Azure / Azure/Azure-Landing-Zones

Enable allLogs category group resource logging - missing policies

Open
#459 8 comments 3 reactions 0 assignees View on GitHub
Transfer From: caf-enterprise-scale :arrow_right:
Dominant language
PowerShell
Stars
96
Forks
70
Avg merge
3d 1h
Merged PRs (30d)
7

Description

### Community Note

- Please vote on this issue by adding a 👍 [reaction](https://blog.github.com/2016-03-10-add-reactions-to-pull-requests-issues-and-comments/) to the original issue to help the community and maintainers prioritize this request
- Please do not leave "+1" or "me too" comments, they generate extra noise for issue followers and do not help prioritize the request
- If you are interested in working on this issue or have submitted a pull request, please leave a comment

### Versions

Azure/caf-enterprise-scale/azurerm version 6.2.0

➜ git:(main) terraform version
Terraform v1.10.2
on darwin_arm64
+ provider registry.terraform.io/azure/azapi v1.15.0
+ provider registry.terraform.io/hashicorp/azurerm v3.117.0
+ provider registry.terraform.io/hashicorp/random v3.6.3
+ provider registry.terraform.io/hashicorp/time v0.12.1

### Description

#### Describe the bug

In the initiative assignment "Enable category group resource logging for supported resources to Log Analytics", only 69 policies are deployed. 71 policies are missing - including key resource types like azure firewall, app gateway, storage accounts etc.

![Image](https://github.com/user-attachments/assets/eb95a700-c51c-4a10-9584-02b64a5005ab)

A colleague of mine has deployed the module separately and also only 69 policies are present compared to the 140 registered on AzAdvisor

https://www.azadvertizer.net/azpolicyinitiativesadvertizer/0884adba-2312-4468-abeb-5422caed1038.html

Contributor guide

Open the contributing guide

Research direction

Start with the initiative assignment “Enable category group resource logging for supported resources to Log Analytics” and compare its deployed policies with the 140 registered in AzAdvertizer. Check why only 69 are present, including Azure Firewall, Application Gateway, and storage accounts; done means the supported resource logging policies are included in the assignment.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure, terraform
Domain
cloud
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.