Ensure that Diagnostic Log Delivery is Configured for Azure Databricks workspaces. Azure Databricks Diagnostic Logging provides insights into system operations, user activities, and security events within a Databricks workspace.
excellence
Enabling diagnostic logs helps organizations detect security threats by logging access, job executions, and cluster activities, ensure compliance with industry regulations, and monitor operational performance to troubleshoot issues proactively. Without diagnostic logging enabled, organizations lack visibility into security and operational activities within Databricks workspaces, making it difficult to maintain an audit trail for forensic investigations and meet regulatory compliance standards. Organizations need comprehensive logging to detect unauthorized access attempts, track job executions, monitor cluster state changes, and understand user account activities. The logs must be securely stored in approved locations such as Azure Log Analytics workspace for analysis and querying, Azure Storage Account for long-term retention, or Azure Event Hubs for integration with SIEM tools.
To enable diagnostic logging features, your Microsoft Azure Databricks workspaces must be on the Premium pricing tier. Logs consume storage and may require additional monitoring tools, leading to increased operational overhead and costs. Incomplete log configurations may result in missing critical events, reducing monitoring effectiveness. Organizations should carefully plan log retention policies and monitor storage costs associated with diagnostic logging.
Audit
To determine if diagnostic logging is configured for your Azure Databricks workspaces, perform the following operations:
Remediation / Resolution
To enable diagnostic logging for your Azure Databricks workspaces, perform the following operations: