the active backlogs. We can't comment on when it will be available at this time. However, our team will share updates with you when it is prioritized. Thanks!