MR
Mayur Rathi
@sickn33
⭐ 47.3k GitHub stars

azure-monitor-audit

azure-monitor-audit is an code AI skill with a core value of Configure Azure Monitor and Activity Log for auditing. It helps developers solve real-world problems in the code domain, boosting efficiency, automating repetitive tasks, and optimizing workflows.

Configure Azure Monitor and Activity Log for auditing. Set up diagnostic settings and log analytics. Use when auditing Azure activity.

Last verified on: 2026-10-06

Quick Facts

Category code
Works With Claude
Source sickn33/antigravity-awesome-skills
Stars ⭐ 47.3k
Last Verified 2026-10-06
Risk Level Low
mkdir -p ./skills/azure-monitor-audit && curl -sfL https://raw.githubusercontent.com/sickn33/antigravity-awesome-skills/main/skills/azure-monitor-audit/SKILL.md -o ./skills/azure-monitor-audit/SKILL.md

Run in terminal / PowerShell. Requires curl (Unix) or PowerShell 5+ (Windows).

Skill Content

# Azure Monitor Audit


Audit Azure activity with Monitor, Activity Logs, and Log Analytics for compliance, security, and operational visibility.


When to Use


- Enabling centralized audit logging across Azure subscriptions

- Meeting compliance requirements for SOC 2, HIPAA, PCI DSS, or ISO 27001

- Investigating security incidents or unauthorized activity in Azure

- Setting up alerting on administrative and security events

- Building compliance dashboards and automated evidence collection


Create Log Analytics Workspace


bash
# Create resource group for audit resources
az group create \
  --name rg-audit \
  --location eastus

# Create Log Analytics workspace
az monitor log-analytics workspace create \
  --resource-group rg-audit \
  --workspace-name audit-workspace \
  --location eastus \
  --retention-time 365 \
  --sku PerGB2018

# Get workspace ID for later use
WORKSPACE_ID=$(az monitor log-analytics workspace show \
  --resource-group rg-audit \
  --workspace-name audit-workspace \
  --query id -o tsv)

# Enable audit solutions
az monitor log-analytics solution create \
  --resource-group rg-audit \
  --solution-type SecurityCenterFree \
  --workspace audit-workspace

Configure Diagnostic Settings for Subscription Activity Log


bash
# Export subscription activity log to Log Analytics
az monitor diagnostic-settings subscription create \
  --name activity-log-to-workspace \
  --location global \
  --workspace "$WORKSPACE_ID" \
  --logs '[
    {"category": "Administrative", "enabled": true},
    {"category": "Security", "enabled": true},
    {"category": "ServiceHealth", "enabled": true},
    {"category": "Alert", "enabled": true},
    {"category": "Recommendation", "enabled": true},
    {"category": "Policy", "enabled": true},
    {"category": "Autoscale", "enabled": true},
    {"category": "ResourceHealth", "enabled": true}
  ]'

# Also archive to storage account for long-term retention
az storage account create \
  --name auditlogsarchive \
  --resource-group rg-audit \
  --location eastus \
  --sku Standard_GRS \
  --kind StorageV2 \
  --min-tls-version TLS1_2 \
  --allow-blob-public-access false

az monitor diagnostic-settings subscription create \
  --name activity-log-to-storage \
  --location global \
  --storage-account /subscriptions/{sub}/resourceGroups/rg-audit/providers/Microsoft.Storage/storageAccounts/auditlogsarchive \
  --logs '[
    {"category": "Administrative", "enabled": true, "retentionPolicy": {"enabled": true, "days": 2555}},
    {"category": "Security", "enabled": true, "retentionPolicy": {"enabled": true, "days": 2555}}
  ]'

Resource-Level Diagnostic Settings


bash
# Enable diagnostics for Azure Key Vault
az monitor diagnostic-settings create \
  --name keyvault-audit \
  --resource /subscriptions/{sub}/resourceGroups/{rg}/providers/Microsoft.KeyVault/vaults/{vault} \
  --workspace "$WORKSPACE_ID" \
  --logs '[
    {"category": "AuditEvent", "enabled": true, "retentionPolicy": {"enabled": true, "days": 365}},
    {"category": "AzurePolicyEvaluationDetails", "enabled": true}
  ]' \
  --metrics '[
    {"category": "AllMetrics", "enabled": true}
  ]'

# Enable diagnostics for Azure SQL Database
az monitor diagnostic-settings create \
  --name sql-audit \
  --resource /subscriptions/{sub}/resourceGroups/{rg}/providers/Microsoft.Sql/servers/{server}/databases/{db} \
  --workspace "$WORKSPACE_ID" \
  --logs '[
    {"category": "SQLSecurityAuditEvents", "enabled": true},
    {"category": "SQLInsights", "enabled": true},
    {"category": "AutomaticTuning", "enabled": true}
  ]'

# Enable diagnostics for Azure App Service
az monitor diagnostic-settings create \
  --name appservice-audit \
  --resource /subscriptions/{sub}/resourceGroups/{rg}/providers/Microsoft.Web/sites/{app} \
  --workspace "$WORKSPACE_ID" \
  --logs '[
    {"category": "AppServiceHTTPLogs", "enabled": true},
    {"category": "AppServiceAuditLogs", "enabled": true},
    {"category": "AppServiceIPSecAuditLogs", 

🎯 Best For

  • Claude users
  • Software engineers
  • Development teams
  • Tech leads

💡 Use Cases

  • Code quality improvement
  • Best practice enforcement

📖 How to Use This Skill

  1. 1

    Install the Skill

    Copy the install command from the Terminal tab and run it. The SKILL.md file downloads to your local skills directory.

  2. 2

    Load into Your AI Assistant

    Open Claude and reference the skill. Paste the SKILL.md content or use the system prompt tab.

  3. 3

    Apply azure-monitor-audit to Your Work

    Open your project in the AI assistant and ask it to apply the skill. Start with a small module to verify the output quality.

  4. 4

    Review and Refine

    Review AI suggestions before committing. Run tests, check for regressions, and iterate on the skill output.

❓ Frequently Asked Questions

Is azure-monitor-audit compatible with Cursor and VS Code?

Yes — this skill works with any AI coding assistant including Cursor, VS Code with Copilot, and JetBrains IDEs.

Do I need specific dependencies for azure-monitor-audit?

Check the install command and Works With section. Most code skills only require the AI assistant and your codebase.

How do I install azure-monitor-audit?

Copy the install command from the Terminal tab and run it. The skill downloads to ./skills/azure-monitor-audit/SKILL.md, ready to use.

Can I customize this skill for my team?

Absolutely. Edit the SKILL.md file to add team-specific instructions, examples, or workflows.

⚠️ Common Mistakes to Avoid

Skipping validation

Always test AI-generated code changes, even for simple refactors.

Missing dependency updates

Check if the skill requires updated dependencies or new packages.

🔗 Related Skills