π‘οΈ Azure Diagnostic Setting for Azure AppService HTTP logs is not enabledπ’βͺ
- Contextual name: π‘οΈ Diagnostic Setting for Azure AppService HTTP logs is not enabledπ’βͺ
- ID:
/ce/ca/azure/monitor/diagnostic-settings-for-appservice-http-logs - Tags:
- βͺ Impossible policy
- π’ Policy with categories
- π’ Policy with type
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
SECURITY,RELIABILITY
Descriptionβ
Descriptionβ
Enable the AppServiceHTTPLogs diagnostic log category for Azure App Service instances to ensure all HTTP requests are captured and centrally logged.
Rationaleβ
Capturing web requests can be important supporting information for security analysts performing monitoring and incident response activities. Once logging is enabled, these logs can be ingested into a SIEM or another central aggregation point for the organization.
Impactβ
Log consumption and processing will incur additional cost.
Auditβ
From Azure Portalβ
Go to
App Services.For each
App Service:Under
Monitoring, go toDiagnostic Settings.Ensure a diagnostic setting exists that logs
HTTP logsto a destination aligned to your environment's approach to log consumption (event hub, storage account, etc. dependent on what is consuming the logs such as SIEM or other log aggregation utility).From Azure Policyβ
If referencing a digital copy of this Benchmark, clicking a Policy ID will open a link to the associated Policy definition in Azure.
... see more
Remediationβ
Remediationβ
From Azure Portalβ
Go to
App Services.For each App Service:
Under
Monitoring, go toDiagnostic Settings.To update an existing diagnostic setting, click
Edit settingfor that setting. To create a new diagnostic setting, clickAdd diagnostic settingand provide a name.Check the checkbox next to
HTTP logs.Configure a destination based on your logging consumption capability, for example, stream to an Event Hub and consume with a SIEM integration.
Click
Save.
policy.yamlβ
Linked Framework Sectionsβ
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| πΌ CIS Azure v5.0.0 β πΌ 6.1.1.6 Ensure that logging for Azure AppService 'HTTP logs' is enabled (Automated) | 1 | no data | |||
| πΌ Cloudaware Framework β πΌ Logging and Monitoring Configuration | 77 | no data |