turbot/azure_compliance

Query: log_analytics_workspace_block_log_ingestion_and_querying_from_public

Usage

powerpipe query azure_compliance.query.log_analytics_workspace_block_log_ingestion_and_querying_from_public

SQL

select
w.id as resource,
case
when type = 'Microsoft.OperationalInsights/workspaces' and public_network_access_for_ingestion = 'Enabled' and public_network_access_for_query = 'Enabled' then 'ok'
else 'alarm'
end as status,
case
when type = 'Microsoft.OperationalInsights/workspaces' and public_network_access_for_ingestion = 'Enabled' and public_network_access_for_query = 'Enabled' then w.name || ' workspace allows log ingestion and querying from public network.'
else w.name || ' workspace does not allow log ingestion and querying from public network.'
end as reason
, w.resource_group as resource_group
, sub.display_name as subscription
from
azure_log_analytics_workspace as w
left join azure_subscription sub on sub.subscription_id = w.subscription_id;

Controls

The query is being used by the following controls: