Diagnostic log delivery should be configured for Azure Databricks

Description

Ensure diagnostic log delivery is configured for each Azure Databricks workspace. Diagnostic settings forward workspace activity logs (clusters, jobs, notebooks, secrets, and other categories) to a Log Analytics workspace, storage account, or event hub, providing the audit trail needed to investigate security incidents.

This rule passes when a workspace has at least one diagnostic setting with at least one enabled log category.

Remediation

Create a diagnostic setting on the Databricks workspace and enable the relevant log categories. See Configure diagnostic log delivery in Azure Databricks and Create diagnostic settings.