Azure workbook question
hi, I've created a KQL query to basically provide means to audit group membership changes. Exported to a csv the name of each security group and its managedBy attributes and using it inside the query as external data. Then joining with SecurityEvent…
![](https://techprofile.blob.core.windows.net/images/U1Jln6XVxUOXS5Rme1kflg.png?8DC69F)
Sending Diagnostic Settings to the same workspace
I have a Log Analytics workspace that I send all of diagnostic settings to for auditing purposes. The Log Analytics workspace itself has its own set of Diagnostic Settings. I am trying to keep a single workspace for the time being. Is there any issues…
Azure Monitor Workbook and Azure AD objects ?
Hello, I was looking for a way to query Azure AD objects (first use case are service principals) from an Azure Monitor Workbook (essentially the goal would be to have a dashboard to check for near expiring secrets and cross the information with Azure…
![](https://techprofile.blob.core.windows.net/images/-TF2gf5_AwAAAAAAAAAAAA.png?8D8568)
Show licenses overview on Azure Workbooks
Hi, I would like to add the following Graph query: https://graph.microsoft.com/v1.0/subscribedSkus?$select=skuPartNumber,consumedUnits,prepaidUnits on an Azure Workbooks. Is there a way to show missing licenses on a Azure Workbooks. Thanks
![](https://techprofile.blob.core.windows.net/images/a8bh8pTwoEKoPKgpm7J9oA.png?8D99FA)
![](https://techprofile.blob.core.windows.net/images/-TF2gf5_AwAAAAAAAAAAAA.png?8D8568)
Azure Policy for enabling diagnostic settings for WebApp/Function App - No resources remediated
I am working in an existing Azure environment where there is no governance and I am in the process of creating Azure Policies. Currently I am working on creating Azure Policy to enable Diagnostic settings for Azure Web App, Azure Function App and Web…
![](https://techprofile.blob.core.windows.net/images/ny8DxPvPMky3dIOsQ9_3Dg.png?8DC7C0)
Log Search Alert Rule fired when i created it manually on Portal but when i created it by Terraform with the same configuration it not fired
When I create a Log search Alert Rule manually on Azure Portal. It fired alerts perfectly when the condition is met. But when I created a Log search Alert Rule with the same configuration in Terraform. It did not fired alerts when the condition is met I…
Error Code:STATUS_ACCESS_VIOLATION when searching alert rules in Azure Portal in EDGE
Hi, Since KB5039212 was installed I am unable to search within Azure for alert rules where the customer has a sizable number of alerts (e.g. where AMBA has been deployed) If I search within the search bar it errors out with…
Ingesting custom logs from VM to custom table
Hello, I'm having issues ingesting a custom log file from my IIS-enabled VM to a log analytics workspace. The steps I've taken to resolve this issue include: -Verified that the extension was successfully installed and provisioned -Verified that the…
Concurrent Automation Runbook jobs being triggered for a single web app stop activity
Azure activity log alert was set up for triggering alert for web app stop operation and azure automation runbook was specified in action group for this alert rule. Multiple Azure Automation Runbook jobs are being triggered concurrently due to multiple…
Logical disk alert for a VM at 80% utilization was not triggered
Even after enabling VMInsights and log-based alert rule, logical disk alert for a VM at 80% utilization was not triggered as expected. What is the correct way to configure such alert after enabling VMInsights? PS - Based on common issues that we have…
Unable to edit alert rule in Azure portal
Unable to edit alert rule in Azure portal. The error received is 'Failed to update alert rule'. This error suggests an internal server problem and advises retrying or contacting support with a provided correlation ID. PS - Based on common issues that we…
Using a single metric alerts for multiple resources in Azure
How do you monitor multiple resources using a single metric alert rule? Can Azure Metric alert rules be used for multiple resources? If yes, how? PS - Based on common issues that we have seen from customers and other sources, we are posting these…
Disabling the 'auto resolve' option for alert rule causes alerts to be fired
When the 'auto resolve' option of the alert rule is disabled, alerts start firing, but when enabled, the alerts stop firing. What is the use of 'auto resolve' feature of alert rule? PS - Based on the issues that we have seen from multiple customers and…
Migrating Application Insights availability test alert rule to different Azure Subscription
After migrating the ApplicationInsights to a different Azure subscription, unable to find availability test alerts rule which gets automatically created for the Application Insights availability tests. PS - Based on the issues that we have seen from…
Including the result of log search query for Log based alert rule
How to include result of log search in alert generated by log based alert rule. Specifically, how do we include results from KQL queries, such as computer names, rows of result returned etc. directly in Azure email notifications sent for Azure Monitor…
Facing challenges with a suppression rule that isn't working as expected for a couple of servers, despite following Microsoft's configuration suggestions
How do you troubleshoot a suppression rule, if it does not work for a couple of servers? PS - Based on the issues that we have seen from multiple customers and sources, we are posting these questions to help the Azure community.
Configuring alert rules for your Virtual Machine Scale Sets (VMSS) in the Azure portal
How to configure alert rules for your Virtual Machine Scale Sets (VMSS) in the Azure portal? What should be the correct scope and dimension for metric alerts?
![](https://techprofile.blob.core.windows.net/images/8a0dedc1000b41f2826f4a6e4f59767f.png)
log search query alerts specifically for SQL exceptions
How to setup Azure Monitor log-based alert rule to alert for SQL exceptions (or any other exceptions)?
![](https://techprofile.blob.core.windows.net/images/U1Jln6XVxUOXS5Rme1kflg.png?8DC69F)
MS Defender agent uninstalling - Complete #help
Hello Community I have a VM where a 3rd party AV is installed , previously we were using MS defender endpoint but it was giving pain for redhat machines. Problem : I have a win10 VM where i have uninstalled the MDE agent from extension . but…
AVD Insights Host Performance Blade Empty after change to new Azure Monitoring Agent
Hi all, I have a quick question regarding the AVD Insights. Does anyone else currently have issues with the "Host Performance" blade showing "the query returned no results" for all the insights? I have this issue currently in multiple…