Description
If StorageRead, StorageWrite and StorageDelete are disabled in Azure Queue Storage diagnostic settings, those settings do not collect the corresponding operation logs.
Potential impact
Without another collection path, records needed to investigate queue data access or changes may be missing.
Remediation
Enable the required log categories at the queue service scope and configure a destination such as Log Analytics. Verify that logs arrive and set retention to suit operational needs.
Examples
The examples apply to queueServices/default in an existing storage account. Supply the account name and an existing workspace ID. Blob, File and Table services use separate diagnostic settings.
Before
bicep
param storageAccountName string
param workspaceId string
resource storageAccount 'Microsoft.Storage/storageAccounts@2021-09-01' existing = {
name: storageAccountName
}
resource queueService 'Microsoft.Storage/storageAccounts/queueServices@2021-09-01' existing = {
parent: storageAccount
name: 'default'
}
resource default_Microsoft_Insights 'Microsoft.Insights/diagnosticSettings@2021-05-01-preview' = {
name: 'default'
scope: queueService
properties: {
workspaceId: workspaceId
logs: [
{
category: 'StorageRead'
enabled: false
}
{
category: 'StorageWrite'
enabled: false
}
{
category: 'StorageDelete'
enabled: false
}
]
}
}
After
bicep
param storageAccountName string
param workspaceId string
resource storageAccount 'Microsoft.Storage/storageAccounts@2021-09-01' existing = {
name: storageAccountName
}
resource queueService 'Microsoft.Storage/storageAccounts/queueServices@2021-09-01' existing = {
parent: storageAccount
name: 'default'
}
resource default_Microsoft_Insights 'Microsoft.Insights/diagnosticSettings@2021-05-01-preview' = {
name: 'default'
scope: queueService
properties: {
workspaceId: workspaceId
logs: [
{
category: 'StorageRead'
enabled: true
}
{
category: 'StorageWrite'
enabled: true
}
{
category: 'StorageDelete'
enabled: true
}
]
}
}