Azure SQL監査ログの保持期間の確認

調査や監査に必要な期間、ログを保持してください。

説明

Azure SQLの監査ログの保持期間は、過去の活動を調査できる範囲を決めます。Blob Storageの監査ポリシーでretention_in_days = 0は、ログを破棄する意味ではなく無期限の保持を意味します。

想定される影響

必要な調査期間より短く保持すると、過去のアクセスや変更履歴を確認できなくなる場合があります。

対処方法

組織の調査・監査要件に応じてretention_in_daysを設定してください。90日を超える保持が必要なら、それより長い期間を指定し、ストレージのライフサイクルルールで先に削除されないことも確認してください。

例

以下は現在のAzureRMの独立した監査ポリシーで保持期間を20日から95日に延ばす例です。95日は例示であり、すべての組織に必須の基準ではありません。パスワードも例示用です。

変更前

hcl
resource "azurerm_mssql_server" "example" {
  name                         = "sqlserver"
  resource_group_name          = azurerm_resource_group.example.name
  location                     = azurerm_resource_group.example.location
  version                      = "12.0"
  administrator_login          = "mradministrator"
  administrator_login_password = "thisIsDog11"

}

resource "azurerm_mssql_server_extended_auditing_policy" "example" {
  server_id = azurerm_mssql_server.example.id
  blob_storage_endpoint                        = azurerm_storage_account.example.primary_blob_endpoint
  storage_account_access_key              = azurerm_storage_account.example.primary_access_key
  storage_account_access_key_is_secondary = false
  retention_in_days                       = 20
}

変更後

hcl
resource "azurerm_mssql_server" "example" {
  name                         = "sqlserver"
  resource_group_name          = azurerm_resource_group.example.name
  location                     = azurerm_resource_group.example.location
  version                      = "12.0"
  administrator_login          = "mradministrator"
  administrator_login_password = "thisIsDog11"

}

resource "azurerm_mssql_server_extended_auditing_policy" "example" {
  server_id = azurerm_mssql_server.example.id
  blob_storage_endpoint                        = azurerm_storage_account.example.primary_blob_endpoint
  storage_account_access_key              = azurerm_storage_account.example.primary_access_key
  storage_account_access_key_is_secondary = false
  retention_in_days                       = 95
}

参考資料