Azure / Azure/Azure-Landing-Zones

Issue with the Policy "Enable allLogs category group resource logging for supported resources to Log Analytics"

Open
#458 0 comments 4 reactions 0 assignees View on GitHub
Transfer From: caf-enterprise-scale :arrow_right:
Dominant language
PowerShell
Stars
96
Forks
70
Avg merge
3d 1h
Merged PRs (30d)
7

Description

### Community Note

- Please vote on this issue by adding a 👍 [reaction](https://blog.github.com/2016-03-10-add-reactions-to-pull-requests-issues-and-comments/) to the original issue to help the community and maintainers prioritize this request
- Please do not leave "+1" or "me too" comments, they generate extra noise for issue followers and do not help prioritize the request
- If you are interested in working on this issue or have submitted a pull request, please leave a comment

### Description

While trying to upgrade the CAF to version 6.1.0, we are facing issues with one of the policy changes.

- Old Policy: Deploy-Resource-Diag
- New Policy: Deploy-Diag-Logs

1) **Diagnostic setting not getting removed**
While attempting to implement the new policy assignment, 'Enable allLogs category group resource logging for supported resources to Log Analytics,' we noticed that the removal of the older policy (Deploy Diagnostic Settings to Azure Services), which is being deprecated, didn’t remove the diagnostic setting enforced by the same policy.

2) **The New policy set cannot be assigned due to duplication**
The new policy set cannot be assigned because the diagnostic setting enforced by the previous policy still remains in place.

3) **Various Components settings missing in the New Policy**
Additionally, we identified that the new policies are not enforcing various components that are available in the earlier policy.
example: AKS diagnostic settings
Could someone provide an update on how this needs to be done?

Contributor guide

Open the contributing guide

Research direction

Start by comparing the deprecated Deploy-Resource-Diag policy with the replacement Deploy-Diag-Logs policy, focusing on diagnostic-setting removal, assignment duplication, and AKS coverage. Reproduce the upgrade from CAF 6.1.0 and inspect the resulting Azure policy assignments and diagnostic settings. Done means the old settings are removed, the new policy set assigns without duplication, and the missing supported resources are covered.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure
Domain
cloud, devops
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.