Data Exports - Create Or Update
Create or update a data export.
PUT https://management.azure.com/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.OperationalInsights/workspaces/{workspaceName}/dataExports/{dataExportName}?api-version=2026-03-01
URI Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
|
data
|
path | True |
string |
The data export rule name. |
|
resource
|
path | True |
string minLength: 1maxLength: 90 |
The name of the resource group. The name is case insensitive. |
|
subscription
|
path | True |
string (uuid) |
The ID of the target subscription. The value must be an UUID. |
|
workspace
|
path | True |
string minLength: 4maxLength: 63 pattern: ^[A-Za-z0-9][A-Za-z0-9-]+[A-Za-z0-9]$ |
The name of the workspace. |
|
api-version
|
query | True |
string minLength: 1 |
The API version to use for this operation. |
Request Body
| Name | Required | Type | Description |
|---|---|---|---|
| properties.destination.resourceId | True |
string |
The destination resource ID. This can be copied from the Properties entry of the destination resource in Azure. |
| properties.tableNames | True |
string[] |
An array of tables to export, for example: [“Heartbeat, SecurityEvent”]. |
| properties.createdDate |
string |
The latest data export rule modification time. |
|
| properties.dataExportId |
string |
The data export rule ID. |
|
| properties.destination.metaData.eventHubName |
string |
Optional. Allows to define an Event Hub name. Not applicable when destination is Storage Account. |
|
| properties.enable |
boolean |
Active when enabled. |
|
| properties.lastModifiedDate |
string |
Date and time when the export was last modified. |
Responses
| Name | Type | Description |
|---|---|---|
| 200 OK |
Resource 'DataExport' update operation succeeded |
|
| 201 Created |
Resource 'DataExport' create operation succeeded |
|
| Other Status Codes |
An unexpected error response. |
Security
azure_auth
Azure Active Directory OAuth2 Flow.
Type:
oauth2
Flow:
implicit
Authorization URL:
https://login.microsoftonline.com/common/oauth2/authorize
Scopes
| Name | Description |
|---|---|
| user_impersonation | impersonate your user account |
Examples
DataExportCreate
Sample request
PUT https://management.azure.com/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/RgTest1/providers/Microsoft.OperationalInsights/workspaces/DeWnTest1234/dataExports/export1?api-version=2026-03-01
{
"properties": {
"destination": {
"resourceId": "/subscriptions/192b9f85-a39a-4276-b96d-d5cd351703f9/resourceGroups/OIAutoRest1234/providers/Microsoft.EventHub/namespaces/test"
},
"tableNames": [
"Heartbeat"
]
}
}
Sample response
{
"name": "export1",
"type": "Microsoft.OperationalInsights/workspaces/export",
"id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourcegroups/RgTest1/providers/microsoft.operationalinsights/workspaces/DeWnTest1234/export/export1",
"properties": {
"createdDate": "Sun, 12 Jan 2020 12:51:10 GMT",
"dataExportId": "d5233afc-7829-4b89-c594-08d7975e19a5",
"destination": {
"type": "EventHub",
"resourceId": "/subscriptions/192b9f85-a39a-4276-b96d-d5cd351703f9/resourceGroups/OIAutoRest1234/providers/Microsoft.EventHub/namespaces/test"
},
"enable": true,
"lastModifiedDate": "Sun, 12 Jan 2020 12:51:10 GMT",
"tableNames": [
"Heartbeat"
]
}
}
{
"name": "export1",
"type": "Microsoft.OperationalInsights/workspaces/export",
"id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourcegroups/RgTest1/providers/microsoft.operationalinsights/workspaces/DeWnTest1234/export/export1",
"properties": {
"createdDate": "Sun, 12 Jan 2020 12:51:10 GMT",
"dataExportId": "d5233afc-7829-4b89-c594-08d7975e19a5",
"destination": {
"type": "EventHub",
"resourceId": "/subscriptions/192b9f85-a39a-4276-b96d-d5cd351703f9/resourceGroups/OIAutoRest1234/providers/Microsoft.EventHub/namespaces/test"
},
"enable": true,
"lastModifiedDate": "Sun, 12 Jan 2020 12:51:10 GMT",
"tableNames": [
"Heartbeat"
]
}
}
Definitions
| Name | Description |
|---|---|
|
created |
The type of identity that created the resource. |
|
Data |
The top level data export resource container. |
|
Error |
The resource management error additional info. |
|
Error |
The error detail. |
|
Error |
Error response |
|
system |
Metadata pertaining to creation and last modification of the resource. |
| Type |
The type of the destination resource |
createdByType
The type of identity that created the resource.
| Value | Description |
|---|---|
| User | |
| Application | |
| ManagedIdentity | |
| Key |
DataExport
The top level data export resource container.
| Name | Type | Description |
|---|---|---|
| id |
string (arm-id) |
Fully qualified resource ID for the resource. E.g. "/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}" |
| name |
string |
The name of the resource |
| properties.createdDate |
string |
The latest data export rule modification time. |
| properties.dataExportId |
string |
The data export rule ID. |
| properties.destination.metaData.eventHubName |
string |
Optional. Allows to define an Event Hub name. Not applicable when destination is Storage Account. |
| properties.destination.resourceId |
string |
The destination resource ID. This can be copied from the Properties entry of the destination resource in Azure. |
| properties.destination.type |
The type of the destination resource |
|
| properties.enable |
boolean |
Active when enabled. |
| properties.lastModifiedDate |
string |
Date and time when the export was last modified. |
| properties.tableNames |
string[] |
An array of tables to export, for example: [“Heartbeat, SecurityEvent”]. |
| systemData |
Azure Resource Manager metadata containing createdBy and modifiedBy information. |
|
| type |
string |
The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts" |
ErrorAdditionalInfo
The resource management error additional info.
| Name | Type | Description |
|---|---|---|
| info |
object |
The additional info. |
| type |
string |
The additional info type. |
ErrorDetail
The error detail.
| Name | Type | Description |
|---|---|---|
| additionalInfo |
The error additional info. |
|
| code |
string |
The error code. |
| details |
The error details. |
|
| message |
string |
The error message. |
| target |
string |
The error target. |
ErrorResponse
Error response
| Name | Type | Description |
|---|---|---|
| error |
The error object. |
systemData
Metadata pertaining to creation and last modification of the resource.
| Name | Type | Description |
|---|---|---|
| createdAt |
string (date-time) |
The timestamp of resource creation (UTC). |
| createdBy |
string |
The identity that created the resource. |
| createdByType |
The type of identity that created the resource. |
|
| lastModifiedAt |
string (date-time) |
The timestamp of resource last modification (UTC) |
| lastModifiedBy |
string |
The identity that last modified the resource. |
| lastModifiedByType |
The type of identity that last modified the resource. |
Type
The type of the destination resource
| Value | Description |
|---|---|
| StorageAccount |
StorageAccount |
| EventHub |
EventHub |