Description
Comprehensive Tailscale telemetry for **Personal (Free) and Standard** tier tailnets. Polls nine endpoints in one Connect:
- `/logging/configuration` - configuration audit events (includes ACL, DNS, tag/group, settings changes)
- `/devices` - device inventory (hostname, OS, IPs, tags, lastSeen, expiry)
- `/users` - user inventory (role, status, deviceCount, connection state)
- `/keys?all=true` - auth keys, API tokens, and OAuth client metadata
- `/webhooks` - webhook configuration
- `/dns/nameservers`, `/dns/preferences`, `/dns/searchpaths` - DNS state (merged into single `Tailscale_Dns_CL` table with `ConfigType` discriminator)
- `/settings` - tailnet settings flags (device approval, key duration, etc.)
Split-DNS state (per-domain DNS overrides) is captured via the audit log rather than a separate snapshot table - every change is recorded with the full before/after document and actor attribution, which is richer than a periodic snapshot.
**OAuth scopes required on the Tailscale client:** `logs:configuration:read`, `devices:core:read`, `users:read`, `auth_keys:read`, `webhooks:read`, `dns:read`, `feature_settings:read` (or the bundled `all:read`). For Premium and Enterprise tailnets that also need network flow logs and posture integrations, install **Tailscale Premium (CCF)** instead.
- Declared status
- 1
- Declared author / publisher
- Community
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Data types
Declared permissions
Read/Write on the workspace
Workspace
Workspace
Connector instructions
Content published in the repository. Refer to the original file for all parameters.
Connect Tailscale
Generate an OAuth client at https://login.tailscale.com/admin/settings/oauth with these **Read** scopes: Logs > Configuration, General > DNS, General > Users, Devices > Core, Keys > Auth Keys, Keys > Webhooks, Settings > Feature Settings (or tick `all:read` to grant all read scopes at once). Find your tailnet name on the Keys page.
Tailscale tailnet
OAuth Client ID
OAuth Client Secret
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
9800e51↗- Source identifier
TailscaleCCF
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC