Skip to content

Commit 4562a01

Browse files
authored
Merge pull request #109988 from rboucher/master
Update graphic for CMK and circonus for Partner article.
2 parents 1294972 + 2ddcbe8 commit 4562a01

File tree

6 files changed

+13
-13
lines changed

6 files changed

+13
-13
lines changed

articles/azure-monitor/platform/customer-managed-keys.md

Lines changed: 13 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@ We recommend you review [Limitations and constraints](#limitations-and-constrain
2828

2929
> [!NOTE]
3030
> Log Analytics and Application Insights are using the same data-store platform and query engine.
31-
> We are bringing these two stores together via integration of Application Insights into Log Analytics to create a single unified logs store under Azure Monitor. This change is planned for the second quarter of calendar year 2020. If you dont have to deploy CMK for your Application Insights data by then, we recommend waiting for the completion of the consolidation since such deployments will be disrupted by the consolidation and you will have to re-configure CMK after the migration to Log Analytics workspace. The 1TB per day minimum applies at the cluster level and until the consolidation completes during second quarter, Application Insights and Log Analytics require separate clusters.
31+
> We are bringing these two stores together via integration of Application Insights into Log Analytics to create a single unified logs store under Azure Monitor. This change is planned for the second quarter of calendar year 2020. If you don't have to deploy CMK for your Application Insights data by then, we recommend waiting for the completion of the consolidation since such deployments will be disrupted by the consolidation and you will have to re-configure CMK after the migration to Log Analytics workspace. The 1TB per day minimum applies at the cluster level and until the consolidation completes during second quarter, Application Insights and Log Analytics require separate clusters.
3232
3333
## Customer-managed key (CMK) overview
3434

@@ -69,11 +69,11 @@ with your Key Vault key. The underlay ADX cluster storage uses the
6969
managed identity that\'s associated with the *Cluster* resource to
7070
authenticate and access your Azure Key Vault via Azure Active Directory.
7171

72-
![CMK Overview](media/customer-managed-keys/cmk-overview.png)
73-
1. Customers Key Vault.
74-
2. Customers Log Analytics *Cluster* resource having managed identity with permissions to Key Vault – The identity is supported at the data-store (ADX cluster) level.
75-
3. Azure Monitor dedicated ADX cluster.
76-
4. Customers workspaces associated to *Cluster* resource for CMK encryption.
72+
![CMK Overview](media/customer-managed-keys/cmk-overview-8bit.png)
73+
1. Customer's Key Vault.
74+
2. Customer's Log Analytics *Cluster* resource having managed identity with permissions to Key Vault – The identity is supported at the data-store (ADX cluster) level.
75+
3. Azure Monitor dedicated ADX cluster.
76+
4. Customer's workspaces associated to *Cluster* resource for CMK encryption.
7777

7878
## Encryption keys management
7979

@@ -152,11 +152,11 @@ These settings are available via CLI and PowerShell:
152152

153153
### Create *Cluster* resource
154154

155-
This resource is used as an intermediate identity connection between your Key Vault and your Log Analytics workspaces. After you receive confirmation that your subscriptions were whitelisted, create a Log Analytics *Cluster* resource at the region where your workspaces are located. Application Insights and Log Analytics require separate *Cluster* resources types. The type of the *Cluster* resource is defined at creation time by setting the *clusterType* property to either *LogAnalytics*, or *ApplicationInsights*. The Cluster resource type cant be altered after.
155+
This resource is used as an intermediate identity connection between your Key Vault and your Log Analytics workspaces. After you receive confirmation that your subscriptions were whitelisted, create a Log Analytics *Cluster* resource at the region where your workspaces are located. Application Insights and Log Analytics require separate *Cluster* resources types. The type of the *Cluster* resource is defined at creation time by setting the *clusterType* property to either *LogAnalytics*, or *ApplicationInsights*. The Cluster resource type can't be altered after.
156156

157157
For Application Insights CMK configuration, follow the Appendix content.
158158

159-
You must specify the capacity reservation level (sku) when creating a *Cluster* resource. The capacity reservation level can be in the range of 1,000 to 2,000 GB per day and you can update it in steps of 100 later. If you need capacity reservation level higher than 2,000 GB per day, reach your Microsoft contact to enable it. This property doesnt affect billing currently -- once pricing model for dedicated cluster is introduced, billing will apply to any existing CMK deployments.
159+
You must specify the capacity reservation level (sku) when creating a *Cluster* resource. The capacity reservation level can be in the range of 1,000 to 2,000 GB per day and you can update it in steps of 100 later. If you need capacity reservation level higher than 2,000 GB per day, reach your Microsoft contact to enable it. This property doesn't affect billing currently -- once pricing model for dedicated cluster is introduced, billing will apply to any existing CMK deployments.
160160

161161
**Create**
162162

@@ -234,7 +234,7 @@ Update your Key Vault with a new access policy that grants permissions to your *
234234
- Key permissions: select 'Get', 'Wrap Key' and 'Unwrap Key' permissions.
235235
- Select principal: enter the principal-id value that returned in the response in the previous step.
236236

237-
![grant Key Vault permissions](media/customer-managed-keys/grant-key-vault-permissions.png)
237+
![grant Key Vault permissions](media/customer-managed-keys/grant-key-vault-permissions-8bit.png)
238238

239239
The *Get* permission is required to verify that your Key Vault is configured as recoverable to protect your key and the access to your Azure Monitor data.
240240

@@ -429,7 +429,7 @@ All your data is accessible after the key rotation operation including data inge
429429
must be turned on
430430
- [Purge protection](https://docs.microsoft.com/azure/key-vault/key-vault-ovw-soft-delete#purge-protection) should be turned on to guard against force deletion of the secret / vault even after soft delete
431431

432-
- Application Insights and Log Analytics require separate *Cluster* resources. The type of the *Cluster* resource is defined at creation time by setting the clusterType property to either LogAnalytics, or ApplicationInsights. The *Cluster* resource type cant be altered.
432+
- Application Insights and Log Analytics require separate *Cluster* resources. The type of the *Cluster* resource is defined at creation time by setting the "clusterType" property to either 'LogAnalytics', or 'ApplicationInsights'. The *Cluster* resource type can't be altered.
433433

434434
- *Cluster* resource move to another resource group or subscription
435435
isn't supported currently.
@@ -503,7 +503,7 @@ All your data is accessible after the key rotation operation including data inge
503503

504504
The same response as for '*Cluster* resources for a resource group', but in subscription scope.
505505

506-
- Delete your *Cluster* resource -- a soft-delete operation is performed to allow the recovery of your Cluster resource, your data and associated workspaces within 14 days, whether the deletion was accidental or intentional. The *Cluster* resource name remains reserved during the soft-delete period and you cant create a new cluster with that name.
506+
- Delete your *Cluster* resource -- a soft-delete operation is performed to allow the recovery of your Cluster resource, your data and associated workspaces within 14 days, whether the deletion was accidental or intentional. The *Cluster* resource name remains reserved during the soft-delete period and you can't create a new cluster with that name.
507507
After the soft-delete period, your *Cluster* resource and data are non-recoverable. Associated workspaces are de-associated from the *Cluster* resource and new data is ingested to shared Storage and encrypted with Microsoft key.
508508

509509
```rst
@@ -533,7 +533,7 @@ possible while the configuration of CMK on your workspace, will also
533533
apply to your Application Insights data.
534534

535535
> [!NOTE]
536-
> If you dont have to deploy CMK for your Application Insight data before the integration, we recommend waiting with Application Insights CMK since such deployments will be disrupted by the integration and you will have to re-configure CMK after the migration to Log Analytics workspace. The 1TB per day minimum applies at the cluster level and until the consolidation completes during second quarter, Application Insights and Log Analytics require separate clusters.
536+
> If you don't have to deploy CMK for your Application Insight data before the integration, we recommend waiting with Application Insights CMK since such deployments will be disrupted by the integration and you will have to re-configure CMK after the migration to Log Analytics workspace. The 1TB per day minimum applies at the cluster level and until the consolidation completes during second quarter, Application Insights and Log Analytics require separate clusters.
537537
538538
## Application Insights CMK configuration
539539

@@ -547,7 +547,7 @@ of the ones listed above.
547547

548548
### Create a *Cluster* resource
549549

550-
This resource is used as intermediate identity connection between your Key Vault and your components. AFTER you received a confirmation that your subscriptions were whitelisted, create a Log Analytics *Cluster* resource at the region where your components are located. The type of the *Cluster* resource is defined at creation time by setting the *clusterType* property to either *LogAnalytics*, or *ApplicationInsights*. It should be *ApplicationInsights* for Application Insights CMK. The *clusterType* setting cant be altered after the configuration.
550+
This resource is used as intermediate identity connection between your Key Vault and your components. AFTER you received a confirmation that your subscriptions were whitelisted, create a Log Analytics *Cluster* resource at the region where your components are located. The type of the *Cluster* resource is defined at creation time by setting the *clusterType* property to either *LogAnalytics*, or *ApplicationInsights*. It should be *ApplicationInsights* for Application Insights CMK. The *clusterType* setting can't be altered after the configuration.
551551

552552
**Create**
553553

Binary file not shown.
-14.3 KB
Loading
-4.99 KB
Loading
-8.73 KB
Loading

0 commit comments

Comments
 (0)