Azure Event Hubs Azure-Microsoft.EventHub
| operationName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all for Azure-Microsoft.EventHub rules that match the resource provider but no specific operation. | N | N |
| Microsoft.EventHub/ | Checks availability of namespace under given subscription. | N | N |
| Microsoft.EventHub/ | Checks availability of namespace under given subscription. This API is deprecated please use CheckNameAvailability instead. | N | N |
| Microsoft.EventHub/ | Delete EventHub Cluster Resource | N | N |
| Microsoft.EventHub/ | Create or Update EventHub Cluster Resource | N | N |
| Microsoft.EventHub/ | Deletes the VNet rules in EventHub Resource Provider for the specified VNet | N | N |
| Microsoft.EventHub/ | Updates Namespace Authorization Rule. This API is deprecated. Please use a PUT call to update the Namespace Authorization Rule instead.. This operation is not supported on API version 2017-04-01. | N | N |
| Microsoft.EventHub/ | Delete Namespace Authorization Rule. The Default Namespace Authorization Rule cannot be deleted. | N | N |
| Microsoft.EventHub/ | Get the Connection String to the Namespace | N | N |
| Microsoft.EventHub/ | Regenerate the Primary or Secondary key to the Resource | N | N |
| Microsoft.EventHub/ | Create a Namespace level Authorization Rules and update its properties. The Authorization Rules Access Rights, the Primary and Secondary Keys can be updated. | N | Y |
| Microsoft.EventHub/ | Delete Namespace Resource | Y | N |
| Microsoft.EventHub/ | Checks availability of namespace alias under given subscription. | N | N |
| Microsoft.EventHub/ | Gets the authorization rules keys for the Disaster Recovery primary namespace | N | N |
| Microsoft.EventHub/ | Disables Disaster Recovery and stops replicating changes from primary to secondary namespaces. | N | N |
| Microsoft.EventHub/ | Checks availability of namespace alias under given subscription (Deprecated). | N | N |
| Microsoft.EventHub/ | Deletes the Disaster Recovery configuration associated with the namespace. This operation can only be invoked via the primary namespace. | N | N |
| Microsoft.EventHub/ | Invokes a GEO DR failover and reconfigures the namespace alias to point to the secondary namespace. | N | N |
| Microsoft.EventHub/ | Creates or Updates the Disaster Recovery configuration associated with the namespace. | N | N |
| Microsoft.EventHub/ | Operation to update EventHub. This operation is not supported on API version 2017-04-01. Authorization Rules. Please use a PUT call to update Authorization Rule. | N | N |
| Microsoft.EventHub/ | Operation to delete EventHub Authorization Rules | N | N |
| Microsoft.EventHub/ | Get the Connection String to EventHub | N | N |
| Microsoft.EventHub/ | Regenerate the Primary or Secondary key to the Resource | N | N |
| Microsoft.EventHub/ | Create EventHub Authorization Rules and Update its properties. The Authorization Rules Access. Rights can be updated. | Y | N |
| Microsoft.EventHub/ | Operation to delete ConsumerGroup Resource | N | N |
| Microsoft.EventHub/ | Create or Update ConsumerGroup properties. | N | N |
| Microsoft.EventHub/ | Operation to delete EventHub Resource | N | Y |
| Microsoft.EventHub/ | Create or Update EventHub properties. | N | N |
| Microsoft.EventHub/ | Failover Namespace Resource | N | N |
| Microsoft.EventHub/ | Delete IP Filter Resource | N | N |
| Microsoft.EventHub/ | Create IP Filter Resource | N | N |
| Microsoft.EventHub/ | Updates the Messaging Plan for a namespace.<br>This API is deprecated.<br>Properties exposed via the MessagingPlan resource are moved to the (parent) Namespace resource in later API versions..<br>This operation is not supported on API version 2017-04-01. | N | N |
| Microsoft.EventHub/ | Delete VNET Rule Resource | N | N |
| Microsoft.EventHub/ | Create VNET Rule Resource | N | N |
| Microsoft.EventHub/ | Delete VNET Rule Resource | N | N |
| Microsoft.EventHub/ | Create VNET Rule Resource | N | N |
| Microsoft.EventHub/ | Delete Network Security Perimeter Association Proxy | N | N |
| Microsoft.EventHub/ | Reconcile Network Security Perimeter Association Proxy | N | N |
| Microsoft.EventHub/ | Create or Update Network Security Perimeter Association Proxy | N | N |
| Microsoft.EventHub/ | Reconcile Network Security Perimeter Configurations | N | N |
| Microsoft.EventHub/ | Delete Private Endpoint Connection Proxy | N | N |
| Microsoft.EventHub/ | Validate Private Endpoint Connection Proxy | N | N |
| Microsoft.EventHub/ | Create Private Endpoint Connection Proxy | N | N |
| Microsoft.EventHub/ | Removes Private Endpoint Connection | N | N |
| Microsoft.EventHub/ | Create or Update Private Endpoint Connection | N | N |
| Microsoft.EventHub/ | Approve Private Endpoint Connection | N | N |
| Microsoft.EventHub/ | Get list of Namespace diagnostic settings Resource Descriptions | N | N |
| Microsoft.EventHub/ | Remove ACS namespace | N | N |
| Microsoft.EventHub/ | Operation to delete SchemaGroup Resource | N | N |
| Microsoft.EventHub/ | Create or Update SchemaGroup properties. | N | N |
| Microsoft.EventHub/ | UpdateNamespaceState | N | N |
| Microsoft.EventHub/ | Delete VNET Rule Resource | N | N |
| Microsoft.EventHub/ | Create VNET Rule Resource | N | N |
| Microsoft.EventHub/ | Create a Namespace Resource and Update its properties. Tags and Capacity of the Namespace are the properties which can be updated. | Y | N |
| Microsoft.EventHub/ | Registers the subscription for the EventHub resource provider and enables the creation of EventHub resources | Y | N |
| Microsoft.EventHub/ | Registers the EventHub Resource Provider | N | N |
any: Azure Event Hubs (catch-all)
#Description
Catch-all for Azure-Microsoft.EventHub rules that match the resource provider but no specific operation.
Microsoft.EventHub/checkNameAvailability/action
#Description
Checks availability of namespace under given subscription.
Microsoft.EventHub/checkNamespaceAvailability/action
#Description
Checks availability of namespace under given subscription. This API is deprecated please use CheckNameAvailability instead.
Microsoft.EventHub/clusters/delete
#Description
Delete EventHub Cluster Resource
Microsoft.EventHub/clusters/write
#Description
Create or Update EventHub Cluster Resource
Microsoft.EventHub/locations/deleteVirtualNetworkOrSubnets/action
#Description
Deletes the VNet rules in EventHub Resource Provider for the specified VNet
Microsoft.EventHub/namespaces/Delete
#Description
Delete Namespace Resource
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.EventHub/namespaces/dwh92eef0eventhub",
"action": "Microsoft.EventHub/namespaces/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.EventHub/namespaces/dwh92eef0eventhub",
"action": "Microsoft.EventHub/namespaces/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "a5d21409-babe-4ee9-b9ce-2914644d604b",
"EventDataId": "98826c98-08fa-8c0c-1843-c2ec6165117f",
"EventSubmissionTimestamp": "2026-07-02T17:20:17.3783391Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.EVENTHUB/NAMESPACES/DELETE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.EventHub/namespaces/dwh92eef0eventhub",
"message": "Microsoft.EventHub/namespaces/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "98826c98-08fa-8c0c-1843-c2ec6165117f",
"eventSubmissionTimestamp": "2026-07-02T17:20:17.3783391Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh92eef0eventhub",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.EVENTHUB",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.EventHub/namespaces/dwh92eef0eventhub",
"message": "Microsoft.EventHub/namespaces/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "98826c98-08fa-8c0c-1843-c2ec6165117f",
"eventSubmissionTimestamp": "2026-07-02T17:20:17.3783391Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh92eef0eventhub",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.EVENTHUB",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.EVENTHUB",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
Microsoft.EventHub/namespaces/disasterRecoveryConfigs/action
#Description
Checks availability of namespace alias under given subscription.
Microsoft.EventHub/namespaces/disasterRecoveryConfigs/breakPairing/action
#Description
Disables Disaster Recovery and stops replicating changes from primary to secondary namespaces.
Microsoft.EventHub/namespaces/disasterrecoveryconfigs/checkNameAvailability/action
#Description
Checks availability of namespace alias under given subscription (Deprecated).
Microsoft.EventHub/namespaces/disasterRecoveryConfigs/delete
#Description
Deletes the Disaster Recovery configuration associated with the namespace. This operation can only be invoked via the primary namespace.
Microsoft.EventHub/namespaces/disasterRecoveryConfigs/failover/action
#Description
Invokes a GEO DR failover and reconfigures the namespace alias to point to the secondary namespace.
Microsoft.EventHub/namespaces/disasterRecoveryConfigs/write
#Description
Creates or Updates the Disaster Recovery configuration associated with the namespace.
Microsoft.EventHub/namespaces/eventHubs/consumergroups/Delete
#Description
Operation to delete ConsumerGroup Resource
Microsoft.EventHub/namespaces/eventHubs/consumergroups/write
#Description
Create or Update ConsumerGroup properties.
Microsoft.EventHub/namespaces/eventhubs/Delete
#Description
Operation to delete EventHub Resource
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1485, T1562, T1562.008Panther #
T1562.008
Microsoft.EventHub/namespaces/eventhubs/write
#Description
Create or Update EventHub properties.
Microsoft.EventHub/namespaces/failover/action
#Description
Failover Namespace Resource
Microsoft.EventHub/namespaces/ipFilterRules/delete
#Description
Delete IP Filter Resource
Microsoft.EventHub/namespaces/ipFilterRules/write
#Description
Create IP Filter Resource
Microsoft.EventHub/namespaces/messagingPlan/write
#Description
Updates the Messaging Plan for a namespace.<br>This API is deprecated.<br>Properties exposed via the MessagingPlan resource are moved to the (parent) Namespace resource in later API versions..<br>This operation is not supported on API version 2017-04-01.
Microsoft.EventHub/namespaces/networkruleset/delete
#Description
Delete VNET Rule Resource
Microsoft.EventHub/namespaces/networkruleset/write
#Description
Create VNET Rule Resource
Microsoft.EventHub/namespaces/networkrulesets/delete
#Description
Delete VNET Rule Resource
Microsoft.EventHub/namespaces/networkrulesets/write
#Description
Create VNET Rule Resource
Microsoft.EventHub/namespaces/networkSecurityPerimeterAssociationProxies/delete
#Description
Delete Network Security Perimeter Association Proxy
Microsoft.EventHub/namespaces/networkSecurityPerimeterAssociationProxies/reconcile/action
#Description
Reconcile Network Security Perimeter Association Proxy
Microsoft.EventHub/namespaces/networkSecurityPerimeterAssociationProxies/write
#Description
Create or Update Network Security Perimeter Association Proxy
Microsoft.EventHub/namespaces/networkSecurityPerimeterConfigurations/reconcile/action
#Description
Reconcile Network Security Perimeter Configurations
Microsoft.EventHub/namespaces/privateEndpointConnectionProxies/delete
#Description
Delete Private Endpoint Connection Proxy
Microsoft.EventHub/namespaces/privateEndpointConnectionProxies/validate/action
#Description
Validate Private Endpoint Connection Proxy
Microsoft.EventHub/namespaces/privateEndpointConnectionProxies/write
#Description
Create Private Endpoint Connection Proxy
Microsoft.EventHub/namespaces/privateEndpointConnections/delete
#Description
Removes Private Endpoint Connection
Microsoft.EventHub/namespaces/privateEndpointConnections/write
#Description
Create or Update Private Endpoint Connection
Microsoft.EventHub/namespaces/privateEndpointConnectionsApproval/action
#Description
Approve Private Endpoint Connection
Microsoft.EventHub/namespaces/providers/Microsoft.Insights/diagnosticSettings/write
#Description
Get list of Namespace diagnostic settings Resource Descriptions
Microsoft.EventHub/namespaces/removeAcsNamepsace/action
#Description
Remove ACS namespace
Microsoft.EventHub/namespaces/schemagroups/delete
#Description
Operation to delete SchemaGroup Resource
Microsoft.EventHub/namespaces/schemagroups/write
#Description
Create or Update SchemaGroup properties.
Microsoft.EventHub/namespaces/updateState/action
#Description
UpdateNamespaceState
Microsoft.EventHub/namespaces/virtualNetworkRules/delete
#Description
Delete VNET Rule Resource
Microsoft.EventHub/namespaces/virtualNetworkRules/write
#Description
Create VNET Rule Resource
Microsoft.EventHub/namespaces/write
#Description
Create a Namespace Resource and Update its properties. Tags and Capacity of the Namespace are the properties which can be updated.
Example Resource Log Record #
{
"ActivityStatus": "",
"ActivityStatusValue": "Success",
"ActivitySubstatus": "",
"ActivitySubstatusValue": "",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.EventHub/namespaces/zceh55001",
"action": "Microsoft.EventHub/namespaces/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.EventHub/namespaces/zceh55001",
"action": "Microsoft.EventHub/namespaces/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"Category": "",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782752670",
"nbf": "1782752670",
"exp": "1782756583",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "3 5",
"xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
"xms_idrel": "1 2",
"xms_sub_fct": "2 3",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782752670",
"nbf": "1782752670",
"exp": "1782756583",
"aio": "REDACTED",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "REDACTED",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "3 5",
"xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
"xms_idrel": "1 2",
"xms_sub_fct": "2 3",
"xms_tcdt": "1768616282",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "f3cb742e-cd33-48e1-aa8a-afdf83f75f47",
"EventDataId": "9bf9799d-ec50-ccc3-7a5f-0c2a1b054d9c",
"EventSubmissionTimestamp": "2026-06-29T17:45:20.7797653Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationId": "",
"OperationName": "",
"OperationNameValue": "MICROSOFT.EVENTHUB/NAMESPACES/WRITE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.EventHub/namespaces/zceh55001",
"message": "Microsoft.EventHub/namespaces/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "9bf9799d-ec50-ccc3-7a5f-0c2a1b054d9c",
"eventSubmissionTimestamp": "2026-06-29T17:45:20.7797653Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zceh55001",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.EVENTHUB",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.EventHub/namespaces/zceh55001",
"message": "Microsoft.EventHub/namespaces/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "9bf9799d-ec50-ccc3-7a5f-0c2a1b054d9c",
"eventSubmissionTimestamp": "2026-06-29T17:45:20.7797653Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zceh55001",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.EVENTHUB",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Resource": "",
"ResourceGroup": "RG-LOGCAPTURE-GEN",
"ResourceId": "",
"ResourceProvider": "",
"ResourceProviderValue": "MICROSOFT.EVENTHUB",
"SourceSystem": "Azure",
"SubscriptionId": "22222222-2222-2222-2222-222222222222",
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T17:45:20.7797653Z",
"Type": "AzureActivity",
"_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.eventhub/namespaces/zceh55001"
}
Microsoft.EventHub/register/action
#Description
Registers the subscription for the EventHub resource provider and enables the creation of EventHub resources
Example Resource Log Record #
{
"ActivityStatus": "",
"ActivityStatusValue": "Success",
"ActivitySubstatus": "",
"ActivitySubstatusValue": "OK",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"action": "Microsoft.EventHub/register/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"action": "Microsoft.EventHub/register/action",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"Category": "",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782752670",
"nbf": "1782752670",
"exp": "1782756583",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "3 5",
"xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
"xms_idrel": "1 2",
"xms_sub_fct": "2 3",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782752670",
"nbf": "1782752670",
"exp": "1782756583",
"aio": "REDACTED",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "REDACTED",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "3 5",
"xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
"xms_idrel": "1 2",
"xms_sub_fct": "2 3",
"xms_tcdt": "1768616282",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "5954ebc4-f7e4-4c60-b1b6-34d7546563a0",
"EventDataId": "e7f29c6c-ecc8-ac83-d576-ddafbd80d76d",
"EventSubmissionTimestamp": "2026-06-29T17:43:23.5836238Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationId": "",
"OperationName": "",
"OperationNameValue": "MICROSOFT.EVENTHUB/REGISTER/ACTION",
"Properties": {
"statusCode": "OK",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.EventHub",
"message": "Microsoft.EventHub/register/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "e7f29c6c-ecc8-ac83-d576-ddafbd80d76d",
"eventSubmissionTimestamp": "2026-06-29T17:43:23.5836238Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resourceProviderValue": "MICROSOFT.EVENTHUB",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.EventHub",
"message": "Microsoft.EventHub/register/action",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "e7f29c6c-ecc8-ac83-d576-ddafbd80d76d",
"eventSubmissionTimestamp": "2026-06-29T17:43:23.5836238Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resourceProviderValue": "MICROSOFT.EVENTHUB",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"statusCode": "OK",
"serviceRequestId": "",
"activitySubstatusValue": "OK"
},
"Resource": "",
"ResourceGroup": "",
"ResourceId": "",
"ResourceProvider": "",
"ResourceProviderValue": "MICROSOFT.EVENTHUB",
"SourceSystem": "Azure",
"SubscriptionId": "22222222-2222-2222-2222-222222222222",
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T17:43:23.5836238Z",
"Type": "AzureActivity",
"_ResourceId": ""
}
Microsoft.EventHub/unregister/action
#Description
Registers the EventHub Resource Provider