AKS container log collection is disabled

Enable AKS container log collection and verify that logs arrive.

Description

Disabling the omsagent add-on in AKS stops Azure Monitor container log collection through that integration.

Potential impact

Without an alternative collection path, records needed to investigate failures or suspicious workload activity may be missing.

Remediation

Enable container log collection and configure a Log Analytics workspace and collection rules. Prepare managed identity authentication and required permissions, then verify incoming logs.

Examples

These are add-on configuration excerpts, not complete cluster deployment templates. Set logAnalyticsWorkspaceResourceId to an existing workspace’s resource ID. Control plane logs require separate diagnostic settings.

Before

bicep
param kubernetesVersion string

resource aksCluster1 'Microsoft.ContainerService/managedClusters@2020-02-01' = {
  name: 'aksCluster1'
  location: resourceGroup().location
  properties: {
    kubernetesVersion: kubernetesVersion
    addonProfiles: {
      omsagent: {
        enabled: false
      }
    }
  }
}

After

bicep
param kubernetesVersion string
param logAnalyticsWorkspaceResourceId string

resource aksCluster1 'Microsoft.ContainerService/managedClusters@2020-02-01' = {
  name: 'aksCluster1'
  location: resourceGroup().location
  properties: {
    kubernetesVersion: kubernetesVersion
    addonProfiles: {
      omsagent: {
        enabled: true
        config: {
          logAnalyticsWorkspaceResourceID: logAnalyticsWorkspaceResourceId
          useAADAuth: 'true'
        }
      }
    }
  }
}

References