Incident Report 071021 - Infrastructure Analysis
METHODOLOGY
The approach and methodology for the line of action were defined by our Tier-3 team to collect usable information required for analysis of the issues reported, in order to provide resolution, thus maintaining a safer and more controlled operation scheme and publishing a report.
ANALYSIS RESULTS
Below is the complete analysis and results.
SUMMARY OF REPORT
Azure Monitor Agent VM extension stopped working when we re-provisioned app and encoder VMs during the deployment of a software upgrade.
Azure Monitor Logs provides monitoring capabilities across cloud and on-premises assets. The Log Analytics agent virtual machine extension for Windows is published and supported by Microsoft. The extension installs the Log Analytics agent on Azure virtual machines, and enrolls virtual machines into an existing Log Analytics workspace.
FINDINGS
The below resources fall into the scope of impact and can be affected due to security vulnerabilities.
- Production nodes in US region.
- Production nodes in US Gov region.
- Production nodes in Japan region.
- Recommended actions may affect user productivity and temporary downtime (system reboot) will be required for new changes to take effect.
- New VM Scale Sets need to be set up in order to resolve VM monitoring issues.
TOOLS
For the execution of this project, the most up-to-date versions of the following tools and components associated with them were used:
LINE OF ACTION AND ASSOCIATED TIMELINES
The following table outlines actions performed and their schedule to remediate security issues and vulnerabilities.
REMEDIATION PROCEDURE
Below is the detail about actions performed to remove security vulnerabilities.