↳ GitHub sourceConnector
Citrix DaaS Audit & Sessions (via Codeless Connector Framework)
Description
Ingest configuration audit logs and session activity from Citrix DaaS (Citrix Virtual Apps and Desktops service). Provides audit trails for security investigations, compliance monitoring, and operational troubleshooting.
- Declared status
- 1
- Declared author / publisher
- Microsoft
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Data types
Declared permissions
Read and Write permissions are required.
Workspace
Workspace
Citrix Cloud API Access
Required permissions: Citrix Cloud API client credentials with read access to CVAD Manage APIs
Connector instructions
Content published in the repository. Refer to the original file for all parameters.
Configure Citrix Cloud API Access
Follow these steps to enable API access:
1. Log in to **Citrix Cloud** console
2. Navigate to **Identity and Access Management** > **API Access**
3. Click **Create Client** (Secure Client)
4. Copy the **Client ID** and **Client Secret**
5. Note your **Customer ID** and **Site ID** (Instance ID)
To collect logs from multiple Citrix tenants, add a separate connection for each tenant. Every record is tagged with its **CitrixCustomerId** so you can differentiate tenants.
Add Citrix tenant
Add Citrix DaaS Connection
Base API URL
Citrix Customer ID
Citrix Site ID (Instance ID)
OAuth Client ID
OAuth Client Secret
Create a separate connection for each Citrix tenant you want to collect logs from.
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
9800e51↗- Source identifier
CitrixDaaSActionsConnector
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC