standard
turbot/azure_compliance

Trigger: Detect & correct MySQL flexible servers with audit log disabled

Detect MySQL flexible servers with audit log disabled and then enable audit log.

Query

select
concat(id, ' [', subscription_id, '/', resource_group, ']') as title,
id as id,
name as server_name,
resource_group,
subscription_id,
_ctx ->> 'connection_name' as conn
from
azure_mysql_flexible_server,
jsonb_array_elements(flexible_server_configurations) as config
where
config ->> 'Name' = 'audit_log_enabled'
and config -> 'ConfigurationProperties' ->> 'value' <> 'ON';

Schedule

15m

Tags

category = Compliance
plugin = azure
service = Azure/MySQL