AZURE HEROES
  • Home-Updates
  • Blog
    • Azure Blog
    • Azure Heroes Events >
      • Azure Heroes Sessions #1
      • Azure Heroes Sessions #2
      • Azure Heroes Sessions #3
      • Azure Heroes Sessions #4
      • Azure Heroes Sessions #5
      • Azure Heroes Sessions #6
      • Azure Heroes Sessions #7
  • Who We Are!
  • eBooks
  • Azure All In One!
    • Azure Disk & Storage
    • Azure Network
    • Azure VPN
    • Azure VMs
  • Free Azure Support!
  • Contact Us
  • Events
    • Beginners Event
    • Developers Event
    • Special Event
    • Azure Workshop #4
    • Azure Workshop #5
    • Azure Workshop #6
    • Azure Workshop #7
    • Azure Workshop #8
    • Azure Heroes Sessions #9
    • Azure Heroes Sessions #10
    • Azure Heroes Sessions #11
    • Azure Heroes Sessions #12
    • Azure Heroes Sessions #13
    • Azure Heroes Sessions #14
    • Azure Heroes Sessions #15
    • Azure Heroes Sessions #16
    • Azure Heroes Sessions #17
    • Azure Heroes Sessions #18
  • Registration Form
  • Privacy Policy
  • Home-Updates
  • Blog
    • Azure Blog
    • Azure Heroes Events >
      • Azure Heroes Sessions #1
      • Azure Heroes Sessions #2
      • Azure Heroes Sessions #3
      • Azure Heroes Sessions #4
      • Azure Heroes Sessions #5
      • Azure Heroes Sessions #6
      • Azure Heroes Sessions #7
  • Who We Are!
  • eBooks
  • Azure All In One!
    • Azure Disk & Storage
    • Azure Network
    • Azure VPN
    • Azure VMs
  • Free Azure Support!
  • Contact Us
  • Events
    • Beginners Event
    • Developers Event
    • Special Event
    • Azure Workshop #4
    • Azure Workshop #5
    • Azure Workshop #6
    • Azure Workshop #7
    • Azure Workshop #8
    • Azure Heroes Sessions #9
    • Azure Heroes Sessions #10
    • Azure Heroes Sessions #11
    • Azure Heroes Sessions #12
    • Azure Heroes Sessions #13
    • Azure Heroes Sessions #14
    • Azure Heroes Sessions #15
    • Azure Heroes Sessions #16
    • Azure Heroes Sessions #17
    • Azure Heroes Sessions #18
  • Registration Form
  • Privacy Policy

Understanding Log Tiers and Best Practices

8/21/2023

0 Comments

 
One of the most common questions I encounter is, "Where do the Azure logs go?" Surprisingly, the responses vary from "I have no clue" to "I think we get some of the alerts in the SIEM." This ambiguity highlights a crucial gap in many organizations' understanding of their Azure environment's logging infrastructure
Picture
Effective log collection is the cornerstone of robust cloud security and compliance practices. Without clear visibility into your Azure logs and a well-defined strategy for collecting and analyzing them, you could be leaving your organization vulnerable to threats and compliance violations.
To address this challenge, it's essential to establish clear log collection tiers and standards across your Azure tenant. These tiers define the types of logs to collect, their significance, and the level of detail required for each.


Tier
Background
Logs Included
Tier 1
Bare minimum for essential Production workloads
- Common Logs for Windows Servers
- Syslog Logs (non-debug) for Linux Servers
- AKS Diagnostic Logs T1 (kube-audit-admin & guard)
- Key Vault Audit Logs
- Azure Activity Logs
- Entra ID Signin Logs (all including Graph)
- Bastion Audit Logs
- Recovery Vault Audit Logs
- Automation Audit Logs
- Container Registry Audit Logs
Tier 2
Often reached via incident retrospectives
- NSG Flow Logs
- NetworkSecurityGroupEvent Logs
- DeviceProcessEvents/DeviceNetworkEvents Logs
- App Gateway/FrontDoor Logs - Firewall Logs
- VM Insights Logs
- AKS Container Insights Logs
Tier 3
Granular detail not often feasible in commercial enterprise settings
- AKS Diagnostic Logs T3
- Container App Logs
- Database Logs (SQL, CosmosDB, etc)
- App Service/Function Logs - Firewall Logs T3
- Application Insights Logs
- AKS Syslog Logs
- API Gateway Logs
- Storage Logs
I would highly recommend creating useful analytics queries and hunting rules that actually use your logs so your SOC can alert. And lastly I think threat modeling on custom apps and ingesting those logs is equally important to ingest as tier 2. The latter requires some more effort and understanding of the actual apps though
0 Comments



Leave a Reply.

    Author

    Mohammad Al Rousan is a Microsoft MVP (Azure), Microsoft Certified Solution Expert (MCSE) in Cloud Platform & Azure DevOps & Infrastructure, An active community blogger and speaker. Al Rousan has over 11 years of professional experience in IT Infrastructure and very passionate about Microsoft technologies and products.

    Picture
    Picture
    Top 10 Microsoft Azure Blogs

    Archives

    January 2025
    December 2024
    November 2024
    October 2024
    September 2024
    July 2024
    June 2024
    May 2024
    April 2024
    February 2024
    September 2023
    August 2023
    May 2023
    November 2022
    October 2022
    July 2022
    June 2022
    May 2022
    April 2022
    March 2022
    February 2022
    January 2022
    December 2021
    November 2021
    May 2021
    February 2021
    December 2020
    November 2020
    October 2020
    September 2020
    August 2020
    June 2020
    April 2020
    January 2020
    July 2019
    June 2019
    May 2019
    February 2019
    January 2019

    Categories

    All
    AKS
    Azure
    Beginner
    CDN
    DevOps
    End Of Support
    Fundamentals
    Guide
    Hybrid
    License
    Migration
    Network
    Security
    SQL
    Storage
    Virtual Machines
    WAF

    RSS Feed

    Follow
    Free counters!
Powered by Create your own unique website with customizable templates.