Azure Event Hubs Azure-Microsoft.EventHub

operationNameDescriptionSampleRule
anyCatch-all for Azure-Microsoft.EventHub rules that match the resource provider but no specific operation.NN
Microsoft.EventHub/checkNameAvailability/actionChecks availability of namespace under given subscription.NN
Microsoft.EventHub/checkNamespaceAvailability/actionChecks availability of namespace under given subscription. This API is deprecated please use CheckNameAvailability instead.NN
Microsoft.EventHub/clusters/deleteDelete EventHub Cluster ResourceNN
Microsoft.EventHub/clusters/writeCreate or Update EventHub Cluster ResourceNN
Microsoft.EventHub/locations/deleteVirtualNetworkOrSubnets/actionDeletes the VNet rules in EventHub Resource Provider for the specified VNetNN
Microsoft.EventHub/namespaces/authorizationRules/actionUpdates Namespace Authorization Rule. This API is deprecated. Please use a PUT call to update the Namespace Authorization Rule instead.. This operation is not supported on API version 2017-04-01.NN
Microsoft.EventHub/namespaces/authorizationRules/deleteDelete Namespace Authorization Rule. The Default Namespace Authorization Rule cannot be deleted.NN
Microsoft.EventHub/namespaces/authorizationRules/listkeys/actionGet the Connection String to the NamespaceNN
Microsoft.EventHub/namespaces/authorizationRules/regenerateKeys/actionRegenerate the Primary or Secondary key to the ResourceNN
Microsoft.EventHub/namespaces/authorizationRules/writeCreate a Namespace level Authorization Rules and update its properties. The Authorization Rules Access Rights, the Primary and Secondary Keys can be updated.NY
Microsoft.EventHub/namespaces/DeleteDelete Namespace ResourceYN
Microsoft.EventHub/namespaces/disasterRecoveryConfigs/actionChecks availability of namespace alias under given subscription.NN
Microsoft.EventHub/namespaces/disasterRecoveryConfigs/authorizationRules/listkeys/actionGets the authorization rules keys for the Disaster Recovery primary namespaceNN
Microsoft.EventHub/namespaces/disasterRecoveryConfigs/breakPairing/actionDisables Disaster Recovery and stops replicating changes from primary to secondary namespaces.NN
Microsoft.EventHub/namespaces/disasterrecoveryconfigs/checkNameAvailability/actionChecks availability of namespace alias under given subscription (Deprecated).NN
Microsoft.EventHub/namespaces/disasterRecoveryConfigs/deleteDeletes the Disaster Recovery configuration associated with the namespace. This operation can only be invoked via the primary namespace.NN
Microsoft.EventHub/namespaces/disasterRecoveryConfigs/failover/actionInvokes a GEO DR failover and reconfigures the namespace alias to point to the secondary namespace.NN
Microsoft.EventHub/namespaces/disasterRecoveryConfigs/writeCreates or Updates the Disaster Recovery configuration associated with the namespace.NN
Microsoft.EventHub/namespaces/eventhubs/authorizationRules/actionOperation to update EventHub. This operation is not supported on API version 2017-04-01. Authorization Rules. Please use a PUT call to update Authorization Rule.NN
Microsoft.EventHub/namespaces/eventhubs/authorizationRules/deleteOperation to delete EventHub Authorization RulesNN
Microsoft.EventHub/namespaces/eventhubs/authorizationRules/listkeys/actionGet the Connection String to EventHubNN
Microsoft.EventHub/namespaces/eventhubs/authorizationRules/regenerateKeys/actionRegenerate the Primary or Secondary key to the ResourceNN
Microsoft.EventHub/namespaces/eventhubs/authorizationRules/writeCreate EventHub Authorization Rules and Update its properties. The Authorization Rules Access. Rights can be updated.YN
Microsoft.EventHub/namespaces/eventHubs/consumergroups/DeleteOperation to delete ConsumerGroup ResourceNN
Microsoft.EventHub/namespaces/eventHubs/consumergroups/writeCreate or Update ConsumerGroup properties.NN
Microsoft.EventHub/namespaces/eventhubs/DeleteOperation to delete EventHub ResourceNY
Microsoft.EventHub/namespaces/eventhubs/writeCreate or Update EventHub properties.NN
Microsoft.EventHub/namespaces/failover/actionFailover Namespace ResourceNN
Microsoft.EventHub/namespaces/ipFilterRules/deleteDelete IP Filter ResourceNN
Microsoft.EventHub/namespaces/ipFilterRules/writeCreate IP Filter ResourceNN
Microsoft.EventHub/namespaces/messagingPlan/writeUpdates the Messaging Plan for a namespace.<br>This API is deprecated.<br>Properties exposed via the MessagingPlan resource are moved to the (parent) Namespace resource in later API versions..<br>This operation is not supported on API version 2017-04-01.NN
Microsoft.EventHub/namespaces/networkruleset/deleteDelete VNET Rule ResourceNN
Microsoft.EventHub/namespaces/networkruleset/writeCreate VNET Rule ResourceNN
Microsoft.EventHub/namespaces/networkrulesets/deleteDelete VNET Rule ResourceNN
Microsoft.EventHub/namespaces/networkrulesets/writeCreate VNET Rule ResourceNN
Microsoft.EventHub/namespaces/networkSecurityPerimeterAssociationProxies/deleteDelete Network Security Perimeter Association ProxyNN
Microsoft.EventHub/namespaces/networkSecurityPerimeterAssociationProxies/reconcile/actionReconcile Network Security Perimeter Association ProxyNN
Microsoft.EventHub/namespaces/networkSecurityPerimeterAssociationProxies/writeCreate or Update Network Security Perimeter Association ProxyNN
Microsoft.EventHub/namespaces/networkSecurityPerimeterConfigurations/reconcile/actionReconcile Network Security Perimeter ConfigurationsNN
Microsoft.EventHub/namespaces/privateEndpointConnectionProxies/deleteDelete Private Endpoint Connection ProxyNN
Microsoft.EventHub/namespaces/privateEndpointConnectionProxies/validate/actionValidate Private Endpoint Connection ProxyNN
Microsoft.EventHub/namespaces/privateEndpointConnectionProxies/writeCreate Private Endpoint Connection ProxyNN
Microsoft.EventHub/namespaces/privateEndpointConnections/deleteRemoves Private Endpoint ConnectionNN
Microsoft.EventHub/namespaces/privateEndpointConnections/writeCreate or Update Private Endpoint ConnectionNN
Microsoft.EventHub/namespaces/privateEndpointConnectionsApproval/actionApprove Private Endpoint ConnectionNN
Microsoft.EventHub/namespaces/providers/Microsoft.Insights/diagnosticSettings/writeGet list of Namespace diagnostic settings Resource DescriptionsNN
Microsoft.EventHub/namespaces/removeAcsNamepsace/actionRemove ACS namespaceNN
Microsoft.EventHub/namespaces/schemagroups/deleteOperation to delete SchemaGroup ResourceNN
Microsoft.EventHub/namespaces/schemagroups/writeCreate or Update SchemaGroup properties.NN
Microsoft.EventHub/namespaces/updateState/actionUpdateNamespaceStateNN
Microsoft.EventHub/namespaces/virtualNetworkRules/deleteDelete VNET Rule ResourceNN
Microsoft.EventHub/namespaces/virtualNetworkRules/writeCreate VNET Rule ResourceNN
Microsoft.EventHub/namespaces/writeCreate a Namespace Resource and Update its properties. Tags and Capacity of the Namespace are the properties which can be updated.YN
Microsoft.EventHub/register/actionRegisters the subscription for the EventHub resource provider and enables the creation of EventHub resourcesYN
Microsoft.EventHub/unregister/actionRegisters the EventHub Resource ProviderNN

any: Azure Event Hubs (catch-all)

#
Namespace
Microsoft.EventHub

Description

Catch-all for Azure-Microsoft.EventHub rules that match the resource provider but no specific operation.

Microsoft.EventHub/checkNameAvailability/action

#
Namespace
Microsoft.EventHub

Description

Checks availability of namespace under given subscription.

Microsoft.EventHub/checkNamespaceAvailability/action

#
Namespace
Microsoft.EventHub

Description

Checks availability of namespace under given subscription. This API is deprecated please use CheckNameAvailability instead.

Microsoft.EventHub/clusters/delete

#
Namespace
Microsoft.EventHub

Description

Delete EventHub Cluster Resource

Microsoft.EventHub/clusters/write

#
Namespace
Microsoft.EventHub

Description

Create or Update EventHub Cluster Resource

Microsoft.EventHub/locations/deleteVirtualNetworkOrSubnets/action

#
Namespace
Microsoft.EventHub

Description

Deletes the VNet rules in EventHub Resource Provider for the specified VNet

Microsoft.EventHub/namespaces/authorizationRules/action

#
Namespace
Microsoft.EventHub

Description

Updates Namespace Authorization Rule. This API is deprecated. Please use a PUT call to update the Namespace Authorization Rule instead.. This operation is not supported on API version 2017-04-01.

Microsoft.EventHub/namespaces/authorizationRules/delete

#
Namespace
Microsoft.EventHub

Description

Delete Namespace Authorization Rule. The Default Namespace Authorization Rule cannot be deleted.

Microsoft.EventHub/namespaces/authorizationRules/listkeys/action

#
Namespace
Microsoft.EventHub

Description

Get the Connection String to the Namespace

Microsoft.EventHub/namespaces/authorizationRules/regenerateKeys/action

#
Namespace
Microsoft.EventHub

Description

Regenerate the Primary or Secondary key to the Resource

Microsoft.EventHub/namespaces/authorizationRules/write

#
Namespace
Microsoft.EventHub

Description

Create a Namespace level Authorization Rules and update its properties. The Authorization Rules Access Rights, the Primary and Secondary Keys can be updated.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Azure Event Hub Authorization Rule Created or Updated source medium: Identifies when an Event Hub Authorization Rule is created or updated in Azure. An authorization rule is associated with specific rights, and carries a pair of cryptographic keys. When you create an Event Hubs namespace, a policy rule named RootManageSharedAccessKey is created for the namespace. This has manage permissions for the entire namespace and it's recommended that you treat this rule like an administrative root account and don't use it in your application.T1098, T1098.003, T1552, T1552.005

Microsoft.EventHub/namespaces/Delete

#
Namespace
Microsoft.EventHub

Description

Delete Namespace Resource

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.EventHub/namespaces/dwh92eef0eventhub",
    "action": "Microsoft.EventHub/namespaces/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.EventHub/namespaces/dwh92eef0eventhub",
    "action": "Microsoft.EventHub/namespaces/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "a5d21409-babe-4ee9-b9ce-2914644d604b",
  "EventDataId": "98826c98-08fa-8c0c-1843-c2ec6165117f",
  "EventSubmissionTimestamp": "2026-07-02T17:20:17.3783391Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.EVENTHUB/NAMESPACES/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.EventHub/namespaces/dwh92eef0eventhub",
    "message": "Microsoft.EventHub/namespaces/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "98826c98-08fa-8c0c-1843-c2ec6165117f",
    "eventSubmissionTimestamp": "2026-07-02T17:20:17.3783391Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0eventhub",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.EVENTHUB",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.EventHub/namespaces/dwh92eef0eventhub",
    "message": "Microsoft.EventHub/namespaces/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "98826c98-08fa-8c0c-1843-c2ec6165117f",
    "eventSubmissionTimestamp": "2026-07-02T17:20:17.3783391Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh92eef0eventhub",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.EVENTHUB",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.EVENTHUB",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.EventHub/namespaces/disasterRecoveryConfigs/action

#
Namespace
Microsoft.EventHub

Description

Checks availability of namespace alias under given subscription.

Microsoft.EventHub/namespaces/disasterRecoveryConfigs/authorizationRules/listkeys/action

#
Namespace
Microsoft.EventHub

Description

Gets the authorization rules keys for the Disaster Recovery primary namespace

Microsoft.EventHub/namespaces/disasterRecoveryConfigs/breakPairing/action

#
Namespace
Microsoft.EventHub

Description

Disables Disaster Recovery and stops replicating changes from primary to secondary namespaces.

Microsoft.EventHub/namespaces/disasterrecoveryconfigs/checkNameAvailability/action

#
Namespace
Microsoft.EventHub

Description

Checks availability of namespace alias under given subscription (Deprecated).

Microsoft.EventHub/namespaces/disasterRecoveryConfigs/delete

#
Namespace
Microsoft.EventHub

Description

Deletes the Disaster Recovery configuration associated with the namespace. This operation can only be invoked via the primary namespace.

Microsoft.EventHub/namespaces/disasterRecoveryConfigs/failover/action

#
Namespace
Microsoft.EventHub

Description

Invokes a GEO DR failover and reconfigures the namespace alias to point to the secondary namespace.

Microsoft.EventHub/namespaces/disasterRecoveryConfigs/write

#
Namespace
Microsoft.EventHub

Description

Creates or Updates the Disaster Recovery configuration associated with the namespace.

Microsoft.EventHub/namespaces/eventhubs/authorizationRules/action

#
Namespace
Microsoft.EventHub

Description

Operation to update EventHub. This operation is not supported on API version 2017-04-01. Authorization Rules. Please use a PUT call to update Authorization Rule.

Microsoft.EventHub/namespaces/eventhubs/authorizationRules/delete

#
Namespace
Microsoft.EventHub

Description

Operation to delete EventHub Authorization Rules

Microsoft.EventHub/namespaces/eventhubs/authorizationRules/listkeys/action

#
Namespace
Microsoft.EventHub

Description

Get the Connection String to EventHub

Microsoft.EventHub/namespaces/eventhubs/authorizationRules/regenerateKeys/action

#
Namespace
Microsoft.EventHub

Description

Regenerate the Primary or Secondary key to the Resource

Microsoft.EventHub/namespaces/eventhubs/authorizationRules/write

#
Namespace
Microsoft.EventHub

Description

Create EventHub Authorization Rules and Update its properties. The Authorization Rules Access. Rights can be updated.

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Failure",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "NotFound",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.EventHub/namespaces/zceh55001/eventhubs/zchub/authorizationRules/zcrule",
    "action": "Microsoft.EventHub/namespaces/eventhubs/authorizationRules/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.EventHub/namespaces/zceh55001/eventhubs/zchub/authorizationRules/zcrule",
    "action": "Microsoft.EventHub/namespaces/eventhubs/authorizationRules/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "aio": "REDACTED",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "REDACTED",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "f800272d-1f1c-4c6e-a0cb-0bfe249ee8d2",
  "EventDataId": "506340a0-f13b-6300-054f-d302eb8cc773",
  "EventSubmissionTimestamp": "2026-06-29T17:45:24.3551453Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Error",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.EVENTHUB/NAMESPACES/EVENTHUBS/AUTHORIZATIONRULES/WRITE",
  "Properties": {
    "statusCode": "NotFound",
    "serviceRequestId": "",
    "statusMessage": {
      "error": {
        "code": "EntityNotFound",
        "message": "EventHub entity does not exist"
      }
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.EventHub/namespaces/zceh55001/eventhubs/zchub/authorizationRules/zcrule",
    "message": "Microsoft.EventHub/namespaces/eventhubs/authorizationRules/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "506340a0-f13b-6300-054f-d302eb8cc773",
    "eventSubmissionTimestamp": "2026-06-29T17:45:24.3551453Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zceh55001/zchub/zcrule",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.EVENTHUB",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Failure",
    "activitySubstatusValue": "NotFound"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.EventHub/namespaces/zceh55001/eventhubs/zchub/authorizationRules/zcrule",
    "message": "Microsoft.EventHub/namespaces/eventhubs/authorizationRules/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "506340a0-f13b-6300-054f-d302eb8cc773",
    "eventSubmissionTimestamp": "2026-06-29T17:45:24.3551453Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zceh55001/zchub/zcrule",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.EVENTHUB",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Failure",
    "statusCode": "NotFound",
    "serviceRequestId": "",
    "activitySubstatusValue": "NotFound",
    "statusMessage": {
      "error": {
        "code": "EntityNotFound",
        "message": "EventHub entity does not exist"
      }
    }
  },
  "Resource": "",
  "ResourceGroup": "RG-LOGCAPTURE-GEN",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.EVENTHUB",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T17:45:24.3551453Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.eventhub/namespaces/zceh55001/eventhubs/zchub/authorizationrules/zcrule"
}

Microsoft.EventHub/namespaces/eventHubs/consumergroups/Delete

#
Namespace
Microsoft.EventHub

Description

Operation to delete ConsumerGroup Resource

Microsoft.EventHub/namespaces/eventHubs/consumergroups/write

#
Namespace
Microsoft.EventHub

Description

Create or Update ConsumerGroup properties.

Microsoft.EventHub/namespaces/eventhubs/Delete

#
Namespace
Microsoft.EventHub

Description

Operation to delete EventHub Resource

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Azure Event Hub Deleted source medium: Identifies an Event Hub deletion in Azure. An Event Hub is an event processing service that ingests and processes large volumes of events and data. An adversary may delete an Event Hub in an attempt to evade detection.T1485, T1562, T1562.008

Panther #

  • Azure Event Hub Deleted source high: Detects when an Azure Event Hub is deleted. Event Hubs are critical event processing services that ingest and process large volumes of data for log collection, SIEM ingestion, and real-time analytics. Adversaries may delete Event Hubs to evade detection by disrupting data flows and erasing evidence of their malicious activities. Deletion of Event Hubs used for security logging can blind security teams to ongoing attacks.T1562.008

Microsoft.EventHub/namespaces/eventhubs/write

#
Namespace
Microsoft.EventHub

Description

Create or Update EventHub properties.

Microsoft.EventHub/namespaces/failover/action

#
Namespace
Microsoft.EventHub

Description

Failover Namespace Resource

Microsoft.EventHub/namespaces/ipFilterRules/delete

#
Namespace
Microsoft.EventHub

Description

Delete IP Filter Resource

Microsoft.EventHub/namespaces/ipFilterRules/write

#
Namespace
Microsoft.EventHub

Description

Create IP Filter Resource

Microsoft.EventHub/namespaces/messagingPlan/write

#
Namespace
Microsoft.EventHub

Description

Updates the Messaging Plan for a namespace.<br>This API is deprecated.<br>Properties exposed via the MessagingPlan resource are moved to the (parent) Namespace resource in later API versions..<br>This operation is not supported on API version 2017-04-01.

Microsoft.EventHub/namespaces/networkruleset/delete

#
Namespace
Microsoft.EventHub

Description

Delete VNET Rule Resource

Microsoft.EventHub/namespaces/networkruleset/write

#
Namespace
Microsoft.EventHub

Description

Create VNET Rule Resource

Microsoft.EventHub/namespaces/networkrulesets/delete

#
Namespace
Microsoft.EventHub

Description

Delete VNET Rule Resource

Microsoft.EventHub/namespaces/networkrulesets/write

#
Namespace
Microsoft.EventHub

Description

Create VNET Rule Resource

Microsoft.EventHub/namespaces/networkSecurityPerimeterAssociationProxies/delete

#
Namespace
Microsoft.EventHub

Description

Delete Network Security Perimeter Association Proxy

Microsoft.EventHub/namespaces/networkSecurityPerimeterAssociationProxies/reconcile/action

#
Namespace
Microsoft.EventHub

Description

Reconcile Network Security Perimeter Association Proxy

Microsoft.EventHub/namespaces/networkSecurityPerimeterAssociationProxies/write

#
Namespace
Microsoft.EventHub

Description

Create or Update Network Security Perimeter Association Proxy

Microsoft.EventHub/namespaces/networkSecurityPerimeterConfigurations/reconcile/action

#
Namespace
Microsoft.EventHub

Description

Reconcile Network Security Perimeter Configurations

Microsoft.EventHub/namespaces/privateEndpointConnectionProxies/delete

#
Namespace
Microsoft.EventHub

Description

Delete Private Endpoint Connection Proxy

Microsoft.EventHub/namespaces/privateEndpointConnectionProxies/validate/action

#
Namespace
Microsoft.EventHub

Description

Validate Private Endpoint Connection Proxy

Microsoft.EventHub/namespaces/privateEndpointConnectionProxies/write

#
Namespace
Microsoft.EventHub

Description

Create Private Endpoint Connection Proxy

Microsoft.EventHub/namespaces/privateEndpointConnections/delete

#
Namespace
Microsoft.EventHub

Description

Removes Private Endpoint Connection

Microsoft.EventHub/namespaces/privateEndpointConnections/write

#
Namespace
Microsoft.EventHub

Description

Create or Update Private Endpoint Connection

Microsoft.EventHub/namespaces/privateEndpointConnectionsApproval/action

#
Namespace
Microsoft.EventHub

Description

Approve Private Endpoint Connection

Microsoft.EventHub/namespaces/providers/Microsoft.Insights/diagnosticSettings/write

#
Namespace
Microsoft.EventHub

Description

Get list of Namespace diagnostic settings Resource Descriptions

Microsoft.EventHub/namespaces/removeAcsNamepsace/action

#
Namespace
Microsoft.EventHub

Description

Remove ACS namespace

Microsoft.EventHub/namespaces/schemagroups/delete

#
Namespace
Microsoft.EventHub

Description

Operation to delete SchemaGroup Resource

Microsoft.EventHub/namespaces/schemagroups/write

#
Namespace
Microsoft.EventHub

Description

Create or Update SchemaGroup properties.

Microsoft.EventHub/namespaces/updateState/action

#
Namespace
Microsoft.EventHub

Description

UpdateNamespaceState

Microsoft.EventHub/namespaces/virtualNetworkRules/delete

#
Namespace
Microsoft.EventHub

Description

Delete VNET Rule Resource

Microsoft.EventHub/namespaces/virtualNetworkRules/write

#
Namespace
Microsoft.EventHub

Description

Create VNET Rule Resource

Microsoft.EventHub/namespaces/write

#
Namespace
Microsoft.EventHub

Description

Create a Namespace Resource and Update its properties. Tags and Capacity of the Namespace are the properties which can be updated.

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Success",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.EventHub/namespaces/zceh55001",
    "action": "Microsoft.EventHub/namespaces/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.EventHub/namespaces/zceh55001",
    "action": "Microsoft.EventHub/namespaces/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "aio": "REDACTED",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "REDACTED",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "f3cb742e-cd33-48e1-aa8a-afdf83f75f47",
  "EventDataId": "9bf9799d-ec50-ccc3-7a5f-0c2a1b054d9c",
  "EventSubmissionTimestamp": "2026-06-29T17:45:20.7797653Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.EVENTHUB/NAMESPACES/WRITE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.EventHub/namespaces/zceh55001",
    "message": "Microsoft.EventHub/namespaces/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "9bf9799d-ec50-ccc3-7a5f-0c2a1b054d9c",
    "eventSubmissionTimestamp": "2026-06-29T17:45:20.7797653Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zceh55001",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.EVENTHUB",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.EventHub/namespaces/zceh55001",
    "message": "Microsoft.EventHub/namespaces/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "9bf9799d-ec50-ccc3-7a5f-0c2a1b054d9c",
    "eventSubmissionTimestamp": "2026-06-29T17:45:20.7797653Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zceh55001",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.EVENTHUB",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Resource": "",
  "ResourceGroup": "RG-LOGCAPTURE-GEN",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.EVENTHUB",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T17:45:20.7797653Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.eventhub/namespaces/zceh55001"
}

Microsoft.EventHub/register/action

#
Namespace
Microsoft.EventHub

Description

Registers the subscription for the EventHub resource provider and enables the creation of EventHub resources

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Success",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "OK",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
    "action": "Microsoft.EventHub/register/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
    "action": "Microsoft.EventHub/register/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "aio": "REDACTED",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "REDACTED",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "5954ebc4-f7e4-4c60-b1b6-34d7546563a0",
  "EventDataId": "e7f29c6c-ecc8-ac83-d576-ddafbd80d76d",
  "EventSubmissionTimestamp": "2026-06-29T17:43:23.5836238Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.EVENTHUB/REGISTER/ACTION",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.EventHub",
    "message": "Microsoft.EventHub/register/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "e7f29c6c-ecc8-ac83-d576-ddafbd80d76d",
    "eventSubmissionTimestamp": "2026-06-29T17:43:23.5836238Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resourceProviderValue": "MICROSOFT.EVENTHUB",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.EventHub",
    "message": "Microsoft.EventHub/register/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "e7f29c6c-ecc8-ac83-d576-ddafbd80d76d",
    "eventSubmissionTimestamp": "2026-06-29T17:43:23.5836238Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resourceProviderValue": "MICROSOFT.EVENTHUB",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "OK",
    "serviceRequestId": "",
    "activitySubstatusValue": "OK"
  },
  "Resource": "",
  "ResourceGroup": "",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.EVENTHUB",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T17:43:23.5836238Z",
  "Type": "AzureActivity",
  "_ResourceId": ""
}

Microsoft.EventHub/unregister/action

#
Namespace
Microsoft.EventHub

Description

Registers the EventHub Resource Provider

References #