Risk Level: Medium (should be achieved)
Rule ID: Monitor-007
Ensure that diagnostic settings are configured to log the appropriate activities from the Azure Monitor control/management plane.
optimisation
excellence
efficiency
An Azure Monitor diagnostic setting controls how the diagnostic logs are exported. When a diagnostic setting is created using the Azure Portal, by default no log categories are selected. Capturing the appropriate log categories (i.e. Administrative, Security, Alert, and Policy) for the activities performed within your Azure subscriptions provides proper alerting.
Audit
To determine if the diagnostic settings capture the appropriate log categories, perform the following operations:
Remediation / Resolution
To configure Microsoft Azure diagnostic settings to capture appropriate log categories, perform the following operations:
References
- Azure Official Documentation
- Create diagnostic settings to send Azure Monitor platform logs and metrics to different destinations
- Resource Manager template samples for diagnostic settings in Azure Monitor
- LT-4: Enable logging for Azure resources
- Azure Command Line Interface (CLI) Documentation
- az monitor diagnostic-settings subscription list
- az monitor diagnostic-settings subscription update
Publication date Aug 16, 2019