Azure Queue Storage operation logs are disabled

Send Queue Storage read, write and delete logs to the required destination.

Description

If StorageRead, StorageWrite and StorageDelete are disabled in Azure Queue Storage diagnostic settings, those settings do not collect the corresponding operation logs.

Potential impact

Without another collection path, records needed to investigate queue data access or changes may be missing.

Remediation

Enable the required log categories at the queue service scope and configure a destination such as Log Analytics. Verify that logs arrive and set retention to suit operational needs.

Examples

The examples apply to queueServices/default in an existing storage account. Supply the account name and an existing workspace ID. Blob, File and Table services use separate diagnostic settings.

Before

bicep
param storageAccountName string
param workspaceId string

resource storageAccount 'Microsoft.Storage/storageAccounts@2021-09-01' existing = {
  name: storageAccountName
}

resource queueService 'Microsoft.Storage/storageAccounts/queueServices@2021-09-01' existing = {
  parent: storageAccount
  name: 'default'
}

resource default_Microsoft_Insights 'Microsoft.Insights/diagnosticSettings@2021-05-01-preview' = {
  name: 'default'
  scope: queueService
  properties: {
    workspaceId: workspaceId
    logs: [
      {
        category: 'StorageRead'
        enabled: false
      }
      {
        category: 'StorageWrite'
        enabled: false
      }
      {
        category: 'StorageDelete'
        enabled: false
      }
    ]
  }
}

After

bicep
param storageAccountName string
param workspaceId string

resource storageAccount 'Microsoft.Storage/storageAccounts@2021-09-01' existing = {
  name: storageAccountName
}

resource queueService 'Microsoft.Storage/storageAccounts/queueServices@2021-09-01' existing = {
  parent: storageAccount
  name: 'default'
}

resource default_Microsoft_Insights 'Microsoft.Insights/diagnosticSettings@2021-05-01-preview' = {
  name: 'default'
  scope: queueService
  properties: {
    workspaceId: workspaceId
    logs: [
      {
        category: 'StorageRead'
        enabled: true
      }
      {
        category: 'StorageWrite'
        enabled: true
      }
      {
        category: 'StorageDelete'
        enabled: true
      }
    ]
  }
}

References