matanolabs / matano

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS
https://matano.dev
Apache License 2.0
1.46k stars 99 forks source link

GitHub audit logs can optionally include client IP addresses #157

Closed timoguin closed 1 year ago

timoguin commented 1 year ago

Enterprise audit logs can now be configured to include client IP addresses in the dataset. We should map their actor_ip to client.ip in the managed log source.

https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/displaying-ip-addresses-in-the-audit-log-for-your-enterprise