New high upload volume app - azure blog storage

Aran Billen 701 Reputation points
2024-05-17T07:19:51.6166667+00:00

Hi All,

I have had this Alert: New high upload volume app

How do I investigate further as there isnt much detail to go on?

Screenshot 2024-05-17 at 08.14.53

Any ideas?

Azure Blob Storage
Azure Blob Storage
An Azure service that stores unstructured data in the cloud as blobs.
2,511 questions
0 comments No comments
{count} votes

Accepted answer
  1. Anand Prakash Yadav 6,940 Reputation points Microsoft Vendor
    2024-05-20T10:28:21.45+00:00

    Hello Aran Billen,

    Thank you for posting your query here!

    Given the alert you have received, "New high upload volume app" in Azure Blob Storage, it indicates that there has been an unusual increase in the volume of data being uploaded to your storage account. To investigate this alert further and determine the cause, please check the below steps:

    Metrics Analysis:
    Go to Storage accounts in the Azure portal> Select your storage account> Under Monitoring, click on Metrics> Set the Namespace to Blob and the Metric to Ingress> Adjust the time range to include the period during which the alert was triggered> Analyze the graph for any spikes or abnormal patterns.

    Storage Logging:
    Go to Storage accounts in the Azure portal> Select your storage account> Under Monitoring, click on Diagnostic settings> Ensure that logging is enabled for the Blob service> Download and analyze the logs from the specified storage location.

    Activity Log:
    In the Azure portal, go to Monitor> Select Activity log> Apply filters to focus on activities related to your storage account and specific operation types like Write Blob> Review the details of each relevant entry to understand the source and context of the uploads.

    Do let us know if you have any further queries. I’m happy to assist you further.

    Please do not forget to "Accept the answer” and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.


1 additional answer

Sort by: Most helpful
  1. Gowtham CP 2,450 Reputation points
    2024-05-17T08:55:09.1233333+00:00

    Hello Aran Billen ,

    Thanks for reaching out in the Microsoft Q&A!

    To investigate a New high upload volume app alert in Azure Blob Storage, you can start by checking Microsoft Cloud App Security (MCAS) or Azure Monitor Logs to identify the app. Then, utilize storage insights logs and Azure Activity Log to track upload activity and analyze patterns. You can also check Application Insights if available, and review access controls like Shared Access Signatures (SAS). Don't forget to reach out to app admins for insights and consider setting up proactive monitoring for future incidents.

    If you found this solution helpful, consider accepting it.

    0 comments No comments