π Azure Databricks Diagnostic Log Delivery is not configured π’
- Contextual name: π Databricks Diagnostic Log Delivery is not configured π’
- ID:
/ce/ca/azure/databricks/diagnostic-log-delivery
- Located in: π Azure Databricks
Flagsβ
- π’ Impossible policy
- π’ Policy with categories
- π’ Policy with type
Our Metadataβ
- Policy Type:
COMPLIANCE_POLICY
- Policy Category:
RELIABILITY
Descriptionβ
Descriptionβ
Azure Databricks Diagnostic Logging provides insights into system operations, user activities, and security events within a Databricks workspace. Enabling diagnostic logs helps organizations:
- Detect security threats by logging access, job executions, and cluster activities.
- Ensure compliance with industry regulations such as SOC 2, HIPAA, and GDPR.
- Monitor operational performance and troubleshoot issues proactively.
Rationaleβ
Diagnostic logging provides visibility into security and operational activities within Databricks workspaces while maintaining an audit trail for forensic investigations, and it supports compliance with regulatory standards that require logging and monitoring.
Impactβ
Logs consume storage and may require additional monitoring tools, leading to increased operational overhead and costs. Incomplete log configurations may result in missing critical events, reducing monitoring effectiveness.
Auditβ
From Azure Portalβ
Check if diagnostic logging is enabled for the Databricks workspace:
... see more
Remediationβ
Remediationβ
From Azure Portalβ
Enable diagnostic logging for Azure Databricksβ
Navigate to your Azure Databricks workspace.
In the left-hand menu, select
Monitoring
>Diagnostic settings
.Click
+ Add diagnostic setting
.Under
Category details
, select the log categories you wish to capture, such as AuditLogs, Clusters, Notebooks, and Jobs.Choose a destination for the logs:
Log Analytics workspace
: For advanced querying and monitoring.Storage account
: For long-term retention.Event Hub
: For integration with third-party systems.Provide a
Name
for the diagnostic setting.Click
Save
.Implement log retention policiesβ
- Navigate to your Log Analytics workspace.
- Under
General
, selectUsage and estimated costs
.- Click
Data Retention
.- Adjust the retention period slider to the desired number of days (up to 730 days).
- Click
OK
.Monitor logs for anomaliesβ
- Navigate to
Azure Monitor
.- Select
Alerts
>+ New alert rule
.- Under
Scope
, specify the Databricks resource.... see more
policy.yamlβ
Linked Framework Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ CIS Azure v4.0.0 β πΌ 3.1.7 Ensure that diagnostic log delivery is configured for Azure Databricks (Manual) | 1 | |||
πΌ Cloudaware Framework β πΌ System Configuration | 30 |