Granting access to Azure application service log stream

MrFlinstone 481 Reputation points
2022-06-06T22:54:43.3+00:00

Hi All.

I granted a user monitoring reader role but found out that they are still unable to access the application service log stream. Can someone confirm what permissions are required for access to the application service log stream.

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,813 questions
{count} votes

1 answer

Sort by: Most helpful
  1. AnuragSingh-MSFT 20,106 Reputation points
    2022-06-07T08:16:33.607+00:00

    Hi @MrFlinstone

    Thanks for posting the question.

    I see that you are trying to understand the minimum permission required to access the "AppService Log Stream". Please note that the "Monitoring Reader" role provides access to "monitoring" data i.e., the metrics and AppServiceHTTPLogs and AzureMetrics table in Logs. However, the log files can contain sensitive information, such as IP addresses or usernames. In order to avoid unauthorized access to such sensitive information, Contributor or Owner roles are required. You may refer to the following link for more details on it - Security considerations for monitoring data.

    Please let me know if you have any questions.

    ---
    Please 'Accept as answer' and ‘Upvote’ if it helped so that it can help others in the community looking for help on similar topics.

    1 person found this answer helpful.