Skip to content

Commit 4109f3b

Browse files
committed
added all logs policies
1 parent d973cca commit 4109f3b

File tree

1 file changed

+147
-39
lines changed

1 file changed

+147
-39
lines changed

articles/azure-monitor/essentials/diagnostics-settings-policies-deployifnotexists.md

Lines changed: 147 additions & 39 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.author: edbaynash
66
services: azure-monitor
77
ms.topic: conceptual
88
ms.custom: devx-track-azurecli, devx-track-azurepowershell
9-
ms.date: 02/25/2023
9+
ms.date: 02/25/2024
1010
ms.reviewer: lualderm
1111
---
1212

@@ -16,7 +16,7 @@ Policies and policy initiatives provide a simple method to enable logging at-sca
1616
Enable resource logs to track activities and events that take place on your resources and give you visibility and insights into any changes that occur.
1717
Assign policies to enable resource logs and to send them to destinations according to your needs. Send logs to event hubs for third-party SIEM systems, enabling continuous security operations. Send logs to storage accounts for longer term storage or the fulfillment of regulatory compliance.
1818

19-
A set of built-in policies and initiatives exists to direct resource logs to Log Analytics Workspaces, Event Hubs, and Storage Accounts. The policies enable audit logging, sending logs belonging to the **audit** log category group to an event hub, Log Analytics workspace or Storage Account. The policies' `effect` is `DeployIfNotExists`, which deploys the policy as a default if there aren't other settings defined.
19+
A set of built-in policies and initiatives exists to direct resource logs to Log Analytics Workspaces, Event Hubs, and Storage Accounts. The policies enable audit logging, sending logs belonging to the **audit** or the **All logs** log category group, to an event hub, Log Analytics workspace or Storage Account. The policies' `effect` is `DeployIfNotExists`, which deploys the policy as a default if there aren't other settings defined.
2020

2121

2222
## Deploy policies.
@@ -37,12 +37,12 @@ The following steps show how to apply the policy to send audit logs to for key v
3737
1. Select the **Parameters** tab.
3838
1. Select the Log Analytics Workspace that you want to send the audit logs to.
3939
1. Select the **Remediation** tab.
40-
:::image type="content" source="./media/diagnostics-settings-policies-deployifnotexists/assign-policy-parameters.png" alt-text="A screenshot of the assign policy page, parameters tab.":::
40+
:::image type="content" source="./media/diagnostics-settings-policies-deployifnotexists/assign-policy-parameters.png" lightbox="./media/diagnostics-settings-policies-deployifnotexists/assign-policy-parameters.png" alt-text="A screenshot of the assign policy page, parameters tab.":::
4141
1. On the remediation tab, select the keyvault policy from the **Policy to remediate** dropdown.
4242
1. Select the **Create a Managed Identity** checkbox.
4343
1. Under **Type of Managed Identity**, select **System assigned Managed Identity**.
4444
1. Select **Review + create**, then select **Create** .
45-
:::image type="content" source="./media/diagnostics-settings-policies-deployifnotexists/assign-policy-remediation.png" alt-text="A screenshot of the assign policy page, remediation tab.":::
45+
:::image type="content" source="./media/diagnostics-settings-policies-deployifnotexists/assign-policy-remediation.png" lightbox="./media/diagnostics-settings-policies-deployifnotexists/assign-policy-remediation.png" alt-text="A screenshot of the assign policy page, remediation tab.":::
4646

4747

4848
### [CLI](#tab/cli)
@@ -382,41 +382,149 @@ This policy deploys a diagnostic setting using a category group to route logs to
382382
383383
## Supported Resources
384384
385-
Built-in Audit logs policies for Log Analytics workspaces, Event Hubs, and Storage Accounts exist for the following resources:
386-
387-
* microsoft.agfoodplatform/farmbeats
388-
* microsoft.apimanagement/service
389-
* microsoft.appconfiguration/configurationstores
390-
* microsoft.attestation/attestationproviders
391-
* microsoft.automation/automationaccounts
392-
* microsoft.avs/privateclouds
393-
* microsoft.cache/redis
394-
* microsoft.cdn/profiles
395-
* microsoft.cognitiveservices/accounts
396-
* microsoft.containerregistry/registries
397-
* microsoft.devices/iothubs
398-
* microsoft.eventgrid/topics
399-
* microsoft.eventgrid/domains
400-
* microsoft.eventgrid/partnernamespaces
401-
* microsoft.eventhub/namespaces
402-
* microsoft.keyvault/vaults
403-
* microsoft.keyvault/managedhsms
404-
* microsoft.machinelearningservices/workspaces
405-
* microsoft.media/mediaservices
406-
* microsoft.media/videoanalyzers
407-
* microsoft.netapp/netappaccounts/capacitypools/volumes
408-
* microsoft.network/publicipaddresses
409-
* microsoft.network/virtualnetworkgateways
410-
* microsoft.network/p2svpngateways
411-
* microsoft.network/frontdoors
412-
* microsoft.network/bastionhosts
413-
* microsoft.operationalinsights/workspaces
414-
* microsoft.purview/accounts
415-
* microsoft.servicebus/namespaces
416-
* microsoft.signalrservice/signalr
417-
* microsoft.signalrservice/webpubsub
418-
* microsoft.sql/servers/databases
419-
* microsoft.sql/managedinstances
385+
Built-in All logs and Audit logs policies for Log Analytics workspaces, Event Hubs, and Storage Accounts exist for the following resources:
386+
387+
|Resource Type| All logs| Audit Logs|
388+
|---|---|---|
389+
|microsoft.aad/domainservices|Yes|Yes|
390+
|microsoft.agfoodplatform/farmbeats|Yes|Yes|
391+
|microsoft.analysisservices/servers|Yes|No|
392+
|microsoft.apimanagement/service|Yes|Yes|
393+
|microsoft.app/managedenvironments|Yes|Yes|
394+
|microsoft.appconfiguration/configurationstores|Yes|Yes|
395+
|microsoft.appplatform/spring|Yes|No|
396+
|microsoft.attestation/attestationproviders|Yes|Yes|
397+
|microsoft.automation/automationaccounts|Yes|Yes|
398+
|microsoft.autonomousdevelopmentplatform/workspaces|Yes|No|
399+
|microsoft.avs/privateclouds|Yes|Yes|
400+
|microsoft.azureplaywrightservice/accounts|Yes|Yes|
401+
|microsoft.azuresphere/catalogs|Yes|Yes|
402+
|microsoft.batch/batchaccounts|Yes|Yes|
403+
|microsoft.botservice/botservices|Yes|No|
404+
|microsoft.cache/redis|Yes|Yes|
405+
|microsoft.cache/redisenterprise/databases|Yes|Yes|
406+
|microsoft.cdn/cdnwebapplicationfirewallpolicies|Yes|No|
407+
|microsoft.cdn/profiles|Yes|Yes|
408+
|microsoft.cdn/profiles/endpoints|Yes|No|
409+
|microsoft.chaos/experiments|Yes|Yes|
410+
|microsoft.classicnetwork/networksecuritygroups|Yes|No|
411+
|microsoft.cloudtest/hostedpools|Yes|No|
412+
|microsoft.codesigning/codesigningaccounts|Yes|Yes|
413+
|microsoft.cognitiveservices/accounts|Yes|Yes|
414+
|microsoft.communication/communicationservices|Yes|No|
415+
|microsoft.community/communitytrainings|Yes|Yes|
416+
|microsoft.confidentialledger/managedccfs|Yes|Yes|
417+
|microsoft.connectedcache/enterprisemcccustomers|Yes|No|
418+
|microsoft.connectedcache/ispcustomers|Yes|No|
419+
|microsoft.containerinstance/containergroups|Yes|No|
420+
|microsoft.containerregistry/registries|Yes|Yes|
421+
|microsoft.customproviders/resourceproviders|Yes|No|
422+
|microsoft.d365customerinsights/instances|Yes|No|
423+
|microsoft.dashboard/grafana|Yes|Yes|
424+
|microsoft.databricks/workspaces|Yes|No|
425+
|microsoft.datafactory/factories|Yes|No|
426+
|microsoft.datalakeanalytics/accounts|Yes|No|
427+
|microsoft.datalakestore/accounts|Yes|No|
428+
|microsoft.dataprotection/backupvaults|Yes|No|
429+
|microsoft.datashare/accounts|Yes|No|
430+
|microsoft.dbformariadb/servers|Yes|No|
431+
|microsoft.dbformysql/flexibleservers|Yes|Yes|
432+
|microsoft.dbformysql/servers|Yes|No|
433+
|microsoft.dbforpostgresql/flexibleservers|Yes|Yes|
434+
|microsoft.dbforpostgresql/servergroupsv2|Yes|No|
435+
|microsoft.dbforpostgresql/servers|Yes|No|
436+
|microsoft.desktopvirtualization/applicationgroups|Yes|No|
437+
|microsoft.desktopvirtualization/hostpools|Yes|No|
438+
|microsoft.desktopvirtualization/scalingplans|Yes|No|
439+
|microsoft.desktopvirtualization/workspaces|Yes|No|
440+
|microsoft.devcenter/devcenters|Yes|Yes|
441+
|microsoft.devices/iothubs|Yes|Yes|
442+
|microsoft.devices/provisioningservices|Yes|No|
443+
|microsoft.digitaltwins/digitaltwinsinstances|Yes|No|
444+
|microsoft.documentdb/cassandraclusters|Yes|Yes|
445+
|microsoft.documentdb/databaseaccounts|Yes|Yes|
446+
|microsoft.documentdb/mongoclusters|Yes|Yes|
447+
|microsoft.eventgrid/domains|Yes|Yes|
448+
|microsoft.eventgrid/partnernamespaces|Yes|Yes|
449+
|microsoft.eventgrid/partnertopics|Yes|No|
450+
|microsoft.eventgrid/systemtopics|Yes|No|
451+
|microsoft.eventgrid/topics|Yes|Yes|
452+
|microsoft.eventhub/namespaces|Yes|Yes|
453+
|microsoft.experimentation/experimentworkspaces|Yes|No|
454+
|microsoft.healthcareapis/services|Yes|No|
455+
|microsoft.healthcareapis/workspaces/dicomservices|Yes|No|
456+
|microsoft.healthcareapis/workspaces/fhirservices|Yes|No|
457+
|microsoft.healthcareapis/workspaces/iotconnectors|Yes|No|
458+
|microsoft.insights/autoscalesettings|Yes|No|
459+
|microsoft.insights/components|Yes|No|
460+
|microsoft.insights/datacollectionrules|Yes|No|
461+
|microsoft.keyvault/managedhsms|Yes|Yes|
462+
|microsoft.keyvault/vaults|Yes|Yes|
463+
|microsoft.kusto/clusters|Yes|Yes|
464+
|microsoft.loadtestservice/loadtests|Yes|Yes|
465+
|microsoft.logic/integrationaccounts|Yes|No|
466+
|microsoft.logic/workflows|Yes|No|
467+
|microsoft.machinelearningservices/registries|Yes|Yes|
468+
|microsoft.machinelearningservices/workspaces|Yes|Yes|
469+
|microsoft.machinelearningservices/workspaces/onlineendpoints|Yes|No|
470+
|microsoft.managednetworkfabric/networkdevices|Yes|No|
471+
|microsoft.media/mediaservices|Yes|Yes|
472+
|microsoft.media/mediaservices/liveevents|Yes|Yes|
473+
|microsoft.media/mediaservices/streamingendpoints|Yes|Yes|
474+
|microsoft.netapp/netappaccounts/capacitypools/volumes|Yes|Yes|
475+
|microsoft.network/applicationgateways|Yes|No|
476+
|microsoft.network/azurefirewalls|Yes|No|
477+
|microsoft.network/bastionhosts|Yes|Yes|
478+
|microsoft.network/dnsresolverpolicies|Yes|No|
479+
|microsoft.network/expressroutecircuits|Yes|No|
480+
|microsoft.network/frontdoors|Yes|Yes|
481+
|microsoft.network/loadbalancers|Yes|No|
482+
|microsoft.network/networkmanagers|Yes|Yes|
483+
|microsoft.network/networkmanagers/ipampools|Yes|Yes|
484+
|microsoft.network/networksecuritygroups|Yes|No|
485+
|microsoft.network/networksecurityperimeters|Yes|No|
486+
|microsoft.network/p2svpngateways|Yes|Yes|
487+
|microsoft.network/publicipaddresses|Yes|Yes|
488+
|microsoft.network/publicipprefixes|Yes|Yes|
489+
|microsoft.network/trafficmanagerprofiles|Yes|No|
490+
|microsoft.network/virtualnetworkgateways|Yes|Yes|
491+
|microsoft.network/virtualnetworks|Yes|No|
492+
|microsoft.network/vpngateways|Yes|No|
493+
|microsoft.networkanalytics/dataproducts|Yes|Yes|
494+
|microsoft.networkcloud/baremetalmachines|Yes|No|
495+
|microsoft.networkcloud/clusters|Yes|No|
496+
|microsoft.networkcloud/storageappliances|Yes|No|
497+
|microsoft.networkfunction/azuretrafficcollectors|Yes|No|
498+
|microsoft.notificationhubs/namespaces|Yes|Yes|
499+
|microsoft.notificationhubs/namespaces/notificationhubs|Yes|Yes|
500+
|microsoft.openenergyplatform/energyservices|Yes|No|
501+
|microsoft.operationalinsights/workspaces|Yes|Yes|
502+
|microsoft.powerbi/tenants/workspaces|Yes|No|
503+
|microsoft.powerbidedicated/capacities|Yes|No|
504+
|microsoft.purview/accounts|Yes|Yes|
505+
|microsoft.recoveryservices/vaults|Yes|No|
506+
|microsoft.relay/namespaces|Yes|No|
507+
|microsoft.search/searchservices|Yes|Yes|
508+
|microsoft.servicebus/namespaces|Yes|Yes|
509+
|microsoft.servicenetworking/trafficcontrollers|Yes|No|
510+
|microsoft.signalrservice/signalr|Yes|Yes|
511+
|microsoft.signalrservice/webpubsub|Yes|Yes|
512+
|microsoft.sql/managedinstances|Yes|Yes|
513+
|microsoft.sql/managedinstances/databases|Yes|No|
514+
|microsoft.sql/servers/databases|Yes|Yes|
515+
|microsoft.storagecache/caches|Yes|No|
516+
|microsoft.storagemover/storagemovers|Yes|No|
517+
|microsoft.streamanalytics/streamingjobs|Yes|No|
518+
|microsoft.synapse/workspaces|Yes|Yes|
519+
|microsoft.synapse/workspaces/bigdatapools|Yes|Yes|
520+
|microsoft.synapse/workspaces/kustopools|Yes|Yes|
521+
|microsoft.synapse/workspaces/scopepools|Yes|Yes|
522+
|microsoft.synapse/workspaces/sqlpools|Yes|Yes|
523+
|microsoft.timeseriesinsights/environments|Yes|No|
524+
|microsoft.timeseriesinsights/environments/eventsources|Yes|No|
525+
|microsoft.videoindexer/accounts|Yes|No|
526+
|microsoft.web/hostingenvironments|Yes|Yes|
527+
|microsoft.workloads/sapvirtualinstances|Yes|Yes|
420528
421529
## Next Steps
422530

0 commit comments

Comments
 (0)