Azure SQL capability that sends database audit logs to Log Analytics, Event Hubs or a storage account; that account is allowed to be in a different region.
Also called Azure SQL.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Auditing in context, with comparison tables and the common traps.
Terms in this definition
- Capability
Something that a person, organisation or system is able to do.
- Schema
The middle part of a Unity Catalog name (
catalog.schema.table), grouping tables, views, volumes, functions and models inside a catalog. A grant on it covers everything in it now and later, and nothing inside can be reached withoutUSE SCHEMA. - Audit logs
Record directory changes in Microsoft Entra, covering users, groups, applications, policies and other objects. Free tenants keep them for 7 days and P1 or P2 tenants for 30, and diagnostic settings can send them elsewhere for longer.
- Dedicated cluster
To encrypt Azure Monitor Logs with your own keys, the Log Analytics workspace must be linked to this cluster tier. Setting a CMK on a storage account gives Log Analytics no such protection.
- Azure Event Hubs
Azure service for ingesting telemetry at high volume over HTTPS or AMQP; diagnostic settings can send data to it.
- Storage account
The top-level resource in Azure Storage, giving a unique namespace for table, queue, file and blob data. Location, performance and kind are set when it is created and cannot change.
- region
A provider-defined grouping in VCF Automation of Supervisors that all share one NSX Local Manager; tenants consume its compute, storage and memory via quotas set per region.
Related terms
- Allow Azure services and resources to access this server
Networking option on Azure SQL that lets in connections from every Azure IP address, even resources owned by other customers. Leaving it off follows least privilege.
- Audit action group
Named bundle of database-engine events, BATCH_COMPLETED_GROUP being one, selected when defining an audit policy. By default Azure SQL audits BATCH_COMPLETED_GROUP together with successful and failed database authentication.
- Audit Credential Validation
Logs credential checks during user sign-in, such as a domain controller handling NTLM authentication; part of advanced auditing.
- AUDIT_CHANGE_GROUP
Fires when someone creates, alters or drops an audit or audit specification, so it captures changes to the auditing setup itself; logins and queries are covered by other action groups.
- Auto-failover group
Azure SQL feature that geo-replicates a group of databases or an entire Managed Instance, failing over automatically behind listener endpoints that stay the same. For Managed Instance it is the sole regional DR option.
- Automatic backups
Backups that Azure SQL takes on its own, allowing point-in-time restore over a window of 1 to 35 days. Keeping backups longer requires long-term retention (LTR).
- az ml model restore
Command in the Azure Machine Learning CLI that un-archives a model or model version so it shows up in listings again, for rollback or auditing.
- Azure Database Migration Service
Azure service for moving whole instances or many databases at once into Azure SQL targets such as SQL Managed Instance, either online or offline.