↳ GitHub sourceConnector

Tailscale Standard (CCF)

Description

Comprehensive Tailscale telemetry for **Personal (Free) and Standard** tier tailnets. Polls nine endpoints in one Connect: - `/logging/configuration` - configuration audit events (includes ACL, DNS, tag/group, settings changes) - `/devices` - device inventory (hostname, OS, IPs, tags, lastSeen, expiry) - `/users` - user inventory (role, status, deviceCount, connection state) - `/keys?all=true` - auth keys, API tokens, and OAuth client metadata - `/webhooks` - webhook configuration - `/dns/nameservers`, `/dns/preferences`, `/dns/searchpaths` - DNS state (merged into single `Tailscale_Dns_CL` table with `ConfigType` discriminator) - `/settings` - tailnet settings flags (device approval, key duration, etc.) Split-DNS state (per-domain DNS overrides) is captured via the audit log rather than a separate snapshot table - every change is recorded with the full before/after document and actor attribution, which is richer than a periodic snapshot. **OAuth scopes required on the Tailscale client:** `logs:configuration:read`, `devices:core:read`, `users:read`, `auth_keys:read`, `webhooks:read`, `dns:read`, `feature_settings:read` (or the bundled `all:read`). For Premium and Enterprise tailnets that also need network flow logs and posture integrations, install **Tailscale Premium (CCF)** instead.
Declared status
1
Declared author / publisher
Community

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

Read/Write on the workspace
Workspace
Workspace

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

Connect Tailscale
Generate an OAuth client at https://login.tailscale.com/admin/settings/oauth with these **Read** scopes: Logs > Configuration, General > DNS, General > Users, Devices > Core, Keys > Auth Keys, Keys > Webhooks, Settings > Feature Settings (or tick `all:read` to grant all read scopes at once). Find your tailnet name on the Keys page.
Tailscale tailnet
OAuth Client ID
OAuth Client Secret

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
TailscaleCCF
Additional source files 2Solutions/Tailscale (CCF)/Data Connectors/TailscaleAuditLogs_ccf/Tailscale_ConnectorDefinition.jsonsource ↗Solutions/Tailscale (CCF)/Data/Solution_Tailscale.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.