Description
Incorrect categories in a legacy Azure Log Profile can prevent required management events from being exported or cause the configuration to be rejected. Write, Delete and Action belong to this legacy export configuration; they are not interchangeable with current Activity Log diagnostic-setting categories. Native Activity Log recording and exporting to an external destination are also separate.
Potential impact
- Change and deletion history may be unavailable in external storage or monitoring tools.
- Missing long-term records can hinder incident analysis and audit response.
Remediation
- Check category spelling, regions and destinations in an existing Log Profile, and configure the required Write, Delete and Action values.
- Migrate legacy Log Profiles to diagnostic settings and select categories supported by that mechanism. Verify that required management events arrive at the actual destination.
Examples
These subscription-scope legacy excerpts compare categories only. Storage or Event Hubs destinations are omitted; use diagnostic settings for new exports.
Before
resource activityLogProfile 'microsoft.insights/logprofiles@2016-03-01' = {
name: 'activity-log-profile'
location: 'eastus'
properties: {
locations: [
'eastus'
]
categories: [
'Writ'
]
retentionPolicy: {
enabled: true
days: 450
}
}
}
Writ is a misspelling of the intended Write value and may prevent the required export from being configured correctly.
After
resource activityLogProfile 'microsoft.insights/logprofiles@2016-03-01' = {
name: 'activity-log-profile'
location: 'eastus'
properties: {
locations: [
'eastus'
]
categories: [
'Write'
'Delete'
'Action'
]
retentionPolicy: {
enabled: true
days: 450
}
}
}
Write, Delete and Action are selected in the historical format. Regions, destinations and actual delivery still need verification.