Azure Functions connector
The Azure Functions connector lets an agent run custom code in Azure without leaving Elastic: invoke an HTTP-triggered function to do remediation or enrichment, read the keys that an invoke needs, resolve a function app and its running state, and restart, stop, or start an app that is wedged or compromised.
This connector is currently available in Agent Builder only. Workflow support is planned for a future release.
The connector authenticates as a Microsoft Entra app registration (service principal) using the OAuth 2.0 Client Credentials grant.
Azure splits functions across two planes, and this connector uses both:
- The management plane (Azure Resource Manager) resolves apps and functions, reads keys, and controls an app's lifecycle. These actions authenticate with the service principal.
- The data plane (the app's own hostname, such as
my-app.azurewebsites.net) runs the function. It does not accept the service principal token: it authenticates with a function or host key. Theinvokeaction resolves the app's hostname over the management plane first, then sends the key in thex-functions-keyheader.
You can create an Azure Functions connector in Stack Management > Connectors.
- Subscription ID
- The Azure subscription (a GUID) that every action in this connector operates against.
- Token URL
- The Microsoft Entra v2.0 token endpoint for your tenant:
https://login.microsoftonline.com/{tenant-id}/oauth2/v2.0/token, with{tenant-id}replaced by your tenant ID. - Client ID
- The Application (client) ID of the Microsoft Entra app registration.
- Client Secret
- A client secret created for the Microsoft Entra app registration.
The app registration must have the Reader role on the subscription for getFunctionApp, listFunctionApps, listFunctions, and getFunction. It must have the Website Contributor role to restart, stop, or start an app, to re-sync triggers with listSyncFunctionTriggers, and to read keys with listFunctionKeys or listHostKeys.
The invoke action does not use the service principal token. It authenticates with a function or host key, which you supply in the functionKey parameter.
| Action | Description |
|---|---|
invoke |
Invoke an HTTP-triggered function and return its status, headers, and body. Any status the function returns is reported in the status field rather than raised as an error; only an authentication failure or a transport error throws. Parameters: resourceGroupName, functionAppName, functionName (all three required), method, route, body, query, functionKey. |
listFunctionKeys |
Read the function-level keys of one function, as a name-to-key map. Parameters: resourceGroupName, functionAppName, functionName (all three required). |
getFunctionApp |
Get a function app's configuration and running state. Parameters: resourceGroupName, functionAppName (both required). |
restartFunctionApp |
Restart a function app. Parameters: resourceGroupName, functionAppName (both required), softRestart, synchronous. |
listFunctions |
List the functions in an app, with each function's trigger config, language, and invoke URL template. Parameters: resourceGroupName, functionAppName (both required). |
listFunctionApps |
List the App Service sites in the subscription, or in one resource group. Parameters: resourceGroupName, includeSlots (both optional). |
stopFunctionApp |
Stop a function app, so it runs no further executions. Parameters: resourceGroupName, functionAppName (both required). |
startFunctionApp |
Start a stopped function app. Parameters: resourceGroupName, functionAppName (both required). |
listHostKeys |
Read an app's host-level keys: masterKey, functionKeys, and systemKeys. Parameters: resourceGroupName, functionAppName (both required). |
getFunction |
Get one function's configuration, including its trigger type and custom route. Parameters: resourceGroupName, functionAppName, functionName (all three required). |
listSyncFunctionTriggers |
Re-synchronize the app's trigger metadata with its deployed content and return the sync status. Parameters: resourceGroupName, functionAppName (both required). |
listFunctions and listFunctionApps follow Azure's pagination links and return every page. If a result set is larger than the connector retrieves in one call, the response includes truncated: true; narrow the query with resourceGroupName in that case.
invoke does not follow redirects. A function that answers with a 3xx returns that status and its Location header unchanged, so that the function key is never sent to another host.
listFunctionKeys and listHostKeys return live credentials. The masterKey from listHostKeys grants administrative access to the whole app, so prefer listFunctionKeys when only one function is invoked.
Use the Action configuration settings to customize connector networking, such as proxies, certificates, or TLS settings. You can set configurations that apply to all your connectors or use xpack.actions.customHostSettings to set per-host configurations.
To use the Azure Functions connector, you need to:
- In the Azure Portal, go to Microsoft Entra ID > App registrations and create a new app registration (or reuse an existing one). Note its Application (client) ID and Directory (tenant) ID.
- Under Certificates & secrets, create a new client secret and copy its value — it's only shown once.
- Assign the app registration the Reader role on the subscription for read-only use: go to the subscription's Access control (IAM) > Add role assignment.
- To restart, stop, or start an app, to re-sync triggers with
listSyncFunctionTriggers, or to read keys withlistFunctionKeysorlistHostKeys, assign the Website Contributor role instead, either on the subscription or on each function app. - When configuring the connector, enter the subscription ID, the token URL (
https://login.microsoftonline.com/{tenant-id}/oauth2/v2.0/token), the client ID, and the client secret.