Identity and SaaS Recipes
Identity and SaaS Recipes
Added in v0.20.0Collection recipes for Microsoft 365 and Entra, GitHub, Okta, and OneLogin audit events. Each recipe gives Vector, OpenTelemetry Collector, and Grafana Alloy configs for delivering the source’s native JSON to rsigma engine daemon with --schema-routing. Vector posts to /api/v1/events (--input http); the OTel Collector and Alloy use OTLP HTTP (/v1/logs), which needs the daemon-otlp feature (release archives include it). The overview has the schema table and a combined daemon config.
Microsoft 365 / Entra
The Office 365 Management Activity API emits unified audit log events with the common-schema fields RecordType, Operation, CreationTime, Workload, and OrganizationId. The classifier recognizes this raw shape (any Workload) as m365_audit and maps it to product: m365, service: audit, where SigmaHQ’s native-field rules live.
SigmaHQ’s exchange, threat_detection, and threat_management services are written against a separately normalized shape (eventSource, eventName, status), which are not Management Activity common-schema fields. RSigma does not ship a normalization pipeline for that shape, so raw Management Activity events are not classified into those services.
[sources.m365]
type = http_server
address = "0.0.0.0:9002"
[sinks.rsigma]
inputs = ["m365"]
type = http
uri = "http://localhost:8952/api/v1/events"
encoding.codec = json
receivers:
filelog:
include: [/var/log/m365/*.json]
operators:
- type: json_parser
parse_to: body
processors:
batch: {}
exporters:
otlphttp/rsigma:
endpoint: "http://localhost:8952"
compression: none
service:
pipelines:
logs:
receivers: [filelog]
processors: [batch]
exporters: [otlphttp/rsigma]
otelcol.exporter.otlphttp "rsigma" {
client {
endpoint = "http://localhost:8952"
}
}
otelcol.receiver.filelog "m365" {
include = ["/var/log/m365/*.json"]
start_at = "beginning"
operators = [{
type = "json_parser",
parse_to = "body",
}]
output {
logs = [otelcol.exporter.otlphttp.rsigma.input]
}
}
GitHub Audit Log
The GitHub Audit Log API returns JSON with action, actor, org/repo, created_at, and _document_id.
[sources.github]
type = http_server
address = "0.0.0.0:9003"
[sinks.rsigma]
inputs = ["github"]
type = http
uri = "http://localhost:8952/api/v1/events"
encoding.codec = json
receivers:
filelog:
include: [/var/log/github-audit/*.json]
operators:
- type: json_parser
parse_to: body
processors:
batch: {}
exporters:
otlphttp/rsigma:
endpoint: "http://localhost:8952"
compression: none
service:
pipelines:
logs:
receivers: [filelog]
processors: [batch]
exporters: [otlphttp/rsigma]
otelcol.exporter.otlphttp "rsigma" {
client {
endpoint = "http://localhost:8952"
}
}
otelcol.receiver.filelog "github" {
include = ["/var/log/github-audit/*.json"]
start_at = "beginning"
operators = [{
type = "json_parser",
parse_to = "body",
}]
output {
logs = [otelcol.exporter.otlphttp.rsigma.input]
}
}
Okta System Log
Okta System Log API events carry eventType, actor, outcome.result, and published.
[sources.okta]
type = http_server
address = "0.0.0.0:9004"
[sinks.rsigma]
inputs = ["okta"]
type = http
uri = "http://localhost:8952/api/v1/events"
encoding.codec = json
receivers:
filelog:
include: [/var/log/okta/*.json]
operators:
- type: json_parser
parse_to: body
processors:
batch: {}
exporters:
otlphttp/rsigma:
endpoint: "http://localhost:8952"
compression: none
service:
pipelines:
logs:
receivers: [filelog]
processors: [batch]
exporters: [otlphttp/rsigma]
otelcol.exporter.otlphttp "rsigma" {
client {
endpoint = "http://localhost:8952"
}
}
otelcol.receiver.filelog "okta" {
include = ["/var/log/okta/*.json"]
start_at = "beginning"
operators = [{
type = "json_parser",
parse_to = "body",
}]
output {
logs = [otelcol.exporter.otlphttp.rsigma.input]
}
}
OneLogin Events API
OneLogin Events API records carry event_type_id, account_id, created_at, and user_id/actor_user_id.
[sources.onelogin]
type = http_server
address = "0.0.0.0:9005"
[sinks.rsigma]
inputs = ["onelogin"]
type = http
uri = "http://localhost:8952/api/v1/events"
encoding.codec = json
receivers:
filelog:
include: [/var/log/onelogin/*.json]
operators:
- type: json_parser
parse_to: body
processors:
batch: {}
exporters:
otlphttp/rsigma:
endpoint: "http://localhost:8952"
compression: none
service:
pipelines:
logs:
receivers: [filelog]
processors: [batch]
exporters: [otlphttp/rsigma]
otelcol.exporter.otlphttp "rsigma" {
client {
endpoint = "http://localhost:8952"
}
}
otelcol.receiver.filelog "onelogin" {
include = ["/var/log/onelogin/*.json"]
start_at = "beginning"
operators = [{
type = "json_parser",
parse_to = "body",
}]
output {
logs = [otelcol.exporter.otlphttp.rsigma.input]
}
}
See also
- Cloud Collection Recipes for the built-in schema table and a combined daemon config.
- Schema Routing for bindings, aliases, and schema-derived logsource pruning.
- Schema Signatures for the built-in catalog and signature grammar.
- OTLP Integration for
/v1/logs, LogRecord flattening, and agent recipes.