Skip to content

Latest commit

 

History

History
232 lines (194 loc) · 7.92 KB

ensurelogprofileisconfiguredtocaptureallactivities.md

File metadata and controls

232 lines (194 loc) · 7.92 KB

Ensure log profile is configured to capture all activities

org.openrewrite.terraform.azure.EnsureLogProfileIsConfiguredToCaptureAllActivities

Ensure log profile is configured to capture all activities.

Tags

  • Azure
  • terraform
  • CKV_AZURE_38

Recipe source

GitHub, Issue Tracker, Maven Central

  • groupId: org.openrewrite.recipe
  • artifactId: rewrite-terraform
  • version: 2.3.9

Definition

{% tabs %} {% tab title="Recipe List" %}

{% endtab %}

{% tab title="Yaml Recipe List" %}

---
type: specs.openrewrite.org/v1beta/recipe
name: org.openrewrite.terraform.azure.EnsureLogProfileIsConfiguredToCaptureAllActivities
displayName: Ensure log profile is configured to capture all activities
description: Ensure log profile is configured to capture all activities.
tags:
  - Azure
  - terraform
  - CKV_AZURE_38
recipeList:
  - org.openrewrite.terraform.AddConfiguration:
      resourceName: azurerm_monitor_log_profile
      content: categories = [
  "Action",
  "Delete",
  "Write",
]

{% endtab %} {% endtabs %}

Usage

This recipe has no required configuration options. It can be activated by adding a dependency on org.openrewrite.recipe:rewrite-terraform:2.3.9 in your build file or by running a shell command (in which case no build changes are needed): {% tabs %} {% tab title="Gradle" %}

  1. Add the following to your build.gradle file: {% code title="build.gradle" %}
plugins {
    id("org.openrewrite.rewrite") version("6.23.3")
}

rewrite {
    activeRecipe("org.openrewrite.terraform.azure.EnsureLogProfileIsConfiguredToCaptureAllActivities")
    exportDatatables = true
}

repositories {
    mavenCentral()
}

dependencies {
    rewrite("org.openrewrite.recipe:rewrite-terraform:2.3.9")
}

{% endcode %} 2. Run gradle rewriteRun to run the recipe. {% endtab %}

{% tab title="Gradle init script" %}

  1. Create a file named init.gradle in the root of your project. {% code title="init.gradle" %}
initscript {
    repositories {
        maven { url "https://plugins.gradle.org/m2" }
    }
    dependencies { classpath("org.openrewrite:plugin:6.23.3") }
}
rootProject {
    plugins.apply(org.openrewrite.gradle.RewritePlugin)
    dependencies {
        rewrite("org.openrewrite.recipe:rewrite-terraform:2.3.9")
    }
    rewrite {
        activeRecipe("org.openrewrite.terraform.azure.EnsureLogProfileIsConfiguredToCaptureAllActivities")
        exportDatatables = true
    }
    afterEvaluate {
        if (repositories.isEmpty()) {
            repositories {
                mavenCentral()
            }
        }
    }
}

{% endcode %} 2. Run the recipe. {% code title="shell" overflow="wrap"%}

gradle --init-script init.gradle rewriteRun

{% endcode %} {% endtab %} {% tab title="Maven POM" %}

  1. Add the following to your pom.xml file: {% code title="pom.xml" %}
<project>
  <build>
    <plugins>
      <plugin>
        <groupId>org.openrewrite.maven</groupId>
        <artifactId>rewrite-maven-plugin</artifactId>
        <version>5.40.2</version>
        <configuration>
          <exportDatatables>true</exportDatatables>
          <activeRecipes>
            <recipe>org.openrewrite.terraform.azure.EnsureLogProfileIsConfiguredToCaptureAllActivities</recipe>
          </activeRecipes>
        </configuration>
        <dependencies>
          <dependency>
            <groupId>org.openrewrite.recipe</groupId>
            <artifactId>rewrite-terraform</artifactId>
            <version>2.3.9</version>
          </dependency>
        </dependencies>
      </plugin>
    </plugins>
  </build>
</project>

{% endcode %} 2. Run mvn rewrite:run to run the recipe. {% endtab %}

{% tab title="Maven Command Line" %}

You will need to have Maven installed on your machine before you can run the following command.

{% code title="shell" overflow="wrap" %}

mvn -U org.openrewrite.maven:rewrite-maven-plugin:run -Drewrite.recipeArtifactCoordinates=org.openrewrite.recipe:rewrite-terraform:RELEASE -Drewrite.activeRecipes=org.openrewrite.terraform.azure.EnsureLogProfileIsConfiguredToCaptureAllActivities -Drewrite.exportDatatables=true

{% endcode %} {% endtab %} {% tab title="Moderne CLI" %} You will need to have configured the Moderne CLI on your machine before you can run the following command.

{% code title="shell" %}

mod run . --recipe EnsureLogProfileIsConfiguredToCaptureAllActivities

{% endcode %} {% endtab %} {% endtabs %}

See how this recipe works across multiple open-source repositories

Moderne Link Image

The community edition of the Moderne platform enables you to easily run recipes across thousands of open-source repositories.

Please contact Moderne for more information about safely running the recipes on your own codebase in a private SaaS.

Data Tables

Source files that had results

org.openrewrite.table.SourcesFileResults

Source files that were modified by the recipe run.

Column Name Description
Source path before the run The source path of the file before the run. null when a source file was created during the run.
Source path after the run A recipe may modify the source path. This is the path after the run. null when a source file was deleted during the run.
Parent of the recipe that made changes In a hierarchical recipe, the parent of the recipe that made a change. Empty if this is the root of a hierarchy or if the recipe is not hierarchical at all.
Recipe that made changes The specific recipe that made a change.
Estimated time saving An estimated effort that a developer to fix manually instead of using this recipe, in unit of seconds.
Cycle The recipe cycle in which the change was made.

Source files that errored on a recipe

org.openrewrite.table.SourcesFileErrors

The details of all errors produced by a recipe run.

Column Name Description
Source path The file that failed to parse.
Recipe that made changes The specific recipe that made a change.
Stack trace The stack trace of the failure.

Recipe performance

org.openrewrite.table.RecipeRunStats

Statistics used in analyzing the performance of recipes.

Column Name Description
The recipe The recipe whose stats are being measured both individually and cumulatively.
Source file count The number of source files the recipe ran over.
Source file changed count The number of source files which were changed in the recipe run. Includes files created, deleted, and edited.
Cumulative scanning time The total time spent across the scanning phase of this recipe.
99th percentile scanning time 99 out of 100 scans completed in this amount of time.
Max scanning time The max time scanning any one source file.
Cumulative edit time The total time spent across the editing phase of this recipe.
99th percentile edit time 99 out of 100 edits completed in this amount of time.
Max edit time The max time editing any one source file.

Contributors

Jonathan Schneider, Aaron Gershman, pocan101, Kun Li, Knut Wannheden, Sam Snyder