Review Azure Log Profile export categories

Verify that required management activity reaches the actual log destination.

Description

Incorrect categories in a legacy Azure Log Profile can prevent required management events from being exported or cause the configuration to be rejected. Write, Delete and Action belong to this legacy export configuration; they are not interchangeable with current Activity Log diagnostic-setting categories. Native Activity Log recording and exporting to an external destination are also separate.

Potential impact

  • Change and deletion history may be unavailable in external storage or monitoring tools.
  • Missing long-term records can hinder incident analysis and audit response.

Remediation

  • Check category spelling, regions and destinations in an existing Log Profile, and configure the required Write, Delete and Action values.
  • Migrate legacy Log Profiles to diagnostic settings and select categories supported by that mechanism. Verify that required management events arrive at the actual destination.

Examples

These subscription-scope legacy excerpts compare categories only. Storage or Event Hubs destinations are omitted; use diagnostic settings for new exports.

Before

bicep
resource activityLogProfile 'microsoft.insights/logprofiles@2016-03-01' = {
  name: 'activity-log-profile'
  location: 'eastus'
  properties: {
    locations: [
      'eastus'
    ]
    categories: [
      'Writ'
    ]
    retentionPolicy: {
      enabled: true
      days: 450
    }
  }
}

Writ is a misspelling of the intended Write value and may prevent the required export from being configured correctly.

After

bicep
resource activityLogProfile 'microsoft.insights/logprofiles@2016-03-01' = {
  name: 'activity-log-profile'
  location: 'eastus'
  properties: {
    locations: [
      'eastus'
    ]
    categories: [
      'Write'
      'Delete'
      'Action'
    ]
    retentionPolicy: {
      enabled: true
      days: 450
    }
  }
}

Write, Delete and Action are selected in the historical format. Regions, destinations and actual delivery still need verification.

References