-
Notifications
You must be signed in to change notification settings - Fork 987
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Remediation not working for policy Deploys NSG flow logs and traffic analytics to a storageaccountid with a specfied retention period. #990
Comments
Thanks @neok-g for the issue. Can you confirm the definition ID of the policy as we have 2 with the same description:
Thanks Jack |
Hi @jtracey93 Thanks for your response. The policy definition ID of the policy we use is: Thanks |
Any update on this one? |
@jtracey93 Do you need more input from my side? Are you able to reproduce this one? |
Hi @neok-g, I think we are all good, just some time to investigate amongst some other items that we are working on. Hopefully will get a chance to look this week 👍 |
@neok-g, are you able to test this version of the policy please and let us know if it works? https://www.azadvertizer.net/azpolicyadvertizer/Deploy-Nsg-FlowLogs-to-LA.html |
@jtracey93 Thanks! I will take a look at it today |
Perfect @neok-g let us know how it goes |
@jtracey93 I guess you shared the wrong one. We use the "Deploys NSG flow logs and traffic analytics" instead of "Deploys NSG flow logs and traffic analytics to Log Analytics" since we want provide our own storageaccount. |
Apologies @neok-g, was not aware that was your requirement. Out of interest, I saw this built-in is now available https://www.azadvertizer.net/azpolicyadvertizer/5e1cd26a-5090-4fdb-9d6a-84a90335e22d.html And it looks to be a pretty close match to what our custom policy does apart from its assigned to a region, but you can assign multiple times. Just wondering if you could give this a go whilst i find some time to test our one to see if i can replicate your bug? |
@jtracey93 No problem. The thing is we would like to specify retention period in combination with a self-chosen storage account. The only policy that seems to offer both is "Deploys NSG flow logs and traffic analytics". The built-in "Configure network security groups to use specific workspace for traffic analytics" has retention hardcoded 0 days and disabled. |
Any update on this one? |
Could you please provide an update on this one? |
Trigger ADO Sync 1 |
Trigger ADO Sync 2 |
@neok-g been a long time since we've provided updates, apologies. Please note, we have deprecated the ALZ custom policies for "Deploy NSG flow logs *" and they have been superseded by the built-in policy https://www.azadvertizer.net/azpolicyadvertizer/e920df7f-9a64-4066-9b58-52684c02a091.html. |
Describe the bug Remediation for the policy 'Deploys NSG flow logs and traffic analytics to a storageaccountid with a specfied retention period.' does not work. The error is: Reason No policy evaluation result was found. The policy assignment's exclusions may have changed or it no longer exists. Please retry the remediation with 'ResourceDiscoveryMode' set to 'ReEvaluateCompliance'.
Steps to reproduce
Screenshots
The text was updated successfully, but these errors were encountered: