설명
Azure Queue Storage 진단 설정에서 StorageRead, StorageWrite, StorageDelete가 비활성화되어 있으면 해당 설정으로 관련 작업 로그를 수집하지 않습니다.
잠재적 영향
다른 수집 경로도 없으면 큐 데이터 접근이나 변경을 조사할 기록이 부족할 수 있습니다.
해결 방법
큐 서비스 범위에서 필요한 로그 범주를 활성화하고 Log Analytics 같은 수집 대상을 지정하세요. 로그가 도착하는지 확인하고 보존 기간을 운영 목적에 맞게 정하세요.
예시
예시는 기존 스토리지 계정의 queueServices/default에 적용됩니다. 계정 이름과 기존 작업 영역 ID를 지정하세요. Blob·File·Table 서비스는 각각 별도 진단 설정을 구성합니다.
변경 전
bicep
param storageAccountName string
param workspaceId string
resource storageAccount 'Microsoft.Storage/storageAccounts@2021-09-01' existing = {
name: storageAccountName
}
resource queueService 'Microsoft.Storage/storageAccounts/queueServices@2021-09-01' existing = {
parent: storageAccount
name: 'default'
}
resource default_Microsoft_Insights 'Microsoft.Insights/diagnosticSettings@2021-05-01-preview' = {
name: 'default'
scope: queueService
properties: {
workspaceId: workspaceId
logs: [
{
category: 'StorageRead'
enabled: false
}
{
category: 'StorageWrite'
enabled: false
}
{
category: 'StorageDelete'
enabled: false
}
]
}
}
변경 후
bicep
param storageAccountName string
param workspaceId string
resource storageAccount 'Microsoft.Storage/storageAccounts@2021-09-01' existing = {
name: storageAccountName
}
resource queueService 'Microsoft.Storage/storageAccounts/queueServices@2021-09-01' existing = {
parent: storageAccount
name: 'default'
}
resource default_Microsoft_Insights 'Microsoft.Insights/diagnosticSettings@2021-05-01-preview' = {
name: 'default'
scope: queueService
properties: {
workspaceId: workspaceId
logs: [
{
category: 'StorageRead'
enabled: true
}
{
category: 'StorageWrite'
enabled: true
}
{
category: 'StorageDelete'
enabled: true
}
]
}
}