Azure / Azure/Azure-Landing-Zones
Issue with the Policy "Enable allLogs category group resource logging for supported resources to Log Analytics"
- Dominant language
- PowerShell
- Stars
- 96
- Forks
- 70
- Avg merge
- 3d 1h
- Merged PRs (30d)
- 7
Description
### Community Note
- Please vote on this issue by adding a 👍 [reaction](https://blog.github.com/2016-03-10-add-reactions-to-pull-requests-issues-and-comments/) to the original issue to help the community and maintainers prioritize this request
- Please do not leave "+1" or "me too" comments, they generate extra noise for issue followers and do not help prioritize the request
- If you are interested in working on this issue or have submitted a pull request, please leave a comment
### Description
While trying to upgrade the CAF to version 6.1.0, we are facing issues with one of the policy changes.
- Old Policy: Deploy-Resource-Diag
- New Policy: Deploy-Diag-Logs
1) **Diagnostic setting not getting removed**
While attempting to implement the new policy assignment, 'Enable allLogs category group resource logging for supported resources to Log Analytics,' we noticed that the removal of the older policy (Deploy Diagnostic Settings to Azure Services), which is being deprecated, didn’t remove the diagnostic setting enforced by the same policy.
2) **The New policy set cannot be assigned due to duplication**
The new policy set cannot be assigned because the diagnostic setting enforced by the previous policy still remains in place.
3) **Various Components settings missing in the New Policy**
Additionally, we identified that the new policies are not enforcing various components that are available in the earlier policy.
example: AKS diagnostic settings
Could someone provide an update on how this needs to be done?
Contributor guide
Research direction
Start by comparing the deprecated Deploy-Resource-Diag policy with the replacement Deploy-Diag-Logs policy, focusing on diagnostic-setting removal, assignment duplication, and AKS coverage. Reproduce the upgrade from CAF 6.1.0 and inspect the resulting Azure policy assignments and diagnostic settings. Done means the old settings are removed, the new policy set assigns without duplication, and the missing supported resources are covered.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- azure
- Domain
- cloud, devops
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100