last sync: 2023-Jun-19 17:45:01 UTC

Community Policy definition

Deploy Linux Diagnostic Agent to Collect Security Related Events

Name Deploy Linux Diagnostic Agent to Collect Security Related Events
Community-Policy GitHub
Id monitoring_deploy-linux-diagnostic-agent-to-collect-security-related-events
Version n/a
details on versioning
Category undefined
Microsoft docs
Description This Policy will Deploy the Linux Diagnostic Agent and collect the following Logs: Syslog, Auth, AuthPriv; All logs are configured to collect informational detail. Additionaly, to account for VMs provisioned from custom images where the image SKU is blank this Policy is keyed to look for the storageProfile.osDisk.osType property of a VM. This property does not exist at provisioning time, but is populated by the VM agent after provisioining, and so will not trigger an automatic remediation task to be created. You will need to create a remediation task manually or build automation (using Event Grid and a Logic App as an example) to create the remediation tasks on your behalf.
Mode Indexed
Type Custom Community
Effect Fixed
deployIfNotExists
Used RBAC Role
Role Name Role Id
Log Analytics Contributor 92aaf0da-9dab-42b6-94a3-d43ce8d16293
Storage Account Contributor 17d1049b-9a84-46fb-8f53-869881c3d3ab
Rule Aliases IF (1)
Alias Namespace ResourceType DefaultPath Modifiable
Microsoft.Compute/virtualMachines/storageProfile.osDisk.osType Microsoft.Compute virtualMachines properties.storageProfile.osDisk.osType true
THEN-ExistenceCondition (3)
Alias Namespace ResourceType DefaultPath Modifiable
Microsoft.Compute/virtualMachines/extensions/provisioningState Microsoft.Compute virtualMachines/extensions properties.provisioningState false
Microsoft.Compute/virtualMachines/extensions/publisher Microsoft.Compute virtualMachines/extensions properties.publisher false
Microsoft.Compute/virtualMachines/extensions/type Microsoft.Compute virtualMachines/extensions properties.type false
Rule ResourceTypes IF (1)
Microsoft.Compute/virtualMachines
THEN-Deployment (1)
Microsoft.Compute/virtualMachines/extensions
JSON