Skip to main content

πŸ›‘οΈ Azure Diagnostic Setting for Azure AppService HTTP logs is not enabled🟒βšͺ

  • Contextual name: πŸ›‘οΈ Diagnostic Setting for Azure AppService HTTP logs is not enabled🟒βšͺ
  • ID: /ce/ca/azure/monitor/diagnostic-settings-for-appservice-http-logs
  • Tags:
  • Policy Type: COMPLIANCE_POLICY
  • Policy Categories: SECURITY, RELIABILITY

Description​

Open File

Description​

Enable the AppServiceHTTPLogs diagnostic log category for Azure App Service instances to ensure all HTTP requests are captured and centrally logged.

Rationale​

Capturing web requests can be important supporting information for security analysts performing monitoring and incident response activities. Once logging is enabled, these logs can be ingested into a SIEM or another central aggregation point for the organization.

Impact​

Log consumption and processing will incur additional cost.

Audit​

From Azure Portal​
  1. Go to App Services.

    For each App Service:

  2. Under Monitoring, go to Diagnostic Settings.

  3. Ensure a diagnostic setting exists that logs HTTP logs to a destination aligned to your environment's approach to log consumption (event hub, storage account, etc. dependent on what is consuming the logs such as SIEM or other log aggregation utility).

From Azure Policy​

If referencing a digital copy of this Benchmark, clicking a Policy ID will open a link to the associated Policy definition in Azure.

... see more

Remediation​

Open File

Remediation​

From Azure Portal​

  1. Go to App Services.

    For each App Service:

  2. Under Monitoring, go to Diagnostic Settings.

  3. To update an existing diagnostic setting, click Edit setting for that setting. To create a new diagnostic setting, click Add diagnostic setting and provide a name.

  4. Check the checkbox next to HTTP logs.

  5. Configure a destination based on your logging consumption capability, for example, stream to an Event Hub and consume with a SIEM integration.

  6. Click Save.

policy.yaml​

Open File

Linked Framework Sections​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
πŸ’Ό CIS Azure v5.0.0 β†’ πŸ’Ό 6.1.1.6 Ensure that logging for Azure AppService 'HTTP logs' is enabled (Automated)1no data
πŸ’Ό Cloudaware Framework β†’ πŸ’Ό Logging and Monitoring Configuration75no data