Description
Activity Logs record management operations such as resource creation, updates, and deletion. If records are deleted too soon, a later incident investigation may lack necessary evidence. The default retention period is 90 days; longer retention requires export through diagnostic settings and retention management at the destination.
365 days is an example of an organizational requirement. Choose a period based on investigation needs, contractual or regulatory requirements, and storage costs.
Potential impact
- Management records needed for incident investigations or audits may already have been deleted.
- Change-history reviews and long-term analysis may become difficult.
Remediation
- Compare the required retention period with the records that are actually available.
- Export the required logs through diagnostic settings and configure destination controls, such as Log Analytics retention or Storage lifecycle policies.
- Existing Log Profiles are scheduled to retire on September 30, 2026; migrate to diagnostic settings. Verify collection coverage, deletion policies, and access controls.
Examples
These examples compare retention settings in the legacy Log Profile format, not a recommended new configuration. Supply valid resource group and storage account names and authentication for the actual environment.
Before
- name: 로그 프로필 생성
azure_rm_monitorlogprofile:
name: myProfile
location: eastus
locations:
- eastus
- westus
categories:
- Write
- Action
retention_policy:
enabled: false
storage_account:
resource_group: myResourceGroup
name: myStorageAccount
enabled: false disables this retention policy, not log collection. It does not by itself mean that records will soon be deleted.
After
- name: 로그 프로필 생성
azure_rm_monitorlogprofile:
name: myProfile
location: eastus
locations:
- eastus
- westus
categories:
- Write
- Action
retention_policy:
enabled: true
days: 380
storage_account:
resource_group: myResourceGroup
name: myStorageAccount
This legacy format specifies 380 days of retention. days: 0 means indefinite retention, but does not prevent other deletion policies. Manage current configurations through the actual export destination's retention and deletion controls.