5.1.7 Ensure that logging for Azure AppService 'AppServiceHTTPLogs' is enabled.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Enable AppServiceHTTPLogs diagnostic log category for Azure App Service instances to ensure all http requests are captured and centrally logged.

Rationale:

Capturing web requests can be important supporting information for security analysts performing monitoring and incident response activities. Once logging, these logs can be ingested into SIEM or other central aggregation point for the organization.

Impact:

Log consumption and processing will incur additional cost.

Solution

From Azure Portal

Go to App Services

For each App Service:

Go to Diagnostic Settings

Click Add Diagnostic Setting

Check the checkbox next to 'AppServiceHTTPLogs'

Configure destination based on your specific logging consumption capability (for example Stream to an event hub and then consuming with SIEM integration for Event Hub logging).

Default Value:

Not configured.

See Also

https://workbench.cisecurity.org/files/4052