|
One of the most common questions I encounter is, "Where do the Azure logs go?" Surprisingly, the responses vary from "I have no clue" to "I think we get some of the alerts in the SIEM." This ambiguity highlights a crucial gap in many organizations' understanding of their Azure environment's logging infrastructure Effective log collection is the cornerstone of robust cloud security and compliance practices. Without clear visibility into your Azure logs and a well-defined strategy for collecting and analyzing them, you could be leaving your organization vulnerable to threats and compliance violations. To address this challenge, it's essential to establish clear log collection tiers and standards across your Azure tenant. These tiers define the types of logs to collect, their significance, and the level of detail required for each.
I would highly recommend creating useful analytics queries and hunting rules that actually use your logs so your SOC can alert. And lastly I think threat modeling on custom apps and ingesting those logs is equally important to ingest as tier 2. The latter requires some more effort and understanding of the actual apps though
0 Comments
Leave a Reply. |
Author
Mohammad Al Rousan is a Microsoft Most Valuable Professional (MVP) in Azure, a cloud architect, and a recognized leader in enterprise AI and data platforms. With over a decade of hands-on experience, he specializes in designing and scaling secure, production-grade solutions across Azure AI, Databricks, and modern cloud-native architectures. Top 10 Microsoft Azure Blogs
Archives
April 2026
Categories
All
|
RSS Feed