Description
Azure diagnostic settings send supported resource logs, metrics and subscription Activity Logs to destinations such as Log Analytics, Event Hubs or a Storage Account. Without the required exports, tracing security events and operational problems across resources can be difficult.
Activity Logs and platform metrics are collected automatically, so missing diagnostic settings do not mean that all records are absent. Activity Logs are retained for 90 days by default. Resource logs require checking the service’s collection settings and supported categories.
Potential impact
- Missing events in central logs can delay root-cause analysis and assessment of the affected scope.
- Records needed for longer investigations may be unavailable after the default retention period.
Remediation
- Identify required log categories and existing collection paths for critical resources and subscriptions.
- Set supported categories and a suitable destination in
azurerm_monitor_diagnostic_setting. Check any additional service-specific logging settings. - Test event delivery and destination retention, and manage log access and cost.
Examples
The existing Log Analytics workspace is omitted. This partial example exports the Administrative category of the subscription Activity Log.
Before
data "azurerm_subscription" "example" {}
This excerpt references a subscription without configuring log export. It does not establish whether diagnostic settings exist elsewhere.
After
data "azurerm_subscription" "example" {}
resource "azurerm_monitor_diagnostic_setting" "example" {
name = "subscription-diagnostics"
target_resource_id = data.azurerm_subscription.example.id
log_analytics_workspace_id = azurerm_log_analytics_workspace.example.id
enabled_log {
category = "Administrative"
}
}
The selected category is sent to the workspace. This does not include every Activity Log category; verify the required coverage and actual delivery.