SIEM export

Prev Next

Overview

SIEM export lets you stream Turbo360 platform activity logs to an external security information and event management (SIEM) system on a recurring schedule. You can route logs to a Log Analytics workspace where Microsoft Sentinel can query them, or to an Azure Event Hub for downstream ingestion by Splunk, IBM QRadar, Elastic, or any SIEM that supports Event Hub as a data source.

Each export target is configured independently with its own name, target type, service principal, log source selection, and export interval. You can run multiple targets simultaneously, each sending logs to a different destination.

Business value

Security and compliance teams get visibility into Turbo360 activity inside their existing SIEM, alongside the rest of their Azure security data. Role assignments, permission changes, automated task runs, and incident escalations all appear in the same workspace or stream your team already uses. Turbo360 activity is then subject to the same audit, retention, and detection policies you apply everywhere else.

Prerequisites

Before configuring a SIEM export target, make sure the following are in place.

  • A service principal registered in Turbo360 under Settings > Service principals. The service principal must have the appropriate Azure RBAC role assigned on the destination resource (see Required permissions below).
  • For Log Analytics / Sentinel targets: An Azure Log Analytics workspace with a Data Collection Rule (DCR) and Data Collection Endpoint (DCE) configured. You can deploy these using the Bicep template provided in the wizard, or create them manually using the sample record as a schema reference.
  • For Event Hub targets: An Azure Event Hub namespace and hub created in your subscription.

Required permissions

Role Access
Account owner Full access: the only role that can view, create, edit, pause, resume, or delete SIEM export targets

SIEM export is accessible only to the Account owner. The SIEM export option does not appear in the Settings sidebar for any other role.

Dependencies

  • Turbo360 calls the Azure Monitor Logs Ingestion API to write to Log Analytics. The service principal must be granted the Monitoring Metrics Publisher role on the DCR.
  • Turbo360 uses the EventHubProducerClient to write to Event Hub. The service principal must be granted the Azure Event Hubs Data Sender role on the hub.
  • No SAS keys or shared secrets are stored. Authentication is exclusively via service principal (SP RBAC).

How it works

Turbo360 evaluates each active export target on its configured interval (every 30 or 60 minutes). When a run executes, it collects all activity records generated since the previous run and pushes them to the configured destination. Each target tracks its own position independently, so multiple targets never interfere with each other.

For Log Analytics / Sentinel targets, Turbo360 sends records to the DCR using the Logs Ingestion API. The DCR routes records into the Custom-Turbo360Activity_CL custom table in the Log Analytics workspace. Microsoft Sentinel, if connected to that workspace, can query the table directly using KQL.

For Event Hub targets, Turbo360 publishes records as events to the specified hub using the EventHubProducerClient. Downstream SIEMs such as Splunk, QRadar, and Elastic consume those events using their respective Event Hub connector.

Log sources

When creating or editing a target, you select which Turbo360 activity categories to include. Each category maps to a set of underlying audit, run-history, incident, and alert tables.

Activity source What it covers
User & security audit User, role, and permission changes; service principal and API token management; notification channel, theme, and account changes
Business Application Configuration and monitoring changes; automated task run history; incidents and escalations
BAM Business process configuration and monitoring changes; incidents and group incidents; exception detections
Azure Documenter Configuration changes; document and diagram generation runs; notification deliveries
Cost Analyser Cost configuration changes; schedule run history; rightsizing runs; incidents

Record schema

Every record written to the destination follows a consistent JSON schema regardless of target type. Key fields are described below.

Field Description
TimeGenerated UTC timestamp of when the activity occurred
Product The Turbo360 product area that generated the record (e.g. Settings, BusinessApplication)
RecordType The type of activity record (e.g. UserActivity, AutomatedTaskRun)
Category The activity category (e.g. UserManagement, AutomatedTask)
Feature The specific feature or sub-area within the product (e.g. Roles, ResubmitFailedMessages)
ActivityType The action performed (e.g. Updated, Ran)
Description Human-readable description of the activity
UserName Display name of the user who performed the action, or System for automated activities
UserEmail Email address of the user, empty for system-initiated activities
ResourceType The type of resource affected (e.g. Role, AutomatedTask)
ResourceName The name of the affected resource
ResourceId GUID identifying the affected resource
Status Outcome of the activity (e.g. Success, Completed)
Detail JSON-encoded additional detail specific to the activity type
CustomerId GUID identifying the Turbo360 customer tenant
TenantName Display name of the customer tenant

Steps

You manage SIEM export targets from Settings > SIEM export. From this page you can add new targets, view the status of existing ones, and perform actions including editing, running on demand, pausing, resuming, and deleting.

Add a target

Adding a target walks you through a four-step wizard that captures the target name, type, credentials, destination details, and log source selection.

  1. Navigate to Settings > SIEM export.
  2. Select + Add target.
  3. In the Basics step, enter a name for the target in the Name field, select the Export interval (30 min or 60 min), and choose a Target type. The Enabled checkbox is selected by default. Clear it if you want to create the target without activating it immediately.
    • Log Analytics / Sentinel: uses the Logs Ingestion API (DCR). Select this when your destination is a Log Analytics workspace, with or without Microsoft Sentinel.
    • Event Hub: uses EventHubProducerClient (SP RBAC). Select this for downstream SIEMs such as Splunk, QRadar, or Elastic.
  4. Select Next.
  5. Complete the Credentials & destination step based on your target type:
    • Log Analytics / Sentinel: Select the service principal from the dropdown, enter the Data Collection Endpoint (DCE) URL (format: https://...ingest.monitor.azure.com), the DCR Immutable ID (format: dcr-...), and confirm or update the Stream name (default: Custom-Turbo360Activity_CL). Use Download Bicep template to deploy the table, DCE, and DCR together, or Download sample record if you are creating the table manually and need the schema.
    • Event Hub: Select the service principal from the dropdown, enter the Event Hub Namespace (FQDN) (e.g. yournamespace.servicebus.windows.net) and the Event Hub name.
  6. Select Test connection and wait for a successful result. You cannot proceed until the connection test passes.
  7. Select Next.
  8. In the Log sources step, select one or more activity sources to include in this target. Select Select all to include every available source.
  9. Select Next.
  10. Review the target summary on the Review step, then select Save changes (or Save if this is a new target) to save as a draft.

Edit a target

Editing a target lets you update any configuration (name, interval, credentials, destination details, or log source selection) without deleting and recreating it.

  1. Navigate to Settings > SIEM export.
  2. In the targets list, locate the target and select the Edit icon (pencil) in the Actions column.
  3. The wizard opens in edit mode with all existing values pre-filled. Step through each stage, making your changes. To pause the target, clear the Enabled checkbox in the Basics step. The target status changes to Paused when you save.
  4. On the Review step, select Save changes to apply your updates.

Run a target now

Run now triggers an immediate export, bypassing the schedule. It exports all activity accumulated since the last run.

  1. Navigate to Settings > SIEM export.
  2. In the targets list, locate the target and select the Run now icon (lightning bolt) in the Actions column.
  3. In the Run SIEM export now dialog, select Run now to confirm.

Pause a target

Pausing a target stops scheduled exports until you resume it. Activity records continue to accumulate in Turbo360 during the pause and are not lost.

  1. Navigate to Settings > SIEM export.
  2. In the targets list, locate the target and select the Pause icon in the Actions column.
  3. In the Pause SIEM export target dialog, select Pause to confirm.

The target status changes to Paused. Logs already written to the SIEM are unaffected.

Resume a target

When resuming a paused target, you choose how to handle the logs that accumulated during the pause.

  1. Navigate to Settings > SIEM export.
  2. In the targets list, locate the paused target and select the Resume icon in the Actions column.
  3. In the Resume dialog, choose one of the following:
    • Catch up: replays every log accumulated during the pause. Nothing is lost.
    • Only new data: skips the backlog and exports only logs from the point of resumption onward.
  4. Select your preferred option to confirm. The target status returns to Active.

Delete a target

Deleting a target removes the schedule and all stored destination configuration. Logs already written to the SIEM are not affected and are not deleted.

  1. Navigate to Settings > SIEM export.
  2. In the targets list, locate the target and select the Delete icon (bin) in the Actions column.
  3. In the Delete SIEM export target dialog, select Delete to confirm.

Configuration

The following fields are configurable when creating or editing a SIEM export target.

Option Description
Name A display name for the target. Used to identify it in the targets list.
Export interval How often the target runs. Options are 30 min or 60 min.
Enabled Controls whether the target is active. Enabled by default when creating a new target. Clear this at creation to save the target without activating it, or clear it when editing an existing target to pause it.
Target type The destination type: Log Analytics / Sentinel (DCR via Logs Ingestion API) or Event Hub (via EventHubProducerClient). Cannot be changed after the target is created.
Service principal The service principal Turbo360 uses to authenticate with the destination. Must be registered in Settings > Service principals.
Data Collection Endpoint (DCE) (Log Analytics targets only) The ingestion endpoint URL for the DCE associated with your DCR. Format: https://...ingest.monitor.azure.com.
DCR Immutable ID (Log Analytics targets only) The immutable identifier of the Data Collection Rule. Format: dcr-....
Stream name (Log Analytics targets only) The stream name within the DCR. Defaults to Custom-Turbo360Activity_CL.
Event Hub Namespace (FQDN) (Event Hub targets only) The fully qualified domain name of the Event Hub namespace. Format: yournamespace.servicebus.windows.net.
Event Hub name (Event Hub targets only) The name of the specific Event Hub within the namespace.
Log sources The Turbo360 activity categories to include in this target. At least one source must be selected.

Limitations

  • Only the Account owner can access SIEM export. No other role can view or manage targets.
  • Target type (Log Analytics / Sentinel or Event Hub) cannot be changed after the target is created. Delete and recreate the target to switch types.
  • The export interval cannot be set below 30 minutes.
  • A single target exports all selected log sources to one destination. To route different log sources to different destinations, create separate targets.

Troubleshooting

  1. Connection test fails for a Log Analytics target
    Cause: The service principal does not have the Monitoring Metrics Publisher role on the DCR, or the DCE URL or DCR Immutable ID is incorrect.
    Fix: Verify the DCE URL begins with https:// and ends with .ingest.monitor.azure.com. Verify the DCR Immutable ID begins with dcr-. In the Azure portal, confirm the service principal has the Monitoring Metrics Publisher role assigned directly on the DCR resource.

  2. Connection test fails for an Event Hub target
    Cause: The service principal does not have the Azure Event Hubs Data Sender role on the hub, or the namespace FQDN or hub name is incorrect.
    Fix: Confirm the namespace FQDN ends with .servicebus.windows.net and that the hub name matches exactly. In the Azure portal, confirm the service principal has the Azure Event Hubs Data Sender role assigned on the Event Hub resource (not just the namespace).

  3. Target runs but no records appear in Log Analytics
    Cause: The DCR stream name does not match the custom table name in the workspace, or the table has not been created yet.
    Fix: Verify the stream name in the target configuration matches the stream defined in the DCR. If you created the table manually, confirm the schema matches the sample record. Redeploy using the Bicep template if needed.

  4. Target shows a failed last run status
    Cause: A transient connectivity error, an expired service principal credential, or a destination-side issue (workspace throttling, hub unavailability) caused the run to fail.
    Fix: Select Run now to trigger an immediate retry. If the run fails again, check the service principal credentials in Settings > Service principals and verify the destination resource is accessible.

  5. SIEM export is not visible in Settings
    Cause: The signed-in user is not the Account owner.
    Fix: SIEM export is accessible only to the Account owner. Ask your Account owner to configure targets or to grant Account owner access where appropriate.

Related articles