Skip to content

Files

Latest commit

 

History

History
45 lines (32 loc) · 705 Bytes

azure-monitor-capture-all-activities.md

File metadata and controls

45 lines (32 loc) · 705 Bytes

Pattern: Missing capture of all Azure Monitor activities

Issue: -

Description

Log profiles should capture all categories to ensure that all events are logged

Resolution: Configure log profile to capture all activities.

Examples

Example of incorrect code:

resource "azurerm_monitor_log_profile" "bad_example" {
  name = "bad_example"

  categories = []

  retention_policy {
    enabled = true
    days    = 7
  }
}

Example of correct code:

resource "azurerm_monitor_log_profile" "good_example" {
  name = "good_example"

  categories = [
	  "Action",
	  "Delete",
	  "Write",
  ]

  retention_policy {
    enabled = true
    days    = 365
  }
}