Data Source

MongoDB Atlas solution ingests administration logs from MongoDB Atlas using the Administration API via Azure Function App connector.

Ingestion Mechanism

Function App-based connector with filtering capabilities for network IDs and log categories. Ingests to custom table MDBALogTable_CL in Log Analytics workspace.

Detection Surface Unlocked

  • Database administration activity monitoring
  • User access pattern analysis for MongoDB Atlas clusters
  • Configuration change tracking and unauthorized modifications
  • Network-level filtering for focused monitoring on specific MongoDB deployments
  • Atlas cluster audit logging for compliance and security oversight

Affected Files

Solutions/MongoDBAtlas/Data Connectors/ containing Function App implementation, deployment templates, and UI definitions