SecOps Logging - Azure
Our logging structure goals are to remain compliant with standards set by Open Telemetry. This will allow us to use both Azure Monitor and Splunk for collection of logs, traces, and metrics. The final structure for how logs will flow through each application is still being set.
Azure Services we use:
- Azure AI Foundry
- Specifically we use the Azure Open AI Service
- Azure App Service
- Azure Key Vault
Frameworks:
- Microsoft Authentication Library
- M365 Agent Toolkit
| Location | Source | Log | Type | Description | Method | Notes | Integration with Splunk |
|---|---|---|---|---|---|---|---|
| Azure | AI Foundry | Activity | Azure Open AI | Azure Open AI works with Azure Monitor and all associated logs are applicable | Activity Log Schema | ||
| Azure | AI Foundry | Resource | Azure Open AI | Azure Open AI works with Azure Monitor and all associated logs are applicable | Resource Logs Schema | ||
| Azure | AI Foundry | Virtual Machine | Azure Open AI | Azure Open AI works with Azure Monitor and all associated logs are applicable | VM Default Data Collection | ||
| Azure | AI Foundry | Platform Metrics | Azure Open AI | Azure Open AI works with Azure Monitor and all associated logs are applicable | Azure Monitor Metrics | ||
| Azure | App Service | Diagnostic | Application logging | Any messages generated by App | App Service Diagnostics | ||
| Azure | App Service | Diagnostic | Web server logging | Raw HTTP request data coming from App | App Service Diagnostics | ||
| Azure | App Service | Diagnostic | Detailed error messages | Error pages that would have been sent to client (HTTP code > 400) | App Service Diagnostics | ||
| Azure | App Service | Diagnostic | Failed request tracing | Traces from failed HTTP requests | App Service Diagnostics | ||
| Azure | App Service | Diagnostic | Deployment logging | Azure resource logs coming from when App is deployed to a server | App Service Diagnostics | ||
| Azure | App Service | Health | Heartbeat | Response to pings on each instance of App every minute | App Services Health Check | ||
| Azure | Key Vault | - Authentication to Vault - Get - Put - Delete - Patch - Recover - Access Policy Change |
Vault Event | Changes to a Vault in Key Vault | Key Vault - Vault | ||
| Azure | Key Vault | - Create - Get - Import - Delete - Sign - Verify - Wrap - Unwrap - Encrypt - Decrypt - Update - List - List Versions - Purge - Backup - Restore - Recover - Get Deleted - List Deleted - Near Expiry Notification (status) - Expired (status) - Rotate - Rotate If Due (status) - Get Rotation Policy - Set Rotation Policy |
Keys Event | Changes to Keys in Key Vault | Key Vault - Keys | ||
| Azure | Key Vault | - Get - Set - Update - Delete - List - List Versions - Purge - Backup - Restore - Recover - Get Deleted - List Deleted - Near Expiry Notification (status) - Expired (status) |
Secrets Event | Changes to Secrets in Key Vault | Key Vault - Secrets | ||
| Azure | Key Vault | - Get - Create - Import - Update - List - List Versions - Delete - Purge - Backup - Restore - Recover - Get Deleted - List Deleted - Get Policy - Update Policy - Set Policy - Get Contacts - Set Contacts - Delete Contacts - Get Issuer - Set Issuer - Update Issuer - Delete Issuer - List Issuers - Enroll - Renew - Get Pending - Merge Pending (status) - Update Pending (status) - Delete Pending - Near Expiry Notification (status) - Expired (status) |
Certificate Event | Changes to Certificates in Key Vault | Key Vault - Certificates |