azure-policy icon indicating copy to clipboard operation
azure-policy copied to clipboard

Log categories "Deploy Diagnostic Settings for Recovery Services Vault to Log Analytics workspace for resource specific categories."

Open neok-g opened this issue 3 years ago • 1 comments

The built-in policy Deploy Diagnostic Settings for Recovery Services Vault to Log Analytics workspace for resource specific categories only checks the logcategories: "CoreAzureBackup", "AddonAzureBackupJobs", "AddonAzureBackupAlerts", "AddonAzureBackupPolicy", "AddonAzureBackupStorage", "AddonAzureBackupProtectedInstance"

However a recovery services vault has the following log categories available: AzureBackupReport CoreAzureBackup AddonAzureBackupJobs AddonAzureBackupAlerts AddonAzureBackupPolicy AddonAzureBackupStorage AddonAzureBackupProtectedInstance AzureSiteRecoveryJobs AzureSiteRecoveryEvents AzureSiteRecoveryReplicatedItems AzureSiteRecoveryReplicationStats AzureSiteRecoveryRecoveryPoints AzureSiteRecoveryReplicationDataUploadRate AzureSiteRecoveryProtectedDiskDataChurn Health

So this conflicts with the builtin policy Audit Diagnostic Settings which checks for all log categories. Please modify the policy "Deploy Diagnostic Settings for Recovery Services Vault to Log Analytics workspace for resource specific categories." so that it inspects all log categories available for recovery services vault.

neok-g avatar Sep 14 '22 18:09 neok-g

See related issue on Enterprise Scale Repo

neok-g avatar Sep 14 '22 18:09 neok-g