Description
Azure diagnostic settings send selected logs and metrics to configured destinations. Omitting categories needed for investigation can leave important operational and security events unavailable in the central store.
Categories depend on the target. Administrative, Alert, Policy and Security are subscription Activity Log categories, not a universal list for every Azure resource. Key Vault audit logs, for example, use AuditEvent.
Potential impact
- Central records needed to investigate management operations or security events may be missing.
- Unsupported categories or an incorrect destination can prevent configuration or delivery of the required logs.
Remediation
- Check the target's supported categories or category groups and configure
enabled_logfor operational and security requirements. - For subscription Activity Logs, select the required administrative, alert, policy and security categories. Use service-specific categories for individual resources.
- Specify an approved destination, then generate events and verify receipt, access permissions and retention.
Examples
The first is an incomplete Key Vault diagnostic setting without categories or a destination. The revised example targets the subscription Activity Log, where these four categories apply. Supply the referenced subscription and workspace separately.
Before
resource "azurerm_monitor_diagnostic_setting" "example" {
name = "diagnostic-settings-name"
target_resource_id = azurerm_key_vault.example.id
}
This does not provide a complete log-collection configuration.
After
resource "azurerm_monitor_diagnostic_setting" "example" {
name = "diagnostic-settings-name"
target_resource_id = data.azurerm_subscription.example.id
log_analytics_workspace_id = azurerm_log_analytics_workspace.example.id
enabled_log {
category = "Administrative"
}
enabled_log {
category = "Alert"
}
enabled_log {
category = "Policy"
}
enabled_log {
category = "Security"
}
}
The selected subscription categories are sent to Log Analytics. Do not apply this category list unchanged to individual resources such as Key Vault.