Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
This article addresses a scenario where log forwarding continues unexpectedly after an Azure Native Integrations service is disabled. It explains the underlying cause and provides steps to resolve the issue by managing resource locks in Azure.
Tip
If the delete lock is removed after the service has already been deleted, the diagnostic settings must be manually cleaned up to stop log forwarding.
Symptoms
Logs continue to be emitted and diagnostic settings remain active on monitored resources, even after the service is disabled or tag rules are modified to exclude certain resources.
Cause
A delete lock is applied to the resource or the resource group containing the resource. This lock prevents the cleanup of diagnostic settings, which causes logs to continue being forwarded.
Solution
To remove the delete lock from the affected resource or resource group:
- Go to Azure Portal and sign in using your Azure credentials.
- Use the Search bar at the top of the portal to locate the specific resource or resource group.
- Select the resource name to open its Overview page.
- In the left-hand menu, under the Settings section, select Locks.
- You’ll see a list of any management locks applied to the resource.
- Look for a lock with Lock type: Delete (often labeled as
CanNotDelete). - Select the ellipsis (⋯) next to the lock entry.
- Choose Delete from the dropdown menu.
- Confirm the deletion when prompted.
Related content
Lock resources using the Azure portal Configure locks - Azure portal