Microsoft。Sql伺服器/devOpsAuditingSettings

Bicep 資源定義

伺服器/devOpsAuditingSettings 資源類型可以使用目標作業來部署:

如需每個 API 版本中已變更屬性的清單,請參閱 變更記錄檔。

使用範例

Azure 快速入門範例

以下的 Azure 快速啟動範本包含部署此資源類型的Bicep範例。

Bicep檔案 Description
Azure SQL Server 並以 Auditing 寫入 Log Analytics 此範本允許您部署啟用 Auditing 的 Azure SQL 伺服器,將稽核日誌寫入 Log Analytics(OMS 工作空間)

資源格式

創造一個 Microsoft。Sql/servers/devOpsAuditingSettings 資源,請在你的範本中加入以下 Bicep。

resource symbolicname 'Microsoft.Sql/servers/devOpsAuditingSettings@2026-08-01-preview' = {
  parent: resourceSymbolicName
  name: 'string'
  properties: {
    isAzureMonitorTargetEnabled: bool
    isManagedIdentityInUse: bool
    state: 'string'
    storageAccountAccessKey: 'string'
    storageAccountSubscriptionId: 'string'
    storageEndpoint: 'string'
  }
}

屬性值

Microsoft。Sql/servers/devOpsAuditingSettings

Name Description Value
name 資源名稱 'Default' (必要)
父代 在 Bicep 中,你可以指定子資源的父資源。 只有在父資源外部宣告子資源時,才需要新增這個屬性。

如需詳細資訊,請參閱 父資源外部的子資源。
類型的資源符號名稱:伺服器
properties 資源屬性。 ServerDevOpsAuditSettingsProperties

ServerDevOpsAuditSettingsProperties

Name Description Value
isAzureMonitorTargetEnabled 指定是否將 DevOps 稽核事件送至 Azure 監視器。
若要將事件傳送到 Azure 監視器,請將「State」設為「Enabled」,「IsAzureMonitorTargetEnabled」為 true。

使用 REST API 設定 DevOps 稽核時,也應該在 master 資料庫上建立具有 'DevOpsOperationsAudit' 診斷記錄類別的診斷設定。

診斷設定 URI 格式:
輸入 https://management.azure.com/subscriptions/{subscriptionId}/resourceGroups/{resourceGroup}/providers/Microsoft.Sql/servers/{serverName}/databases/master/providers/microsoft.insights/diagnosticSettings/{settingsName}?api-version=2017-05-01-preview

如需詳細資訊,請參閱 診斷設定 REST API
或 診斷設定PowerShell
bool
isManagedIdentityInUse 指定受控識別是否用來存取 Blob 記憶體 bool
狀態 指定稽核的狀態。 如果狀態為 Enabled,則需要 storageEndpoint 或 isAzureMonitorTargetEnabled。 'Disabled'
'Enabled' (必要)
storageAccountAccessKey 指定稽核記憶體帳戶的標識碼金鑰。
如果狀態為 Enabled 且 storageEndpoint 已指定,則未指定 storageAccountAccessKey 會使用 SQL Server 系統指派的受控識別來存取記憶體。
使用受控識別驗證的必要條件:
1. 在 Azure Active Directory (AAD) 中為 SQL Server 分配系統指定的管理身份。
2. 透過在伺服器身份中新增「Storage Blob Data Contributor」RBAC 角色,授予 SQL Server 身份存取權。
如需詳細資訊,請參閱使用受控識別驗證對記憶體 稽核
string

Constraints:
敏感性值。 以安全參數的形式傳入。
storageAccountSubscriptionId 指定 Blob 記憶體訂用帳戶標識碼。 string

Constraints:
最小長度 = 36
最大長度 = 36
圖案 = ^[0-9a-fA-F]{8}-([0-9a-fA-F]{4}-){3}[0-9a-fA-F]{12}$
storageEndpoint 指定 Blob 記憶體端點(例如 https://MyAccount.blob.core.windows.net)。 如果狀態為 Enabled,則需要 storageEndpoint 或 isAzureMonitorTargetEnabled。 字串

ARM 樣本資源定義

伺服器/devOpsAuditingSettings 資源類型可以使用目標作業來部署:

使用範例

Azure Quickstart templates

以下的 Azure 快速起始範本部署此資源類型。

Template Description
Azure SQL Server 並以 Auditing 寫入 Log Analytics

部署至Azure
此範本允許您部署啟用 Auditing 的 Azure SQL 伺服器,將稽核日誌寫入 Log Analytics(OMS 工作空間)

資源格式

創造一個 Microsoft。Sql/servers/devOpsAuditingSettings 資源,請將以下 JSON 加入你的範本。

{
  "type": "Microsoft.Sql/servers/devOpsAuditingSettings",
  "apiVersion": "2026-08-01-preview",
  "name": "string",
  "properties": {
    "isAzureMonitorTargetEnabled": "bool",
    "isManagedIdentityInUse": "bool",
    "state": "string",
    "storageAccountAccessKey": "string",
    "storageAccountSubscriptionId": "string",
    "storageEndpoint": "string"
  }
}

屬性值

Microsoft。Sql/servers/devOpsAuditingSettings

Name Description Value
apiVersion API 版本 『2026-08-01-預覽』
name 資源名稱 'Default' (必要)
properties 資源屬性。 ServerDevOpsAuditSettingsProperties
型別 資源類型 「Microsoft。Sql/servers/devOpsAuditingSettings'

ServerDevOpsAuditSettingsProperties

Name Description Value
isAzureMonitorTargetEnabled 指定是否將 DevOps 稽核事件送至 Azure 監視器。
若要將事件傳送到 Azure 監視器,請將「State」設為「Enabled」,「IsAzureMonitorTargetEnabled」為 true。

使用 REST API 設定 DevOps 稽核時,也應該在 master 資料庫上建立具有 'DevOpsOperationsAudit' 診斷記錄類別的診斷設定。

診斷設定 URI 格式:
輸入 https://management.azure.com/subscriptions/{subscriptionId}/resourceGroups/{resourceGroup}/providers/Microsoft.Sql/servers/{serverName}/databases/master/providers/microsoft.insights/diagnosticSettings/{settingsName}?api-version=2017-05-01-preview

如需詳細資訊,請參閱 診斷設定 REST API
或 診斷設定PowerShell
bool
isManagedIdentityInUse 指定受控識別是否用來存取 Blob 記憶體 bool
狀態 指定稽核的狀態。 如果狀態為 Enabled,則需要 storageEndpoint 或 isAzureMonitorTargetEnabled。 'Disabled'
'Enabled' (必要)
storageAccountAccessKey 指定稽核記憶體帳戶的標識碼金鑰。
如果狀態為 Enabled 且 storageEndpoint 已指定,則未指定 storageAccountAccessKey 會使用 SQL Server 系統指派的受控識別來存取記憶體。
使用受控識別驗證的必要條件:
1. 在 Azure Active Directory (AAD) 中為 SQL Server 分配系統指定的管理身份。
2. 透過在伺服器身份中新增「Storage Blob Data Contributor」RBAC 角色,授予 SQL Server 身份存取權。
如需詳細資訊,請參閱使用受控識別驗證對記憶體 稽核
string

Constraints:
敏感性值。 以安全參數的形式傳入。
storageAccountSubscriptionId 指定 Blob 記憶體訂用帳戶標識碼。 string

Constraints:
最小長度 = 36
最大長度 = 36
圖案 = ^[0-9a-fA-F]{8}-([0-9a-fA-F]{4}-){3}[0-9a-fA-F]{12}$
storageEndpoint 指定 Blob 記憶體端點(例如 https://MyAccount.blob.core.windows.net)。 如果狀態為 Enabled,則需要 storageEndpoint 或 isAzureMonitorTargetEnabled。 字串

Terraform (AzAPI 提供者) 資源定義

伺服器/devOpsAuditingSettings 資源類型可以使用目標作業來部署:

  • 資源團體 關於每個 API 版本變更屬性的清單,請參見 變更日誌。

資源格式

創造一個 Microsoft。Sql/servers/devOpsAuditingSettings 資源,將以下 Terraform 加入你的範本。

resource "azapi_resource" "symbolicname" {
  type = "Microsoft.Sql/servers/devOpsAuditingSettings@2026-08-01-preview"
  name = "string"
  parent_id = "string"
  body = {
    properties = {
      isAzureMonitorTargetEnabled = bool
      isManagedIdentityInUse = bool
      state = "string"
      storageAccountAccessKey = "string"
      storageAccountSubscriptionId = "string"
      storageEndpoint = "string"
    }
  }
}

屬性值

Microsoft。Sql/servers/devOpsAuditingSettings

Name Description Value
name 資源名稱 'Default' (必要)
parent_id 此資源為父系之資源的標識碼。 類型資源的標識碼:伺服器
properties 資源屬性。 ServerDevOpsAuditSettingsProperties
型別 資源類型 「Microsoft。SQL/servers/devOpsAuditingSettings@2026-08-01-preview」

ServerDevOpsAuditSettingsProperties

Name Description Value
isAzureMonitorTargetEnabled 指定是否將 DevOps 稽核事件送至 Azure 監視器。
若要將事件傳送到 Azure 監視器,請將「State」設為「Enabled」,「IsAzureMonitorTargetEnabled」為 true。

使用 REST API 設定 DevOps 稽核時,也應該在 master 資料庫上建立具有 'DevOpsOperationsAudit' 診斷記錄類別的診斷設定。

診斷設定 URI 格式:
輸入 https://management.azure.com/subscriptions/{subscriptionId}/resourceGroups/{resourceGroup}/providers/Microsoft.Sql/servers/{serverName}/databases/master/providers/microsoft.insights/diagnosticSettings/{settingsName}?api-version=2017-05-01-preview

如需詳細資訊,請參閱 診斷設定 REST API
或 診斷設定PowerShell
bool
isManagedIdentityInUse 指定受控識別是否用來存取 Blob 記憶體 bool
狀態 指定稽核的狀態。 如果狀態為 Enabled,則需要 storageEndpoint 或 isAzureMonitorTargetEnabled。 'Disabled'
'Enabled' (必要)
storageAccountAccessKey 指定稽核記憶體帳戶的標識碼金鑰。
如果狀態為 Enabled 且 storageEndpoint 已指定,則未指定 storageAccountAccessKey 會使用 SQL Server 系統指派的受控識別來存取記憶體。
使用受控識別驗證的必要條件:
1. 在 Azure Active Directory (AAD) 中為 SQL Server 分配系統指定的管理身份。
2. 透過在伺服器身份中新增「Storage Blob Data Contributor」RBAC 角色,授予 SQL Server 身份存取權。
如需詳細資訊,請參閱使用受控識別驗證對記憶體 稽核
string

Constraints:
敏感性值。 以安全參數的形式傳入。
storageAccountSubscriptionId 指定 Blob 記憶體訂用帳戶標識碼。 string

Constraints:
最小長度 = 36
最大長度 = 36
圖案 = ^[0-9a-fA-F]{8}-([0-9a-fA-F]{4}-){3}[0-9a-fA-F]{12}$
storageEndpoint 指定 Blob 記憶體端點(例如 https://MyAccount.blob.core.windows.net)。 如果狀態為 Enabled,則需要 storageEndpoint 或 isAzureMonitorTargetEnabled。 字串