I'm very new to Azure Cloud. I have Windows VM in Azure Cloud and would like to set up remote access logs for Azure VM. There needs to be detailed logging of any access as well as any activities performed on the VM. Where should I configure to get access logs of VM. Can any one please let me know?
Azure
There are few options to collect Windows Event log in Azure:
Azure Log Analytics - For collecting and querying logs inside Log Analytics Collect Windows event log data sources with Log Analytics agent
You will need to install Log Analytics agent on VM
Azure diagnostics extension - For collecting logs in Azure Storage Table (less expensive but much harder for querying) Collect data from Azure diagnostics extension to Azure Monitor Logs
You will need to install Diagnostics Extension to Azure VM agent
Use third party, like DataDog or Splunk (you will need to install their agents on your Azure VM)
Logs
RDP related logs could be found in Windows Event journal in:
Access information represented by following entries in logs:
Network Connection
Authentication
Logon
Session Disconnect/Reconnect
Operational:
Security:
Logoff
Source: Tracking and Analyzing Remote Desktop Activity Logs in Windows
For really detailed activities tracking on Windows you will need at least keylogger solution installed or use solutions like CYBERARC Privileged Session Manager which can record whole RDP session on video.