Review Azure service resource-log collection

Collect the resource logs needed from critical Azure services and send them to a central destination.

Description

Resource logs from App Service, Storage Account, Event Hubs, Service Bus and Application Gateway support investigations of service behavior and requests. Missing required logs can hinder failure analysis and security investigations.

Export supported categories through diagnostic settings and check service-specific logging prerequisites. Missing diagnostic settings do not mean that application logs or automatically collected Activity Logs are also absent.

Potential impact

  • Evidence for diagnosing service failures or unusual behavior may be missing.
  • Correlating related events across services in a central system can become difficult.

Remediation

  • Identify required log categories and existing collection paths for each critical service.
  • Configure supported logs and a Log Analytics, Storage Account or Event Hubs destination in azurerm_monitor_diagnostic_setting.
  • Check additional service logging settings, destination permissions and retention, then use real requests to test log delivery.

Examples

These excerpts use the legacy azurerm_app_service format. Referenced resources are omitted; select the web-app resource format supported by your AzureRM version.

Before

hcl
resource "azurerm_app_service" "example" {
  name                = "example-app-service"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  app_service_plan_id = azurerm_app_service_plan.example.id
}

This excerpt has no resource-log export. Check whether an existing alternative path collects the required logs.

After

hcl
resource "azurerm_app_service" "example" {
  name                = "example-app-service"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  app_service_plan_id = azurerm_app_service_plan.example.id
}

resource "azurerm_monitor_diagnostic_setting" "example" {
  name               = "app-service-diagnostics"
  target_resource_id = azurerm_app_service.example.id
  storage_account_id = azurerm_storage_account.example.id

  enabled_log {
    category = "AppServiceHTTPLogs"
  }
}

The AppServiceHTTPLogs category sends incoming HTTP request logs to the storage account. This category alone does not include every audit or application event.

References