cancel
Showing results for 
Search instead for 
Did you mean: 
Administration & Architecture
Explore discussions on Databricks administration, deployment strategies, and architectural best practices. Connect with administrators and architects to optimize your Databricks environment for performance, scalability, and security.
cancel
Showing results for 
Search instead for 
Did you mean: 

Databricks Audit Logs Analysis

dbx-soundar
New Contributor II

Please share the attributes related to the audit logs

How is the audit logs can be utilized by cyber security team? 

What are the insights into the audit logs and how we can maintain the compliance? 

What are the non-compliance items can be identified from the audit logs and how to address? 

What is ServiceName and ActionName from the logs? 

2 REPLIES 2

Walter_C
Databricks Employee
Databricks Employee

The audit logs will only get the information of the events and actions being performed by users, service principals in the workspace, so there is no compliance actions being tracked itself.

The Service name is a subgroup of items you want to check, so for example if you want to check job related events, there is service name called Jobs, same for Account events, etc, while the action name is the actual event you want to track, if you want to check users logins, if a job was deleted, if a table was created in UC.

Thanks Walter for the response.

I have one final query. 

Is the format style for the logs follows any format style like CamelCase, Kebab-Case and Snake_case?

The format style followied to create the catalog/schema/table should be in sync with the databricks generated logs which will help to parse the logs consistently.

Appreciate your response to close this discussion.