Azure Monitor Azure-Microsoft.Insights
any: Azure Monitor (catch-all)
#Description
Catch-all for Azure-Microsoft.Insights rules that match the resource provider but no specific operation.
Microsoft.Insights/ActionGroups/Delete
#Description
Delete an action group
Example Resource Log Record #
{
"ActivityStatus": "",
"ActivityStatusValue": "Success",
"ActivitySubstatus": "",
"ActivitySubstatusValue": "",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/actionGroups/zcag2",
"action": "Microsoft.Insights/actionGroups/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/actionGroups/zcag2",
"action": "Microsoft.Insights/actionGroups/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"Category": "",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782752670",
"nbf": "1782752670",
"exp": "1782756583",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "3 5",
"xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
"xms_idrel": "1 2",
"xms_sub_fct": "2 3",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782752670",
"nbf": "1782752670",
"exp": "1782756583",
"aio": "REDACTED",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "REDACTED",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "3 5",
"xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
"xms_idrel": "1 2",
"xms_sub_fct": "2 3",
"xms_tcdt": "1768616282",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "c63f8086-9a88-4dbd-984a-178474cc29de",
"EventDataId": "9695b7cb-59b8-15ff-19fd-076adcdfd260",
"EventSubmissionTimestamp": "2026-06-29T18:12:09.9433398Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationId": "",
"OperationName": "",
"OperationNameValue": "MICROSOFT.INSIGHTS/ACTIONGROUPS/DELETE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Insights/actiongroups/zcag2",
"message": "Microsoft.Insights/actiongroups/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "9695b7cb-59b8-15ff-19fd-076adcdfd260",
"eventSubmissionTimestamp": "2026-06-29T18:12:09.9433398Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcag2",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.INSIGHTS",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Insights/actiongroups/zcag2",
"message": "Microsoft.Insights/actiongroups/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "9695b7cb-59b8-15ff-19fd-076adcdfd260",
"eventSubmissionTimestamp": "2026-06-29T18:12:09.9433398Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcag2",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.INSIGHTS",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Resource": "",
"ResourceGroup": "RG-LOGCAPTURE-GEN",
"ResourceId": "",
"ResourceProvider": "",
"ResourceProviderValue": "MICROSOFT.INSIGHTS",
"SourceSystem": "Azure",
"SubscriptionId": "22222222-2222-2222-2222-222222222222",
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T18:12:09.9433398Z",
"Type": "AzureActivity",
"_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.insights/actiongroups/zcag2"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
resultType (panther rule field) | in | Succeeded | 1 rule | panther |
resultType (panther rule field) | in | Success | 1 rule | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1562.008
Microsoft.Insights/actionGroups/NetworkSecurityPerimeterAssociationProxies/Delete
#Description
Delete a action group endpoint NSP association proxy
Microsoft.Insights/actionGroups/NetworkSecurityPerimeterAssociationProxies/Write
#Description
Create or update a action group endpoint NSP association proxy
Microsoft.Insights/actionGroups/NetworkSecurityPerimeterConfigurations/Reconcile/Action
#Description
Reconcile action group endpoint NSP configuration
Microsoft.Insights/ActionGroups/Write
#Description
Create or update an action group
Example Resource Log Record #
{
"ActivityStatus": "",
"ActivityStatusValue": "Success",
"ActivitySubstatus": "",
"ActivitySubstatusValue": "Created",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/actionGroups/zcag3",
"action": "Microsoft.Insights/actionGroups/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/actionGroups/zcag3",
"action": "Microsoft.Insights/actionGroups/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"Category": "",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782755989",
"nbf": "1782755989",
"exp": "1782761191",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "5 3",
"xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
"xms_idrel": "1 8",
"xms_sub_fct": "14 3",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782755989",
"nbf": "1782755989",
"exp": "1782761191",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "5 3",
"xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
"xms_idrel": "1 8",
"xms_sub_fct": "14 3",
"xms_tcdt": "1768616282"
},
"CorrelationId": "7320fc66-2dab-4845-b9a0-1ed991a8dda5",
"EventDataId": "c19ad471-0e91-0930-d975-024e1f8418b5",
"EventSubmissionTimestamp": "2026-06-29T19:04:03.3565667Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationId": "",
"OperationName": "",
"OperationNameValue": "MICROSOFT.INSIGHTS/ACTIONGROUPS/WRITE",
"Properties": {
"statusCode": "Created",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/actionGroups/zcag3",
"message": "Microsoft.Insights/actionGroups/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "c19ad471-0e91-0930-d975-024e1f8418b5",
"eventSubmissionTimestamp": "2026-06-29T19:04:03.3565667Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcag3",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.INSIGHTS",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "Created"
},
"Properties_d": {
"statusCode": "Created",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/actionGroups/zcag3",
"message": "Microsoft.Insights/actionGroups/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "c19ad471-0e91-0930-d975-024e1f8418b5",
"eventSubmissionTimestamp": "2026-06-29T19:04:03.3565667Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "zcag3",
"resourceGroup": "RG-LOGCAPTURE-GEN",
"resourceProviderValue": "MICROSOFT.INSIGHTS",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "Created"
},
"Resource": "",
"ResourceGroup": "RG-LOGCAPTURE-GEN",
"ResourceId": "",
"ResourceProvider": "",
"ResourceProviderValue": "MICROSOFT.INSIGHTS",
"SourceSystem": "Azure",
"SubscriptionId": "22222222-2222-2222-2222-222222222222",
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T19:04:03.3565667Z",
"Type": "AzureActivity",
"_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.insights/actiongroups/zcag3"
}
Microsoft.Insights/ActivityLogAlerts/Activated/Action
#Description
Activity Log Alert activated
Example Resource Log Record #
{
"ActivityStatus": "",
"ActivityStatusValue": "Succeeded",
"ActivitySubstatus": "",
"ActivitySubstatusValue": "",
"Authorization": "",
"Authorization_d": "None",
"Caller": "",
"CallerIpAddress": "",
"Category": "",
"CategoryValue": "Alert",
"Claims": "",
"Claims_d": "None",
"CorrelationId": "9c77ebc7-44a9-4722-b0f8-0bc0db8411b4",
"EventDataId": "6f795318-4f00-42c1-955f-28e4d2addeea",
"EventSubmissionTimestamp": "2026-06-29T18:07:10.8340215Z",
"HTTPRequest": "",
"Hierarchy": "",
"Level": "Informational",
"OperationId": "",
"OperationName": "",
"OperationNameValue": "Microsoft.Insights/ActivityLogAlerts/Activated/action",
"Properties": {
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"tenantId": "11111111-1111-1111-1111-111111111111",
"eventDataId": "6f795318-4f00-42c1-955f-28e4d2addeea",
"resourceGroup": "rg-logcapture-gen",
"resourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Resources/deployments/vm_deploy_6hWz04CZWJL8g6USfIXNheOnqPcWQAd6",
"eventTimestamp": "6/29/2026 6:02:38 PM",
"operationName": "Microsoft.Resources/deployments/write",
"status": "Started",
"eventSubmissionTimestamp": "2026-06-29T18:07:10.8340215Z",
"resource": "zcala",
"resourceProviderValue": "microsoft.insights",
"activityStatusValue": "Succeeded"
},
"Properties_d": {
"eventDataId": "6f795318-4f00-42c1-955f-28e4d2addeea",
"eventSubmissionTimestamp": "2026-06-29T18:07:10.8340215Z",
"resource": "zcala",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "microsoft.insights",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Succeeded",
"tenantId": "11111111-1111-1111-1111-111111111111",
"resourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Resources/deployments/vm_deploy_6hWz04CZWJL8g6USfIXNheOnqPcWQAd6",
"eventTimestamp": "6/29/2026 6:02:38 PM",
"operationName": "Microsoft.Resources/deployments/write",
"status": "Started"
},
"Resource": "",
"ResourceGroup": "rg-logcapture-gen",
"ResourceId": "",
"ResourceProvider": "",
"ResourceProviderValue": "microsoft.insights",
"SourceSystem": "Azure",
"SubscriptionId": "22222222-2222-2222-2222-222222222222",
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T18:07:10.8340215Z",
"Type": "AzureActivity",
"_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.insights/activitylogalerts/zcala"
}
Microsoft.Insights/ActivityLogAlerts/Delete
#Description
Delete an activity log alert
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"ActivitySubstatusValue": "NoContent",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/activityLogAlerts/dwhp3bbd4cala",
"action": "Microsoft.Insights/activityLogAlerts/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/activityLogAlerts/dwhp3bbd4cala",
"action": "Microsoft.Insights/activityLogAlerts/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783045937",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783045937",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "ec30e150-ad20-418f-8058-3a2fdfcae8f2",
"EventDataId": "2236da13-157c-52b4-5d54-b64fb123168d",
"EventSubmissionTimestamp": "2026-07-03T01:48:26.4397449Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.INSIGHTS/ACTIVITYLOGALERTS/DELETE",
"Properties": {
"statusCode": "NoContent",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/activityLogAlerts/dwhp3bbd4cala",
"message": "Microsoft.Insights/activityLogAlerts/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "2236da13-157c-52b4-5d54-b64fb123168d",
"eventSubmissionTimestamp": "2026-07-03T01:48:26.4397449Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwhp3bbd4cala",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.INSIGHTS",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "NoContent"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/activityLogAlerts/dwhp3bbd4cala",
"message": "Microsoft.Insights/activityLogAlerts/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "2236da13-157c-52b4-5d54-b64fb123168d",
"eventSubmissionTimestamp": "2026-07-03T01:48:26.4397449Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwhp3bbd4cala",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.INSIGHTS",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"statusCode": "NoContent",
"serviceRequestId": "",
"activitySubstatusValue": "NoContent"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.INSIGHTS",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
Microsoft.Insights/ActivityLogAlerts/Write
#Description
Create or update an activity log alert
Example Resource Log Record #
{
"ActivityStatusValue": "Failure",
"ActivitySubstatusValue": "BadRequest",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/activityLogAlerts/dwhp3bbd4cala",
"action": "Microsoft.Insights/activityLogAlerts/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/activityLogAlerts/dwhp3bbd4cala",
"action": "Microsoft.Insights/activityLogAlerts/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783057703",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"correlationid": "00b19dbe-ce18-40ce-9099-2c45321389fb"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783057703",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"correlationid": "00b19dbe-ce18-40ce-9099-2c45321389fb",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "00b19dbe-ce18-40ce-9099-2c45321389fb",
"EventDataId": "e00b1a76-80f5-702c-e9bf-9138c3dd1cdb",
"EventSubmissionTimestamp": "2026-07-03T01:48:24.8572803Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Error",
"OperationNameValue": "MICROSOFT.INSIGHTS/ACTIVITYLOGALERTS/WRITE",
"Properties": {
"statusCode": "BadRequest",
"serviceRequestId": "",
"statusMessage": {
"code": "UnsupportedCondition",
"message": "Alert Rule with category 'Administrative' and subscription scope must have at least one additional filtering condition. Activity ID: 00b19dbe-ce18-40ce-9099-2c45321389fb."
},
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/activityLogAlerts/dwhp3bbd4cala",
"message": "Microsoft.Insights/activityLogAlerts/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "e00b1a76-80f5-702c-e9bf-9138c3dd1cdb",
"eventSubmissionTimestamp": "2026-07-03T01:48:24.8572803Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwhp3bbd4cala",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.INSIGHTS",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Failure",
"activitySubstatusValue": "BadRequest"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/activityLogAlerts/dwhp3bbd4cala",
"message": "Microsoft.Insights/activityLogAlerts/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "e00b1a76-80f5-702c-e9bf-9138c3dd1cdb",
"eventSubmissionTimestamp": "2026-07-03T01:48:24.8572803Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwhp3bbd4cala",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.INSIGHTS",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Failure",
"statusCode": "BadRequest",
"serviceRequestId": "",
"activitySubstatusValue": "BadRequest",
"statusMessage": {
"code": "UnsupportedCondition",
"message": "Alert Rule with category 'Administrative' and subscription scope must have at least one additional filtering condition. Activity ID: 00b19dbe-ce18-40ce-9099-2c45321389fb."
}
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.INSIGHTS",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
Microsoft.Insights/AlertRules/Activated/Action
#Description
Classic metric alert activated
Microsoft.Insights/AlertRules/Delete
#Description
Delete a classic metric alert
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
resultType (panther rule field) | in | Succeeded | 1 rule | panther |
resultType (panther rule field) | in | Success | 1 rule | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1562.008↳ also matches Microsoft.Insights/MetricAlerts/Delete
Microsoft.Insights/AlertRules/Resolved/Action
#Description
Classic metric alert resolved
Microsoft.Insights/AlertRules/Throttled/Action
#Description
Classic metric alert rule throttled
Microsoft.Insights/AlertRules/Write
#Description
Create or update a classic metric alert
Microsoft.Insights/AutoscaleSettings/Delete
#Description
Delete an autoscale setting
Microsoft.Insights/AutoscaleSettings/PredictiveScaleup/Action
#Description
Predictive Autoscale scale up initiated
Microsoft.Insights/AutoscaleSettings/PredictiveScaleupResult/Action
#Description
Predictive Autoscale scale up completed
Microsoft.Insights/AutoscaleSettings/providers/Microsoft.Insights/diagnosticSettings/Write
#Description
Create or update a resource diagnostic setting
Microsoft.Insights/AutoscaleSettings/Scaledown/Action
#Description
Autoscale scale down initiated
Microsoft.Insights/AutoscaleSettings/ScaledownResult/Action
#Description
Autoscale scale down completed
Microsoft.Insights/AutoscaleSettings/Scaleup/Action
#Description
Autoscale scale up initiated
Microsoft.Insights/AutoscaleSettings/ScaleupResult/Action
#Description
Autoscale scale up completed
Microsoft.Insights/AutoscaleSettings/Write
#Description
Create or update an autoscale setting
Microsoft.Insights/Components/AnalyticsItems/Delete
#Description
Deleting an Application Insights analytics item
Microsoft.Insights/Components/AnalyticsItems/Write
#Description
Writing an Application Insights analytics item
Microsoft.Insights/Components/AnalyticsTables/Action
#Description
Application Insights analytics table action
Microsoft.Insights/Components/AnalyticsTables/Delete
#Description
Deleting an Application Insights analytics table schema
Microsoft.Insights/Components/AnalyticsTables/Write
#Description
Writing an Application Insights analytics table schema
Microsoft.Insights/Components/Annotations/Delete
#Description
Deleting an Application Insights annotation
Microsoft.Insights/Components/Annotations/Write
#Description
Writing an Application Insights annotation
Microsoft.Insights/Components/ApiKeys/Action
#Description
Generating an Application Insights API key
Microsoft.Insights/Components/ApiKeys/Delete
#Description
Deleting an Application Insights API key
Microsoft.Insights/Components/CurrentBillingFeatures/Write
#Description
Writing current billing features for Application Insights component
Microsoft.Insights/Components/DailyCapReached/Action
#Description
Reached the daily cap for Application Insights component
Microsoft.Insights/Components/DailyCapWarningThresholdReached/Action
#Description
Reached the daily cap warning threshold for Application Insights component
Microsoft.Insights/Components/Delete
#Description
Deleting an application insights component configuration
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/components/dwhc6a93dappinsights",
"action": "Microsoft.Insights/components/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/components/dwhc6a93dappinsights",
"action": "Microsoft.Insights/components/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783045937",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783045937",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"CorrelationId": "c7ffb16b-7e03-405f-811b-5d1b43c880f1",
"EventDataId": "58a10880-1899-b537-e31a-27f1253b20a2",
"EventSubmissionTimestamp": "2026-07-03T02:26:12.9041359Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.INSIGHTS/COMPONENTS/DELETE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Insights/components/dwhc6a93dappinsights",
"message": "Microsoft.Insights/components/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "58a10880-1899-b537-e31a-27f1253b20a2",
"eventSubmissionTimestamp": "2026-07-03T02:26:12.9041359Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwhc6a93dappinsights",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.INSIGHTS",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Insights/components/dwhc6a93dappinsights",
"message": "Microsoft.Insights/components/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "58a10880-1899-b537-e31a-27f1253b20a2",
"eventSubmissionTimestamp": "2026-07-03T02:26:12.9041359Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwhc6a93dappinsights",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.INSIGHTS",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.INSIGHTS",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
Microsoft.Insights/Components/ExportConfiguration/Action
#Description
Application Insights export settings action
Microsoft.Insights/Components/ExportConfiguration/Delete
#Description
Deleting Application Insights export settings
Microsoft.Insights/Components/ExportConfiguration/Write
#Description
Writing Application Insights export settings
Microsoft.Insights/Components/Favorites/Delete
#Description
Deleting an Application Insights favorite
Microsoft.Insights/Components/Favorites/Write
#Description
Writing an Application Insights favorite
Microsoft.Insights/Components/linkedStorageAccounts/Write
#Description
Create or modify linked storage account
Microsoft.Insights/Components/Move/Action
#Description
Move an Application Insights Component to another resource group or subscription
Microsoft.Insights/Components/MyAnalyticsItems/Delete
#Description
Deleting an Application Insights personal analytics item
Microsoft.Insights/Components/MyAnalyticsItems/Write
#Description
Writing an Application Insights personal analytics item
Microsoft.Insights/Components/PricingPlans/Write
#Description
Writing an Application Insights component pricing plan
Microsoft.Insights/Components/ProactiveDetectionConfigs/Write
#Description
Writing Application Insights proactive detection configuration
Microsoft.Insights/Components/providers/Microsoft.Insights/diagnosticSettings/Write
#Description
Create or update a resource diagnostic setting
Microsoft.Insights/Components/Purge/Action
#Description
Purging data from Application Insights
Microsoft.Insights/Components/WorkItemConfigs/Delete
#Description
Deleting an Application Insights ALM integration configuration
Microsoft.Insights/Components/WorkItemConfigs/Write
#Description
Writing an Application Insights ALM integration configuration
Microsoft.Insights/Components/Write
#Description
Writing to an application insights component configuration
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"ActivitySubstatusValue": "OK",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/components/dwhc6a93dappinsights",
"action": "Microsoft.Insights/components/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/components/dwhc6a93dappinsights",
"action": "Microsoft.Insights/components/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783059369",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"correlationid": "8b954797-dd76-4f9e-a599-9313c9f4beeb"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783059369",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"correlationid": "8b954797-dd76-4f9e-a599-9313c9f4beeb"
},
"CorrelationId": "8b954797-dd76-4f9e-a599-9313c9f4beeb",
"EventDataId": "e34e64cc-7f04-95f1-92f2-635c460f8355",
"EventSubmissionTimestamp": "2026-07-03T02:16:10.9068058Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.INSIGHTS/COMPONENTS/WRITE",
"Properties": {
"statusCode": "OK",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/components/dwhc6a93dappinsights",
"message": "Microsoft.Insights/components/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "e34e64cc-7f04-95f1-92f2-635c460f8355",
"eventSubmissionTimestamp": "2026-07-03T02:16:10.9068058Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwhc6a93dappinsights",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.INSIGHTS",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"Properties_d": {
"statusCode": "OK",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/components/dwhc6a93dappinsights",
"message": "Microsoft.Insights/components/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "e34e64cc-7f04-95f1-92f2-635c460f8355",
"eventSubmissionTimestamp": "2026-07-03T02:16:10.9068058Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwhc6a93dappinsights",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.INSIGHTS",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.INSIGHTS",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
Microsoft.Insights/CreateNotifications/Write
#Description
Send test notifications to the provided receiver list
Microsoft.Insights/DataCollectionEndpoints/Delete
#Description
Delete a data collection endpoint
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/dataCollectionEndpoints/dwhc6a93ddcendpoint",
"action": "Microsoft.Insights/dataCollectionEndpoints/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/dataCollectionEndpoints/dwhc6a93ddcendpoint",
"action": "Microsoft.Insights/dataCollectionEndpoints/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783045937",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783045937",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"CorrelationId": "89a2a8a6-f3d1-4ef8-a7ae-9be55d31329a",
"EventDataId": "72ab3977-13b3-5d84-14a8-61b602bc7e0a",
"EventSubmissionTimestamp": "2026-07-03T02:26:07.9372506Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.INSIGHTS/DATACOLLECTIONENDPOINTS/DELETE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Insights/dataCollectionEndpoints/dwhc6a93ddcendpoint",
"message": "Microsoft.Insights/dataCollectionEndpoints/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "72ab3977-13b3-5d84-14a8-61b602bc7e0a",
"eventSubmissionTimestamp": "2026-07-03T02:26:07.9372506Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwhc6a93ddcendpoint",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.INSIGHTS",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Insights/dataCollectionEndpoints/dwhc6a93ddcendpoint",
"message": "Microsoft.Insights/dataCollectionEndpoints/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "72ab3977-13b3-5d84-14a8-61b602bc7e0a",
"eventSubmissionTimestamp": "2026-07-03T02:26:07.9372506Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwhc6a93ddcendpoint",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.INSIGHTS",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.INSIGHTS",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
Microsoft.Insights/DataCollectionEndpoints/NetworkSecurityPerimeterAssociationProxies/Delete
#Description
Delete a data collection endpoint NSP association proxy
Microsoft.Insights/DataCollectionEndpoints/NetworkSecurityPerimeterAssociationProxies/Write
#Description
Create or update a data collection endpoint NSP association proxy
Microsoft.Insights/DataCollectionEndpoints/NetworkSecurityPerimeterConfigurations/Reconcile/Action
#Description
Reconcile data collection endpoint NSP configuration
Microsoft.Insights/DataCollectionEndpoints/ScopedPrivateLinkProxies/Delete
#Description
Delete a data collection endpoint private link proxy
Microsoft.Insights/DataCollectionEndpoints/ScopedPrivateLinkProxies/Write
#Description
Create or update a data collection endpoint private link proxy
Microsoft.Insights/DataCollectionEndpoints/TriggerFailback/Action
#Description
Trigger failback on a data collection endpoint
Microsoft.Insights/DataCollectionEndpoints/TriggerFailover/Action
#Description
Trigger failover on a data collection endpoint
Microsoft.Insights/DataCollectionEndpoints/Write
#Description
Create or update a data collection endpoint
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"ActivitySubstatusValue": "OK",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/dataCollectionEndpoints/dwhc6a93ddcendpoint",
"action": "Microsoft.Insights/dataCollectionEndpoints/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/dataCollectionEndpoints/dwhc6a93ddcendpoint",
"action": "Microsoft.Insights/dataCollectionEndpoints/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783059363",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"correlationid": "0088c8b5-cc1c-4c1b-871e-f9524f329182"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783041418",
"nbf": "1783041418",
"exp": "1783059363",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "tUdFU6nO4UmtUjpbHDqEAA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "3 5",
"xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
"xms_idrel": "1 6",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"correlationid": "0088c8b5-cc1c-4c1b-871e-f9524f329182"
},
"CorrelationId": "0088c8b5-cc1c-4c1b-871e-f9524f329182",
"EventDataId": "6def0f04-addb-deaf-a9c1-86c8429218f5",
"EventSubmissionTimestamp": "2026-07-03T02:16:05.1121772Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.INSIGHTS/DATACOLLECTIONENDPOINTS/WRITE",
"Properties": {
"statusCode": "OK",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/dataCollectionEndpoints/dwhc6a93ddcendpoint",
"message": "Microsoft.Insights/dataCollectionEndpoints/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "6def0f04-addb-deaf-a9c1-86c8429218f5",
"eventSubmissionTimestamp": "2026-07-03T02:16:05.1121772Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwhc6a93ddcendpoint",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.INSIGHTS",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"Properties_d": {
"statusCode": "OK",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/dataCollectionEndpoints/dwhc6a93ddcendpoint",
"message": "Microsoft.Insights/dataCollectionEndpoints/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "6def0f04-addb-deaf-a9c1-86c8429218f5",
"eventSubmissionTimestamp": "2026-07-03T02:16:05.1121772Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwhc6a93ddcendpoint",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.INSIGHTS",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "OK"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.INSIGHTS",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
Microsoft.Insights/DataCollectionRuleAssociations/Delete
#Description
Delete a resource's association with a data collection rule
Microsoft.Insights/DataCollectionRuleAssociations/Write
#Description
Create or update a resource's association with a data collection rule
Microsoft.Insights/DataCollectionRules/Delete
#Description
Delete a data collection rule
Microsoft.Insights/DataCollectionRules/Write
#Description
Create or update a data collection rule
Microsoft.Insights/DiagnosticSettings/Delete
#Description
Delete a resource diagnostic setting
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1562, T1562.001, T1562.008Kusto #
T1562, T1562.008Panther #
T1562.008
Microsoft.Insights/DiagnosticSettings/Write
#Description
Create or update a resource diagnostic setting
Example Resource Log Record #
{
"ActivityStatus": "",
"ActivityStatusValue": "Failure",
"ActivitySubstatus": "",
"ActivitySubstatusValue": "Conflict",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/microsoft.insights/diagnosticSettings/ds-activity-law",
"action": "microsoft.insights/diagnosticSettings/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/microsoft.insights/diagnosticSettings/ds-activity-law",
"action": "microsoft.insights/diagnosticSettings/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"Category": "",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782752670",
"nbf": "1782752670",
"exp": "1782756583",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "REDACTED",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "REDACTED",
"rh": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "3 5",
"xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
"xms_idrel": "1 2",
"xms_sub_fct": "2 3",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1782752670",
"nbf": "1782752670",
"exp": "1782756583",
"aio": "REDACTED",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "REDACTED",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "REDACTED",
"ver": "1.0",
"wids": "REDACTED",
"xms_act_fct": "3 5",
"xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
"xms_idrel": "1 2",
"xms_sub_fct": "2 3",
"xms_tcdt": "1768616282",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "REDACTED",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "36cd279a-8b0f-4968-a146-f0d5139a9aa0",
"EventDataId": "3785540e-1413-da5a-18f2-6fed02440c71",
"EventSubmissionTimestamp": "2026-06-29T17:17:35.9549633Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Error",
"OperationId": "",
"OperationName": "",
"OperationNameValue": "MICROSOFT.INSIGHTS/DIAGNOSTICSETTINGS/WRITE",
"Properties": {
"statusCode": "Conflict",
"serviceRequestId": "",
"statusMessage": {
"code": "InvalidAuthenticationToken",
"message": "Please register the subscription '22222222-2222-2222-2222-222222222222' with Microsoft.Insights."
},
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/microsoft.insights/diagnosticSettings/ds-activity-law",
"message": "microsoft.insights/diagnosticSettings/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "3785540e-1413-da5a-18f2-6fed02440c71",
"eventSubmissionTimestamp": "2026-06-29T17:17:35.9549633Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "ds-activity-law",
"resourceProviderValue": "MICROSOFT.INSIGHTS",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Failure",
"activitySubstatusValue": "Conflict"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/microsoft.insights/diagnosticSettings/ds-activity-law",
"message": "microsoft.insights/diagnosticSettings/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "3785540e-1413-da5a-18f2-6fed02440c71",
"eventSubmissionTimestamp": "2026-06-29T17:17:35.9549633Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "ds-activity-law",
"resourceProviderValue": "MICROSOFT.INSIGHTS",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Failure",
"statusCode": "Conflict",
"serviceRequestId": "",
"activitySubstatusValue": "Conflict",
"statusMessage": {
"code": "InvalidAuthenticationToken",
"message": "Please register the subscription '22222222-2222-2222-2222-222222222222' with Microsoft.Insights."
}
},
"Resource": "",
"ResourceGroup": "",
"ResourceId": "",
"ResourceProvider": "",
"ResourceProviderValue": "MICROSOFT.INSIGHTS",
"SourceSystem": "Azure",
"SubscriptionId": "22222222-2222-2222-2222-222222222222",
"TenantId": "00000000-0000-0000-0000-000000000000",
"TimeGenerated": "2026-06-29T17:17:35.9549633Z",
"Type": "AzureActivity",
"_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/microsoft.insights/diagnosticsettings/ds-activity-law"
}
Microsoft.Insights/ExtendedDiagnosticSettings/Delete
#Description
Delete a network flow log diagnostic setting
Microsoft.Insights/ExtendedDiagnosticSettings/Write
#Description
Create or update a network flow log diagnostic setting
Microsoft.Insights/ListMigrationDate/Action
#Description
Get back Subscription migration date
Microsoft.Insights/LogProfiles/Delete
#Description
Delete an Activity Log log profile
Microsoft.Insights/LogProfiles/Write
#Description
Create or update an Activity Log log profile
Microsoft.Insights/MetricAlerts/Delete
#Description
Delete a metric alert
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
resultType (panther rule field) | in | Succeeded | 1 rule | panther |
resultType (panther rule field) | in | Success | 1 rule | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1562.008↳ also matches Microsoft.Insights/AlertRules/Delete
Microsoft.Insights/MetricAlerts/Write
#Description
Create or update a metric alert
Microsoft.Insights/Metrics/Action
#Description
Metric Action
Microsoft.Insights/MigrateToNewpricingModel/Action
#Description
Migrate subscription to new pricing model
Microsoft.Insights/MonitoredObjects/Delete
#Description
Delete a monitored object
Microsoft.Insights/MonitoredObjects/Write
#Description
Create or update a monitored object
Microsoft.Insights/PrivateLinkScopes/Delete
#Description
Delete a private link scope
Microsoft.Insights/PrivateLinkScopes/PrivateEndpointConnectionProxies/Delete
#Description
Delete a private endpoint connection proxy
Microsoft.Insights/PrivateLinkScopes/PrivateEndpointConnectionProxies/Validate/Action
#Description
Validate a private endpoint connection proxy
Microsoft.Insights/PrivateLinkScopes/PrivateEndpointConnectionProxies/Write
#Description
Create or update a private endpoint connection proxy
Microsoft.Insights/PrivateLinkScopes/PrivateEndpointConnections/Delete
#Description
Delete a private endpoint connection
Microsoft.Insights/PrivateLinkScopes/PrivateEndpointConnections/Write
#Description
Create or update a private endpoint connection
Microsoft.Insights/PrivateLinkScopes/PrivateEndpointConnectionsApproval/action
#Description
Approve or reject a connection to a Private Endpoint resource of Microsoft.Network provider
Microsoft.Insights/PrivateLinkScopes/ScopedResources/Delete
#Description
Delete a private link scoped resource
Microsoft.Insights/PrivateLinkScopes/ScopedResources/Write
#Description
Create or update a private link scoped resource
Microsoft.Insights/PrivateLinkScopes/Write
#Description
Create or update a private link scope
Microsoft.Insights/Register/Action
#Description
Register the Microsoft Insights provider
Microsoft.Insights/RollbackToLegacyPricingModel/Action
#Description
Rollback subscription to legacy pricing model
Microsoft.Insights/ScheduledQueryRules/Delete
#Description
Deleting a scheduled query rule
Microsoft.Insights/ScheduledQueryRules/NetworkSecurityPerimeterAssociationProxies/Delete
#Description
Deleting a network security perimeter association proxy for scheduled query rules
Microsoft.Insights/ScheduledQueryRules/NetworkSecurityPerimeterAssociationProxies/Write
#Description
Writing a network security perimeter association proxy for scheduled query rules
Microsoft.Insights/ScheduledQueryRules/networkSecurityPerimeterConfigurations/Reconcile/Action
#Description
Reconciling network security perimeter configuration for scheduled query rules
Microsoft.Insights/ScheduledQueryRules/Write
#Description
Writing a scheduled query rule
Microsoft.Insights/TenantActionGroups/Delete
#Description
Delete a tenant action group
Microsoft.Insights/TenantActionGroups/Write
#Description
Create or update a tenant action group
Microsoft.Insights/Tenants/Register/Action
#Description
Initializes the Microsoft Insights provider
Microsoft.Insights/Unregister/Action
#Description
Register the Microsoft Insights provider
Microsoft.Insights/Webtests/Delete
#Description
Deleting a webtest configuration
Microsoft.Insights/Webtests/Write
#Description
Writing to a webtest configuration
Microsoft.Insights/Workbooks/Delete
#Description
Delete a workbook
Microsoft.Insights/Workbooks/Write
#Description
Create or update a workbook
Microsoft.Insights/WorkbookTemplates/Delete
#Description
Delete a workbook template
Microsoft.Insights/WorkbookTemplates/Write
#Description
Create or update a workbook template