5.1.1 Ensure that a 'Diagnostics Setting' exists

Information

Enable Diagnostic settings for exporting activity logs. Diagnostic setting are available for each individual resources within a subscription. Settings should be configured for all appropriate resources for your environment.

Rationale:

A diagnostic setting controls how a diagnostic log is exported. By default, logs are retained only for 90 days. Diagnostic settings should be defined so that logs can be exported and stored for a longer duration in order to analyze security activities within an Azure subscription.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

From Azure Console

Click on the resource that has a diagnostic status of disabled

Select Add Diagnostic Settings

Enter a Diagnostic setting name

Select the appropriate log, metric, and destination. (This may be Log Analytics/Storage account or Event Hub)

Click save

Repeat these step for all resources as needed.

Default Value:

By default, diagnostic setting is not set.

See Also

https://workbench.cisecurity.org/files/3459