Azure / Azure/PSRule.Rules.Azure

Diagnostic logs in Search services should be enabled

Open
#1,866 1 comment 0 reactions 0 assignees View on GitHub
rule: cognitive-search
Dominant language
PowerShell
Stars
447
Forks
109
Avg merge
2d 19h
Merged PRs (30d)
23

Description

# Rule request

## Suggested rule change

Diagnostic logs in Search services should be enabled.

Enable logs and retain them for up to a year. This enables you to recreate activity trails for investigation purposes when a security incident occurs or your network is compromised.

This is actually an official Defender for Cloud recommendation.

Security pillar for this one.

## Applies to the following

The rule applies to the following:

- Resource type: **[Microsoft.Search/searchServices]**

## Additional context

[Diagnostic logs in Search services should be enabled](https://portal.azure.com/#blade/Microsoft_Azure_Policy/PolicyDetailBlade/definitionId/%2fproviders%2fMicrosoft.Authorization%2fpolicyDefinitions%2fb4330a05-a843-4bc8-bf9a-cacce50c67f4)
[Template reference](https://learn.microsoft.com/en-us/azure/templates/microsoft.logic/workflows)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.