last sync: 2021-Nov-26 17:15:01 UTC

Azure Policy definition

Resource logs in Search services should be enabled

Name Resource logs in Search services should be enabled
Azure Portal
Id b4330a05-a843-4bc8-bf9a-cacce50c67f4
Version 5.0.0
details on versioning
Category Search
Microsoft docs
Description Audit enabling of resource logs. This enables you to recreate activity trails to use for investigation purposes; when a security incident occurs or when your network is compromised
Mode Indexed
Type BuiltIn
Preview FALSE
Deprecated FALSE
Effect Default: AuditIfNotExists
Allowed: (AuditIfNotExists, Disabled)
Used RBAC Role none
History
Date/Time (UTC ymd) (i) Change type Change detail
2021-06-17 14:24:41 change Major (4.0.1 > 5.0.0)
2021-02-10 14:43:58 change Major (3.0.0 > 4.0.1)
Used in Initiatives
Initiative DisplayName Initiative Id Initiative Category State
[Deprecated]: Azure Security Benchmark v1 42a694ed-f65e-42b2-aa9e-8052e9740a92 Regulatory Compliance Deprecated
[Deprecated]: Azure Security Benchmark v2 bb522ac1-bc39-4957-b194-429bcd3bcb0b Regulatory Compliance Deprecated
[Preview]: Motion Picture Association of America (MPAA) 92646f03-e39d-47a9-9e24-58d60ef49af8 Regulatory Compliance Preview
Azure Security Benchmark 1f3afdf9-d0c9-4c3d-847f-89da613e70a8 Security Center GA
CIS Microsoft Azure Foundations Benchmark v1.3.0 612b5213-9160-4969-8578-1518bd2a000c Regulatory Compliance GA
FedRAMP High d5264498-16f4-418a-b659-fa7ef418175f Regulatory Compliance GA
FedRAMP Moderate e95f5a9f-57ad-4d03-bb0b-b1d16db93693 Regulatory Compliance GA
HITRUST/HIPAA a169a624-5599-4385-a696-c8d643089fab Regulatory Compliance GA
New Zealand ISM Restricted d1a462af-7e6d-4901-98ac-61570b4ed22a Regulatory Compliance GA
NIST SP 800-53 Rev. 4 cf25b9c1-bd23-4eb6-bd2c-f4f3ac644a5f Regulatory Compliance GA
NIST SP 800-53 Rev. 5 179d1daa-458f-4e47-8086-2a68d0d6c38f Regulatory Compliance GA
JSON Changes

JSON
{
  "displayName": "Resource logs in Search services should be enabled",
  "policyType": "BuiltIn",
  "mode": "Indexed",
  "description": "Audit enabling of resource logs. This enables you to recreate activity trails to use for investigation purposes; when a security incident occurs or when your network is compromised",
  "metadata": {
    "version": "5.0.0",
    "category": "Search"
  },
  "parameters": {
    "effect": {
      "type": "String",
      "metadata": {
        "displayName": "Effect",
        "description": "Enable or disable the execution of the policy"
      },
      "allowedValues": [
        "AuditIfNotExists",
        "Disabled"
      ],
      "defaultValue": "AuditIfNotExists"
    },
    "requiredRetentionDays": {
      "type": "String",
      "metadata": {
        "displayName": "Required retention (days)",
        "description": "The required resource logs retention in days"
      },
      "defaultValue": "365"
    }
  },
  "policyRule": {
    "if": {
      "field": "type",
      "equals": "Microsoft.Search/searchServices"
    },
    "then": {
      "effect": "[parameters('effect')]",
      "details": {
        "type": "Microsoft.Insights/diagnosticSettings",
        "existenceCondition": {
          "count": {
            "field": "Microsoft.Insights/diagnosticSettings/logs[*]",
            "where": {
              "anyOf": [
                {
                  "allOf": [
                    {
                      "field": "Microsoft.Insights/diagnosticSettings/logs[*].retentionPolicy.enabled",
                      "equals": "true"
                    },
                    {
                      "anyOf": [
                        {
                          "field": "Microsoft.Insights/diagnosticSettings/logs[*].retentionPolicy.days",
                          "equals": "0"
                        },
                        {
                          "value": "[padLeft(current('Microsoft.Insights/diagnosticSettings/logs[*].retentionPolicy.days'), 3, '0')]",
                          "greaterOrEquals": "[padLeft(parameters('requiredRetentionDays'), 3, '0')]"
                        }
                      ]
                    },
                    {
                      "field": "Microsoft.Insights/diagnosticSettings/logs.enabled",
                      "equals": "true"
                    }
                  ]
                },
                {
                  "allOf": [
                    {
                      "field": "Microsoft.Insights/diagnosticSettings/logs.enabled",
                      "equals": "true"
                    },
                    {
                      "anyOf": [
                        {
                          "field": "Microsoft.Insights/diagnosticSettings/logs[*].retentionPolicy.enabled",
                          "notEquals": "true"
                        },
                        {
                          "field": "Microsoft.Insights/diagnosticSettings/storageAccountId",
                          "exists": false
                        }
                      ]
                    }
                  ]
                }
              ]
            }
          },
          "greaterOrEquals": 1
        }
      }
    }
  }
}