Ensure that diagnostic settings are configured to log the appropriate activities from the Azure Monitor control/management plane.
This rule resolution is part of the Conformity Security & Compliance tool for Azure.
optimisation
excellence
efficiency
An Azure Monitor diagnostic setting controls how the diagnostic logs are exported. When a diagnostic setting is created using the Azure Portal, by default no log categories are selected. Capturing the appropriate log categories (i.e. Administrative, Security, Alert, and Policy) for the activities performed within your Azure subscriptions provides proper alerting.
Audit
To determine if the diagnostic settings capture the appropriate log categories, perform the following operations:
Remediation / Resolution
To configure Microsoft Azure diagnostic settings to capture appropriate log categories, perform the following operations:
References
- Azure Official Documentation
- Create diagnostic settings to send Azure Monitor platform logs and metrics to different destinations
- Resource Manager template samples for diagnostic settings in Azure Monitor
- LT-4: Enable logging for Azure resources
- Azure Command Line Interface (CLI) Documentation
- az monitor diagnostic-settings subscription list
- az monitor diagnostic-settings subscription update