The CloudKeyVaultEvents table contains raw logs for Azure Key Vault resources, providing detailed per-operation visibility into key vault activities to support investigation, monitoring, and security analysis.
Schema
Name
Description
Type
AccountApplicationId
The application ID associated with the Key Vault access
String
AccountObjectId
The unique identifier of the object making the Key Vault access
String
AccountTenantId
The unique identifier of the Azure tenant
String
AccountType
The account type used (e.g., app, user)
String
AccountUpn
The user principal name of the accessing user
String
ActivityName
The name of the Key Vault activity performed
String
AdditionalFields
Additional information about the entity or event
Object
AzureResourceId
The Azure Resource ID of the Key Vault
String
DataSource
The source of the key vault logs
String
HttpStatusCode
HTTP status code returned by the Key Vault operation
Int32
IPAddress
The IP address from which the Key Vault was accessed
String
Location
The location of the Key Vault (region)
String
ReportId
Guid to identify the record in the specific table
String
RequestUri
The URI of the Key Vault request
String
ResultSignature
The result signature of the Key Vault operation
String
SourceSystem
String
SubscriptionId
Unique identifier assigned to the Azure subscription