Description
Activity Logs record management operations such as Azure resource creation, deletion and permission changes. Deleting them before the required period ends can prevent later investigation of incidents or changes. Default retention is 90 days; longer storage requires diagnostic export and retention policies at the destination.
A 365-day period is an example organizational baseline, not a universal requirement. Consider investigation needs, contractual or regulatory obligations and storage costs together.
Potential impact
- Evidence of past management operations and changes may be missing.
- Logs required for incident investigations and audits may already have been deleted.
Remediation
- Define the required retention period and compare it with the records actually available.
- Export the required Activity Logs through diagnostic settings and configure the destination, such as Log Analytics retention or Storage Account lifecycle policies.
- Migrate legacy Log Profiles to diagnostic settings before their scheduled retirement on September 30, 2026. Review deletion policies and access permissions, and verify older records.
Examples
These historical excerpts compare retention in azurerm_monitor_log_profile, which was removed in AzureRM 4. Required categories, locations and destinations are omitted. They are not examples for a new current configuration.
Before
resource "azurerm_monitor_log_profile" "example" {
name = "default"
retention_policy {
enabled = true
days = 7
}
}
Seven days is insufficient for an organization that needs a longer investigation history.
After
resource "azurerm_monitor_log_profile" "example" {
name = "default"
retention_policy {
enabled = true
days = 367
}
}
This historical format specifies a longer period. The value alone does not meet every requirement; manage retention and deletion policies at the destination used by current diagnostic settings.