Azure Monitor
Azure Monitor is Azure's platform for collecting logs and metrics and alerting on them. The Azure Enterprise Baseline uses it to send every subscription's Activity Log and every resource's logs to central workspaces, and routes every security alert of the platform to a single action group.
What it does
Azure Monitor collects three kinds of data: the Activity Log of each subscription (every control-plane operation), resource logs and metrics of each resource. A diagnostic setting on a subscription, a resource or the tenant's Microsoft Entra ID sends chosen log categories to a Log Analytics workspace, a storage account or both. Alert rules watch that data: activity log alerts match an operation in the Activity Log, scheduled query rules run a KQL (Kusto Query Language) query on a workspace, and metric alerts compare a metric with a threshold. Each rule notifies an action group, which holds the receivers. A data collection rule tells the Azure Monitor agent what to collect from a cluster or a machine.
How BuiltForProd uses it
Diagnostic settings.
| Source | Categories | Destination | Set by |
|---|---|---|---|
| Activity Log of every subscription | Administrative, Security, ServiceHealth, Alert, Recommendation, Policy, Autoscale, ResourceHealth | The audit workspace and the immutable audit storage | subscription-baseline |
| Microsoft Entra ID | Audit, sign-in (interactive, non-interactive, service principal, managed identity), provisioning; risk logs with P2 | The audit workspace and the audit storage | entra-diagnostics, enable_entra_log_export |
| Baseline resources | Firewall rules and DNS, NSG events, VPN gateway, Key Vault audit events, registry and blob access | The audit workspace | each module |
| Blueprint resources | Cosmos DB for MongoDB vCore, application vault, data lake, Databricks, trigger job | The stage application workspace | each module |
A DeployIfNotExists policy assignment at mg-acme is the backstop: any subscription that lacks the Activity Log setting gets it deployed.
One alert route. The action group ag-acme-security-alerts in acme-core-security (observability-sink) emails the address in security_alert_email of security.hcl, with the common alert schema. Every security alert routes there:
- 10 activity log alerts per subscription (
activity-alerts,enable_cis_alerts, free): the CIS Microsoft Azure Foundations Benchmark v3.0.0 section 6.2 alerts on create or update and delete of policy assignments, network security groups, security solutions, SQL server firewall rules and public IP addresses. - 6 scheduled query rules on the audit workspace (
cis-alerts), every five minutes: tenant-root elevate access, role assignment changes at management-group or subscription scope, 10 or more failed sign-ins for one user, any break-glass sign-in, Conditional Access policy changes, and a Key Vault purge or access change. - The Defender rule on the security workspace, every five minutes, for Microsoft Defender for Cloud alerts of High or Critical severity.
The query rules are described on the Log Analytics page.
In the Web App Blueprint. The AKS cluster's Container Insights add-on collects through a data collection rule, MSCI-eastus2-<prefix>-aks, into the stage application workspace every minute with ContainerLogV2. Managed Prometheus is an option (enable_managed_prometheus, about $0.16 per million samples, as the unit comment states). Where the availability test is on, a metric alert on Application Insights fires when API availability falls below 99% over 15 minutes, and also notifies the platform action group, which the contract publishes as platform--action-group-id.
Terms you will see
| Term | Meaning |
|---|---|
| Diagnostic setting | The export of a source's logs and metrics to a workspace or storage account. |
| Activity Log | Every control-plane operation in a subscription. |
| Action group | The receivers an alert notifies: ag-acme-security-alerts. |
| Activity log alert | A rule that fires on one Activity Log operation. |
| Scheduled query rule | A rule that runs a KQL query on a workspace on a schedule. |
| Data collection rule | What the Azure Monitor agent collects and where it sends it. |
Where to read more
- Azure Enterprise Baseline overview and Azure Web App Blueprint overview.
- Log Analytics for the workspaces the settings feed.
- Observable for what the platform watches and why.