Description
Disabling the omsagent add-on in AKS stops Azure Monitor container log collection through that integration.
Potential impact
Without an alternative collection path, records needed to investigate failures or suspicious workload activity may be missing.
Remediation
Enable container log collection and configure a Log Analytics workspace and collection rules. Prepare managed identity authentication and required permissions, then verify incoming logs.
Examples
These are add-on configuration excerpts, not complete cluster deployment templates. Set logAnalyticsWorkspaceResourceId to an existing workspace’s resource ID. Control plane logs require separate diagnostic settings.
Before
bicep
param kubernetesVersion string
resource aksCluster1 'Microsoft.ContainerService/managedClusters@2020-02-01' = {
name: 'aksCluster1'
location: resourceGroup().location
properties: {
kubernetesVersion: kubernetesVersion
addonProfiles: {
omsagent: {
enabled: false
}
}
}
}
After
bicep
param kubernetesVersion string
param logAnalyticsWorkspaceResourceId string
resource aksCluster1 'Microsoft.ContainerService/managedClusters@2020-02-01' = {
name: 'aksCluster1'
location: resourceGroup().location
properties: {
kubernetesVersion: kubernetesVersion
addonProfiles: {
omsagent: {
enabled: true
config: {
logAnalyticsWorkspaceResourceID: logAnalyticsWorkspaceResourceId
useAADAuth: 'true'
}
}
}
}
}