Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Azure Activity Logs record all control plane operations performed on Microsoft Discovery resources through the Azure Resource Manager (ARM) API. These logs let you audit who made changes, what was changed, and when—covering operations such as creating a workspace, updating a supercomputer, or deleting a bookshelf.
Activity logs are available in Azure Monitor and are separate from the application logs that Discovery stores in MRG-based Log Analytics workspaces. For information on application logs, see Observability in Microsoft Discovery.
Prerequisites
- An Azure account with access to the subscription containing your Microsoft Discovery resources.
- Reader role (or higher) on the subscription or resource group.
What activity logs capture
Activity logs record control plane write and delete operations on Discovery resources. Examples include:
| Operation | Description |
|---|---|
Microsoft.Discovery/workspaces/write |
Create or update a workspace |
Microsoft.Discovery/workspaces/delete |
Delete a workspace |
Microsoft.Discovery/supercomputers/write |
Create or update a supercomputer |
Microsoft.Discovery/supercomputers/delete |
Delete a supercomputer |
Microsoft.Discovery/bookshelves/write |
Create or update a bookshelf |
Microsoft.Discovery/bookshelves/delete |
Delete a bookshelf |
Microsoft.Discovery/tools/write |
Create or update a tool |
Microsoft.Discovery/tools/delete |
Delete a tool |
Microsoft.Discovery/storagecontainers/write |
Create or update a storage container |
Microsoft.Discovery/storagecontainers/delete |
Delete a storage container |
Microsoft.Discovery/storageassets/write |
Create or update a storage asset |
Microsoft.Discovery/storageassets/delete |
Delete a storage asset |
Activity logs also capture:
- The identity (user or service principal) that performed the operation.
- The result of the operation:
Succeeded,Failed, orAccepted. - The timestamp and correlation ID for the operation.
- The request and response details for the ARM API call.
Note
Activity logs don't capture read operations (HTTP GET requests). They record write and delete operations only.
View activity logs in the Azure portal
View logs for a specific resource
- In the Azure portal, navigate to the Microsoft Discovery resource you want to audit (workspace, supercomputer, or bookshelf).
- In the resource's left navigation pane, select Activity log.
- The activity log displays all control plane operations for that resource.
View logs for a resource group
- In the Azure portal, navigate to the resource group that contains your Discovery resources.
- In the resource group's left navigation pane, select Activity log.
- Use the Resource type filter to narrow results to Discovery resource types.
View logs from Azure Monitor
- In the Azure portal, search for Monitor and select Azure Monitor.
- In the left navigation pane, select Activity log.
- Use the filters described in the following section to scope results to your Discovery resources.
Filter activity logs
Use the following filters to narrow activity log results:
| Filter | Description |
|---|---|
| Subscription | Scope logs to the subscription containing your Discovery resources |
| Resource group | Scope logs to the resource group containing your Discovery resources |
| Resource type | Filter to Microsoft.Discovery/workspaces, Microsoft.Discovery/supercomputers, Microsoft.Discovery/bookshelves, Microsoft.Discovery/tools, Microsoft.Discovery/storagecontainers, or Microsoft.Discovery/storageassets |
| Time range | Set the time window for the query (default: last 6 hours, maximum: 90 days) |
| Event severity | Filter by Critical, Error, Warning, or Informational |
| Event initiated by | Filter by user, service principal, or application identity |
Export activity logs for long-term retention
Activity logs are retained for 90 days by default. To retain logs beyond 90 days or to query them with KQL, export them to a Log Analytics workspace or a storage account via diagnostic settings.
Export to a Log Analytics workspace
- In Azure Monitor, go to Activity log and select Export Activity Logs.
- Select Add diagnostic setting.
- Under Destination details, select Send to Log Analytics workspace and choose your Log Analytics workspace.
- Under Categories, select the log categories you want to export (for example, Administrative for control plane operations).
- Select Save.
After export is configured, activity logs appear in the AzureActivity table in the Log Analytics workspace. You can then query them with KQL:
AzureActivity
| where ResourceProviderValue == "MICROSOFT.DISCOVERY"
| where ActivityStatusValue == "Failure"
| order by TimeGenerated desc
Filter to a specific resource type
AzureActivity
| where ResourceProviderValue == "MICROSOFT.DISCOVERY"
| where ResourceGroup == "<your-resource-group>"
| order by TimeGenerated desc
Find failed operations
AzureActivity
| where ResourceProviderValue == "MICROSOFT.DISCOVERY"
| where ActivityStatusValue == "Failure"
| project TimeGenerated, OperationNameValue, Caller, ActivityStatusValue, Properties
| order by TimeGenerated desc
Audit changes by user
AzureActivity
| where ResourceProviderValue == "MICROSOFT.DISCOVERY"
| where Caller == "<user-email-or-service-principal>"
| project TimeGenerated, OperationNameValue, ResourceGroup, ActivityStatusValue
| order by TimeGenerated desc
Troubleshooting
No activity log entries visible
| Cause | Resolution |
|---|---|
| Time range doesn't cover the operation | Extend the time range; activity logs support up to 90 days |
| Filtering by resource group that doesn't contain the resource | Verify the resource group and remove or update the filter |
| Operation was a read operation (HTTP GET) | Activity logs only capture write and delete operations |
Operations show as Failed
Review the Properties column of the failed entry in the Azure portal or use the following KQL query to surface error details:
AzureActivity
| where ResourceProviderValue == "MICROSOFT.DISCOVERY"
| where ActivityStatusValue == "Failure"
| extend ErrorCode = tostring(parse_json(Properties).statusCode)
| extend ErrorMessage = tostring(parse_json(Properties).statusMessage)
| project TimeGenerated, OperationNameValue, Caller, ErrorCode, ErrorMessage
| order by TimeGenerated desc