Chapter 7

Enabling Network Security log collection

Azure provides various levels of logging and auditing from Azure Activity Logs to resource logs. Activity logs provide operational logs of each resource (which is also known as the data plane) and can be exported to various destinations. Resource logs are also known as diagnostic logs. The three destinations are Azure Monitor Log Analytics for cloud monitoring and analysis, Azure Event Hubs for forwarding outside of Azure, and Azure storage for archiving. Organizations can configure one or more destinations—for example, if they are requirements for long-term archiving (storage) and active monitoring (Log Analytics). A diagnostic setting is created to configure resource logs.

It is important ...

Get Microsoft Azure Network Security now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.