Data Source
MongoDB Atlas solution ingests administration logs from MongoDB Atlas using the Administration API via Azure Function App connector.
Ingestion Mechanism
Function App-based connector with filtering capabilities for network IDs and log categories. Ingests to custom table MDBALogTable_CL in Log Analytics workspace.
Detection Surface Unlocked
- Database administration activity monitoring
- User access pattern analysis for MongoDB Atlas clusters
- Configuration change tracking and unauthorized modifications
- Network-level filtering for focused monitoring on specific MongoDB deployments
- Atlas cluster audit logging for compliance and security oversight
Affected Files
Solutions/MongoDBAtlas/Data Connectors/ containing Function App implementation, deployment templates, and UI definitions