Logs of MS defender for cloud for ACR

KISHNANI Vishal T 0 Reputation points
2025-06-18T07:29:08.8833333+00:00

Hi All,

We're trying to check logs for defender for cloud, specifically for acr image scans. Had a ticket raised to find out and the technical team does not seem to have access too which is very strange. We have thousands of images being scanned every month and no transparency on the number of scans.

Microsoft Security | Microsoft Entra | Other
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Catherine Kyalo 2,090 Reputation points Microsoft Employee
    2025-06-19T10:55:24.7866667+00:00

    Hi KISHNANI Vishal T,

    Review Monitor container registry

    Azure Monitor is used to monitor all instances of the ACR registries. It gathers ACR metrics such as push and pull operations.  

    The Diagnostic Settings on the production ACR instances is configured to stream the resource logs of category ContainerRegistryLoginEvents  and ContainerRegistryRepositoryEventsLogs - Supported resource logs for Microsoft.ContainerRegistry/registries

    Based on this Registry operations by Microsoft Defender for Cloud, If resource logs are collected for your registry, you'll see registry login events and image pull events generated by Microsoft Defender for Cloud.

    Table reference https://learn.microsoft.com/en-us/azure/azure-monitor/reference/tables/containerregistryrepositoryevents for ContainerRegistryRepositoryEvents.

    If you find the answer above helpful, please Accept the answer to help anyone in the community who might have a similar question to quickly find the solution.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.