Description
Activity logs support incident investigation and change tracking, so they must remain available for the period the organization needs. A short period may leave logs deleted by the time a problem is discovered. A legacy Log Profile’s retentionPolicy controls retention; disabling it does not stop Activity Log collection. days: 0 means indefinite retention under that policy.
Potential impact
- Records for investigating older changes or incidents may be unavailable.
- Organizational audit and record-retention requirements may not be met.
Remediation
- Choose a period that meets investigation and audit requirements, and check the actual storage lifecycle and deletion policies. A 365-day period is an example target, not a universal requirement.
- Migrate legacy Log Profiles to diagnostic settings and configure retention at the actual Log Analytics, Storage or other destination. Check the oldest records that remain available.
Examples
These historical subscription-scope excerpts compare 300 and 365 days in a Log Profile. Required regions and destinations are omitted; use diagnostic settings for new configurations.
Before
resource activityLogProfile 'microsoft.insights/logprofiles@2016-03-01' = {
name: 'activity-log-profile'
location: 'eastus'
properties: {
categories: [
'Write'
]
retentionPolicy: {
enabled: true
days: 300
}
}
}
Three hundred days may be insufficient if a longer investigation history is needed.
After
resource activityLogProfile 'microsoft.insights/logprofiles@2016-03-01' = {
name: 'activity-log-profile'
location: 'eastus'
properties: {
categories: [
'Write'
]
retentionPolicy: {
enabled: true
days: 365
}
}
}
Retention increases to 365 days. This value alone does not address other deletion policies or every organizational requirement.