Skip to main content
Manusで任意のスキルを実行
ワンクリックで

ingest-entra-directory-audit-ocsf

スター3
フォーク0
更新日2026年7月11日 02:43

Convert verified Microsoft Entra directoryAudit events into OCSF 1.8 API Activity (6003). The first slice maps Microsoft Graph directory audit events for service-principal credential changes, app-role grants, and federated identity credential creation into deterministic OCSF records while preserving Entra natural IDs such as id, correlationId, and activityDateTime for SIEM dedupe and downstream correlation. Use when the user mentions Entra audit log ingestion, Microsoft Graph directoryAudit normalization, or feeding Entra identity telemetry into an OCSF pipeline. Do NOT use for Okta System Log, Azure Activity Logs, or as a detector or policy engine — this skill only normalizes verified Microsoft Graph directoryAudit payloads.

インストール

Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。

ファイルエクスプローラー
6 ファイル
SKILL.md
readonly