Azure Monitor Azure-Microsoft.Insights

operationNameDescriptionSampleRule
anyCatch-all for Azure-Microsoft.Insights rules that match the resource provider but no specific operation.NN
Microsoft.Insights/ActionGroups/DeleteDelete an action groupYY
Microsoft.Insights/actionGroups/NetworkSecurityPerimeterAssociationProxies/DeleteDelete a action group endpoint NSP association proxyNN
Microsoft.Insights/actionGroups/NetworkSecurityPerimeterAssociationProxies/WriteCreate or update a action group endpoint NSP association proxyNN
Microsoft.Insights/actionGroups/NetworkSecurityPerimeterConfigurations/Reconcile/ActionReconcile action group endpoint NSP configurationNN
Microsoft.Insights/ActionGroups/WriteCreate or update an action groupYN
Microsoft.Insights/ActivityLogAlerts/Activated/ActionActivity Log Alert activatedYN
Microsoft.Insights/ActivityLogAlerts/DeleteDelete an activity log alertYN
Microsoft.Insights/ActivityLogAlerts/WriteCreate or update an activity log alertYN
Microsoft.Insights/AlertRules/Activated/ActionClassic metric alert activatedNN
Microsoft.Insights/AlertRules/DeleteDelete a classic metric alertNY
Microsoft.Insights/AlertRules/Resolved/ActionClassic metric alert resolvedNN
Microsoft.Insights/AlertRules/Throttled/ActionClassic metric alert rule throttledNN
Microsoft.Insights/AlertRules/WriteCreate or update a classic metric alertNN
Microsoft.Insights/AutoscaleSettings/DeleteDelete an autoscale settingNN
Microsoft.Insights/AutoscaleSettings/PredictiveScaleup/ActionPredictive Autoscale scale up initiatedNN
Microsoft.Insights/AutoscaleSettings/PredictiveScaleupResult/ActionPredictive Autoscale scale up completedNN
Microsoft.Insights/AutoscaleSettings/providers/Microsoft.Insights/diagnosticSettings/WriteCreate or update a resource diagnostic settingNN
Microsoft.Insights/AutoscaleSettings/Scaledown/ActionAutoscale scale down initiatedNN
Microsoft.Insights/AutoscaleSettings/ScaledownResult/ActionAutoscale scale down completedNN
Microsoft.Insights/AutoscaleSettings/Scaleup/ActionAutoscale scale up initiatedNN
Microsoft.Insights/AutoscaleSettings/ScaleupResult/ActionAutoscale scale up completedNN
Microsoft.Insights/AutoscaleSettings/WriteCreate or update an autoscale settingNN
Microsoft.Insights/Components/AnalyticsItems/DeleteDeleting an Application Insights analytics itemNN
Microsoft.Insights/Components/AnalyticsItems/WriteWriting an Application Insights analytics itemNN
Microsoft.Insights/Components/AnalyticsTables/ActionApplication Insights analytics table actionNN
Microsoft.Insights/Components/AnalyticsTables/DeleteDeleting an Application Insights analytics table schemaNN
Microsoft.Insights/Components/AnalyticsTables/WriteWriting an Application Insights analytics table schemaNN
Microsoft.Insights/Components/Annotations/DeleteDeleting an Application Insights annotationNN
Microsoft.Insights/Components/Annotations/WriteWriting an Application Insights annotationNN
Microsoft.Insights/Components/ApiKeys/ActionGenerating an Application Insights API keyNN
Microsoft.Insights/Components/ApiKeys/DeleteDeleting an Application Insights API keyNN
Microsoft.Insights/Components/CurrentBillingFeatures/WriteWriting current billing features for Application Insights componentNN
Microsoft.Insights/Components/DailyCapReached/ActionReached the daily cap for Application Insights componentNN
Microsoft.Insights/Components/DailyCapWarningThresholdReached/ActionReached the daily cap warning threshold for Application Insights componentNN
Microsoft.Insights/Components/DeleteDeleting an application insights component configurationYN
Microsoft.Insights/Components/ExportConfiguration/ActionApplication Insights export settings actionNN
Microsoft.Insights/Components/ExportConfiguration/DeleteDeleting Application Insights export settingsNN
Microsoft.Insights/Components/ExportConfiguration/WriteWriting Application Insights export settingsNN
Microsoft.Insights/Components/Favorites/DeleteDeleting an Application Insights favoriteNN
Microsoft.Insights/Components/Favorites/WriteWriting an Application Insights favoriteNN
Microsoft.Insights/Components/linkedStorageAccounts/WriteCreate or modify linked storage accountNN
Microsoft.Insights/Components/Move/ActionMove an Application Insights Component to another resource group or subscriptionNN
Microsoft.Insights/Components/MyAnalyticsItems/DeleteDeleting an Application Insights personal analytics itemNN
Microsoft.Insights/Components/MyAnalyticsItems/WriteWriting an Application Insights personal analytics itemNN
Microsoft.Insights/Components/PricingPlans/WriteWriting an Application Insights component pricing planNN
Microsoft.Insights/Components/ProactiveDetectionConfigs/WriteWriting Application Insights proactive detection configurationNN
Microsoft.Insights/Components/providers/Microsoft.Insights/diagnosticSettings/WriteCreate or update a resource diagnostic settingNN
Microsoft.Insights/Components/Purge/ActionPurging data from Application InsightsNN
Microsoft.Insights/Components/WorkItemConfigs/DeleteDeleting an Application Insights ALM integration configurationNN
Microsoft.Insights/Components/WorkItemConfigs/WriteWriting an Application Insights ALM integration configurationNN
Microsoft.Insights/Components/WriteWriting to an application insights component configurationYN
Microsoft.Insights/CreateNotifications/WriteSend test notifications to the provided receiver listNN
Microsoft.Insights/DataCollectionEndpoints/DeleteDelete a data collection endpointYN
Microsoft.Insights/DataCollectionEndpoints/NetworkSecurityPerimeterAssociationProxies/DeleteDelete a data collection endpoint NSP association proxyNN
Microsoft.Insights/DataCollectionEndpoints/NetworkSecurityPerimeterAssociationProxies/WriteCreate or update a data collection endpoint NSP association proxyNN
Microsoft.Insights/DataCollectionEndpoints/NetworkSecurityPerimeterConfigurations/Reconcile/ActionReconcile data collection endpoint NSP configurationNN
Microsoft.Insights/DataCollectionEndpoints/ScopedPrivateLinkProxies/DeleteDelete a data collection endpoint private link proxyNN
Microsoft.Insights/DataCollectionEndpoints/ScopedPrivateLinkProxies/WriteCreate or update a data collection endpoint private link proxyNN
Microsoft.Insights/DataCollectionEndpoints/TriggerFailback/ActionTrigger failback on a data collection endpointNN
Microsoft.Insights/DataCollectionEndpoints/TriggerFailover/ActionTrigger failover on a data collection endpointNN
Microsoft.Insights/DataCollectionEndpoints/WriteCreate or update a data collection endpointYN
Microsoft.Insights/DataCollectionRuleAssociations/DeleteDelete a resource's association with a data collection ruleNN
Microsoft.Insights/DataCollectionRuleAssociations/WriteCreate or update a resource's association with a data collection ruleNN
Microsoft.Insights/DataCollectionRules/DeleteDelete a data collection ruleNN
Microsoft.Insights/DataCollectionRules/WriteCreate or update a data collection ruleNN
Microsoft.Insights/DiagnosticSettings/DeleteDelete a resource diagnostic settingNY
Microsoft.Insights/DiagnosticSettings/WriteCreate or update a resource diagnostic settingYN
Microsoft.Insights/ExtendedDiagnosticSettings/DeleteDelete a network flow log diagnostic settingNN
Microsoft.Insights/ExtendedDiagnosticSettings/WriteCreate or update a network flow log diagnostic settingNN
Microsoft.Insights/ListMigrationDate/ActionGet back Subscription migration dateNN
Microsoft.Insights/LogProfiles/DeleteDelete an Activity Log log profileNN
Microsoft.Insights/LogProfiles/WriteCreate or update an Activity Log log profileNN
Microsoft.Insights/MetricAlerts/DeleteDelete a metric alertNY
Microsoft.Insights/MetricAlerts/WriteCreate or update a metric alertNN
Microsoft.Insights/Metrics/ActionMetric ActionNN
Microsoft.Insights/MigrateToNewpricingModel/ActionMigrate subscription to new pricing modelNN
Microsoft.Insights/MonitoredObjects/DeleteDelete a monitored objectNN
Microsoft.Insights/MonitoredObjects/WriteCreate or update a monitored objectNN
Microsoft.Insights/PrivateLinkScopes/DeleteDelete a private link scopeNN
Microsoft.Insights/PrivateLinkScopes/PrivateEndpointConnectionProxies/DeleteDelete a private endpoint connection proxyNN
Microsoft.Insights/PrivateLinkScopes/PrivateEndpointConnectionProxies/Validate/ActionValidate a private endpoint connection proxyNN
Microsoft.Insights/PrivateLinkScopes/PrivateEndpointConnectionProxies/WriteCreate or update a private endpoint connection proxyNN
Microsoft.Insights/PrivateLinkScopes/PrivateEndpointConnections/DeleteDelete a private endpoint connectionNN
Microsoft.Insights/PrivateLinkScopes/PrivateEndpointConnections/WriteCreate or update a private endpoint connectionNN
Microsoft.Insights/PrivateLinkScopes/PrivateEndpointConnectionsApproval/actionApprove or reject a connection to a Private Endpoint resource of Microsoft.Network providerNN
Microsoft.Insights/PrivateLinkScopes/ScopedResources/DeleteDelete a private link scoped resourceNN
Microsoft.Insights/PrivateLinkScopes/ScopedResources/WriteCreate or update a private link scoped resourceNN
Microsoft.Insights/PrivateLinkScopes/WriteCreate or update a private link scopeNN
Microsoft.Insights/Register/ActionRegister the Microsoft Insights providerNN
Microsoft.Insights/RollbackToLegacyPricingModel/ActionRollback subscription to legacy pricing modelNN
Microsoft.Insights/ScheduledQueryRules/DeleteDeleting a scheduled query ruleNN
Microsoft.Insights/ScheduledQueryRules/NetworkSecurityPerimeterAssociationProxies/DeleteDeleting a network security perimeter association proxy for scheduled query rulesNN
Microsoft.Insights/ScheduledQueryRules/NetworkSecurityPerimeterAssociationProxies/WriteWriting a network security perimeter association proxy for scheduled query rulesNN
Microsoft.Insights/ScheduledQueryRules/networkSecurityPerimeterConfigurations/Reconcile/ActionReconciling network security perimeter configuration for scheduled query rulesNN
Microsoft.Insights/ScheduledQueryRules/WriteWriting a scheduled query ruleNN
Microsoft.Insights/TenantActionGroups/DeleteDelete a tenant action groupNN
Microsoft.Insights/TenantActionGroups/WriteCreate or update a tenant action groupNN
Microsoft.Insights/Tenants/Register/ActionInitializes the Microsoft Insights providerNN
Microsoft.Insights/Unregister/ActionRegister the Microsoft Insights providerNN
Microsoft.Insights/Webtests/DeleteDeleting a webtest configurationNN
Microsoft.Insights/Webtests/WriteWriting to a webtest configurationNN
Microsoft.Insights/Workbooks/DeleteDelete a workbookNN
Microsoft.Insights/Workbooks/WriteCreate or update a workbookNN
Microsoft.Insights/WorkbookTemplates/DeleteDelete a workbook templateNN
Microsoft.Insights/WorkbookTemplates/WriteCreate or update a workbook templateNN

any: Azure Monitor (catch-all)

#
Namespace
Microsoft.Insights

Description

Catch-all for Azure-Microsoft.Insights rules that match the resource provider but no specific operation.

Microsoft.Insights/ActionGroups/Delete

#
Namespace
Microsoft.Insights

Description

Delete an action group

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Success",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/actionGroups/zcag2",
    "action": "Microsoft.Insights/actionGroups/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/actionGroups/zcag2",
    "action": "Microsoft.Insights/actionGroups/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "aio": "REDACTED",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "REDACTED",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "c63f8086-9a88-4dbd-984a-178474cc29de",
  "EventDataId": "9695b7cb-59b8-15ff-19fd-076adcdfd260",
  "EventSubmissionTimestamp": "2026-06-29T18:12:09.9433398Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.INSIGHTS/ACTIONGROUPS/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Insights/actiongroups/zcag2",
    "message": "Microsoft.Insights/actiongroups/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "9695b7cb-59b8-15ff-19fd-076adcdfd260",
    "eventSubmissionTimestamp": "2026-06-29T18:12:09.9433398Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcag2",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.INSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Insights/actiongroups/zcag2",
    "message": "Microsoft.Insights/actiongroups/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "9695b7cb-59b8-15ff-19fd-076adcdfd260",
    "eventSubmissionTimestamp": "2026-06-29T18:12:09.9433398Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcag2",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.INSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Resource": "",
  "ResourceGroup": "RG-LOGCAPTURE-GEN",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.INSIGHTS",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T18:12:09.9433398Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.insights/actiongroups/zcag2"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
resultType (panther rule field)inSucceeded1 rulepanther
resultType (panther rule field)inSuccess1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

Microsoft.Insights/actionGroups/NetworkSecurityPerimeterAssociationProxies/Delete

#
Namespace
Microsoft.Insights

Description

Delete a action group endpoint NSP association proxy

Microsoft.Insights/actionGroups/NetworkSecurityPerimeterAssociationProxies/Write

#
Namespace
Microsoft.Insights

Description

Create or update a action group endpoint NSP association proxy

Microsoft.Insights/actionGroups/NetworkSecurityPerimeterConfigurations/Reconcile/Action

#
Namespace
Microsoft.Insights

Description

Reconcile action group endpoint NSP configuration

Microsoft.Insights/ActionGroups/Write

#
Namespace
Microsoft.Insights

Description

Create or update an action group

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Success",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "Created",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/actionGroups/zcag3",
    "action": "Microsoft.Insights/actionGroups/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/actionGroups/zcag3",
    "action": "Microsoft.Insights/actionGroups/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782755989",
    "nbf": "1782755989",
    "exp": "1782761191",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "5 3",
    "xms_ftd": "Mj7nU8nvfbVTGrVoiK4tJdjxisbwx4DqUPRFiszWj-UBdXNub3J0aC1kc21z",
    "xms_idrel": "1 8",
    "xms_sub_fct": "14 3",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "7320fc66-2dab-4845-b9a0-1ed991a8dda5",
  "EventDataId": "c19ad471-0e91-0930-d975-024e1f8418b5",
  "EventSubmissionTimestamp": "2026-06-29T19:04:03.3565667Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.INSIGHTS/ACTIONGROUPS/WRITE",
  "Properties": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/actionGroups/zcag3",
    "message": "Microsoft.Insights/actionGroups/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "c19ad471-0e91-0930-d975-024e1f8418b5",
    "eventSubmissionTimestamp": "2026-06-29T19:04:03.3565667Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcag3",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.INSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "Created"
  },
  "Properties_d": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/actionGroups/zcag3",
    "message": "Microsoft.Insights/actionGroups/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "c19ad471-0e91-0930-d975-024e1f8418b5",
    "eventSubmissionTimestamp": "2026-06-29T19:04:03.3565667Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "zcag3",
    "resourceGroup": "RG-LOGCAPTURE-GEN",
    "resourceProviderValue": "MICROSOFT.INSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "Created"
  },
  "Resource": "",
  "ResourceGroup": "RG-LOGCAPTURE-GEN",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.INSIGHTS",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T19:04:03.3565667Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.insights/actiongroups/zcag3"
}

Microsoft.Insights/ActivityLogAlerts/Activated/Action

#
Namespace
Microsoft.Insights

Description

Activity Log Alert activated

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Succeeded",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "",
  "Authorization": "",
  "Authorization_d": "None",
  "Caller": "",
  "CallerIpAddress": "",
  "Category": "",
  "CategoryValue": "Alert",
  "Claims": "",
  "Claims_d": "None",
  "CorrelationId": "9c77ebc7-44a9-4722-b0f8-0bc0db8411b4",
  "EventDataId": "6f795318-4f00-42c1-955f-28e4d2addeea",
  "EventSubmissionTimestamp": "2026-06-29T18:07:10.8340215Z",
  "HTTPRequest": "",
  "Hierarchy": "",
  "Level": "Informational",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "Microsoft.Insights/ActivityLogAlerts/Activated/action",
  "Properties": {
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "tenantId": "11111111-1111-1111-1111-111111111111",
    "eventDataId": "6f795318-4f00-42c1-955f-28e4d2addeea",
    "resourceGroup": "rg-logcapture-gen",
    "resourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Resources/deployments/vm_deploy_6hWz04CZWJL8g6USfIXNheOnqPcWQAd6",
    "eventTimestamp": "6/29/2026 6:02:38 PM",
    "operationName": "Microsoft.Resources/deployments/write",
    "status": "Started",
    "eventSubmissionTimestamp": "2026-06-29T18:07:10.8340215Z",
    "resource": "zcala",
    "resourceProviderValue": "microsoft.insights",
    "activityStatusValue": "Succeeded"
  },
  "Properties_d": {
    "eventDataId": "6f795318-4f00-42c1-955f-28e4d2addeea",
    "eventSubmissionTimestamp": "2026-06-29T18:07:10.8340215Z",
    "resource": "zcala",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "microsoft.insights",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Succeeded",
    "tenantId": "11111111-1111-1111-1111-111111111111",
    "resourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Resources/deployments/vm_deploy_6hWz04CZWJL8g6USfIXNheOnqPcWQAd6",
    "eventTimestamp": "6/29/2026 6:02:38 PM",
    "operationName": "Microsoft.Resources/deployments/write",
    "status": "Started"
  },
  "Resource": "",
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "microsoft.insights",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T18:07:10.8340215Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/microsoft.insights/activitylogalerts/zcala"
}

Microsoft.Insights/ActivityLogAlerts/Delete

#
Namespace
Microsoft.Insights

Description

Delete an activity log alert

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "NoContent",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/activityLogAlerts/dwhp3bbd4cala",
    "action": "Microsoft.Insights/activityLogAlerts/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/activityLogAlerts/dwhp3bbd4cala",
    "action": "Microsoft.Insights/activityLogAlerts/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "ec30e150-ad20-418f-8058-3a2fdfcae8f2",
  "EventDataId": "2236da13-157c-52b4-5d54-b64fb123168d",
  "EventSubmissionTimestamp": "2026-07-03T01:48:26.4397449Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.INSIGHTS/ACTIVITYLOGALERTS/DELETE",
  "Properties": {
    "statusCode": "NoContent",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/activityLogAlerts/dwhp3bbd4cala",
    "message": "Microsoft.Insights/activityLogAlerts/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "2236da13-157c-52b4-5d54-b64fb123168d",
    "eventSubmissionTimestamp": "2026-07-03T01:48:26.4397449Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhp3bbd4cala",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.INSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "NoContent"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/activityLogAlerts/dwhp3bbd4cala",
    "message": "Microsoft.Insights/activityLogAlerts/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "2236da13-157c-52b4-5d54-b64fb123168d",
    "eventSubmissionTimestamp": "2026-07-03T01:48:26.4397449Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhp3bbd4cala",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.INSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "NoContent",
    "serviceRequestId": "",
    "activitySubstatusValue": "NoContent"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.INSIGHTS",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Insights/ActivityLogAlerts/Write

#
Namespace
Microsoft.Insights

Description

Create or update an activity log alert

Example Resource Log Record #

{
  "ActivityStatusValue": "Failure",
  "ActivitySubstatusValue": "BadRequest",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/activityLogAlerts/dwhp3bbd4cala",
    "action": "Microsoft.Insights/activityLogAlerts/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/activityLogAlerts/dwhp3bbd4cala",
    "action": "Microsoft.Insights/activityLogAlerts/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783057703",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "correlationid": "00b19dbe-ce18-40ce-9099-2c45321389fb"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783057703",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "correlationid": "00b19dbe-ce18-40ce-9099-2c45321389fb",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "00b19dbe-ce18-40ce-9099-2c45321389fb",
  "EventDataId": "e00b1a76-80f5-702c-e9bf-9138c3dd1cdb",
  "EventSubmissionTimestamp": "2026-07-03T01:48:24.8572803Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Error",
  "OperationNameValue": "MICROSOFT.INSIGHTS/ACTIVITYLOGALERTS/WRITE",
  "Properties": {
    "statusCode": "BadRequest",
    "serviceRequestId": "",
    "statusMessage": {
      "code": "UnsupportedCondition",
      "message": "Alert Rule with category 'Administrative' and subscription scope must have at least one additional filtering condition. Activity ID: 00b19dbe-ce18-40ce-9099-2c45321389fb."
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/activityLogAlerts/dwhp3bbd4cala",
    "message": "Microsoft.Insights/activityLogAlerts/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "e00b1a76-80f5-702c-e9bf-9138c3dd1cdb",
    "eventSubmissionTimestamp": "2026-07-03T01:48:24.8572803Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhp3bbd4cala",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.INSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Failure",
    "activitySubstatusValue": "BadRequest"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/activityLogAlerts/dwhp3bbd4cala",
    "message": "Microsoft.Insights/activityLogAlerts/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "e00b1a76-80f5-702c-e9bf-9138c3dd1cdb",
    "eventSubmissionTimestamp": "2026-07-03T01:48:24.8572803Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhp3bbd4cala",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.INSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Failure",
    "statusCode": "BadRequest",
    "serviceRequestId": "",
    "activitySubstatusValue": "BadRequest",
    "statusMessage": {
      "code": "UnsupportedCondition",
      "message": "Alert Rule with category 'Administrative' and subscription scope must have at least one additional filtering condition. Activity ID: 00b19dbe-ce18-40ce-9099-2c45321389fb."
    }
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.INSIGHTS",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Insights/AlertRules/Activated/Action

#
Namespace
Microsoft.Insights

Description

Classic metric alert activated

Microsoft.Insights/AlertRules/Delete

#
Namespace
Microsoft.Insights

Description

Delete a classic metric alert

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
resultType (panther rule field)inSucceeded1 rulepanther
resultType (panther rule field)inSuccess1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

Microsoft.Insights/AlertRules/Resolved/Action

#
Namespace
Microsoft.Insights

Description

Classic metric alert resolved

Microsoft.Insights/AlertRules/Throttled/Action

#
Namespace
Microsoft.Insights

Description

Classic metric alert rule throttled

Microsoft.Insights/AlertRules/Write

#
Namespace
Microsoft.Insights

Description

Create or update a classic metric alert

Microsoft.Insights/AutoscaleSettings/Delete

#
Namespace
Microsoft.Insights

Description

Delete an autoscale setting

Microsoft.Insights/AutoscaleSettings/PredictiveScaleup/Action

#
Namespace
Microsoft.Insights

Description

Predictive Autoscale scale up initiated

Microsoft.Insights/AutoscaleSettings/PredictiveScaleupResult/Action

#
Namespace
Microsoft.Insights

Description

Predictive Autoscale scale up completed

Microsoft.Insights/AutoscaleSettings/providers/Microsoft.Insights/diagnosticSettings/Write

#
Namespace
Microsoft.Insights

Description

Create or update a resource diagnostic setting

Microsoft.Insights/AutoscaleSettings/Scaledown/Action

#
Namespace
Microsoft.Insights

Description

Autoscale scale down initiated

Microsoft.Insights/AutoscaleSettings/ScaledownResult/Action

#
Namespace
Microsoft.Insights

Description

Autoscale scale down completed

Microsoft.Insights/AutoscaleSettings/Scaleup/Action

#
Namespace
Microsoft.Insights

Description

Autoscale scale up initiated

Microsoft.Insights/AutoscaleSettings/ScaleupResult/Action

#
Namespace
Microsoft.Insights

Description

Autoscale scale up completed

Microsoft.Insights/AutoscaleSettings/Write

#
Namespace
Microsoft.Insights

Description

Create or update an autoscale setting

Microsoft.Insights/Components/AnalyticsItems/Delete

#
Namespace
Microsoft.Insights

Description

Deleting an Application Insights analytics item

Microsoft.Insights/Components/AnalyticsItems/Write

#
Namespace
Microsoft.Insights

Description

Writing an Application Insights analytics item

Microsoft.Insights/Components/AnalyticsTables/Action

#
Namespace
Microsoft.Insights

Description

Application Insights analytics table action

Microsoft.Insights/Components/AnalyticsTables/Delete

#
Namespace
Microsoft.Insights

Description

Deleting an Application Insights analytics table schema

Microsoft.Insights/Components/AnalyticsTables/Write

#
Namespace
Microsoft.Insights

Description

Writing an Application Insights analytics table schema

Microsoft.Insights/Components/Annotations/Delete

#
Namespace
Microsoft.Insights

Description

Deleting an Application Insights annotation

Microsoft.Insights/Components/Annotations/Write

#
Namespace
Microsoft.Insights

Description

Writing an Application Insights annotation

Microsoft.Insights/Components/ApiKeys/Action

#
Namespace
Microsoft.Insights

Description

Generating an Application Insights API key

Microsoft.Insights/Components/ApiKeys/Delete

#
Namespace
Microsoft.Insights

Description

Deleting an Application Insights API key

Microsoft.Insights/Components/CurrentBillingFeatures/Write

#
Namespace
Microsoft.Insights

Description

Writing current billing features for Application Insights component

Microsoft.Insights/Components/DailyCapReached/Action

#
Namespace
Microsoft.Insights

Description

Reached the daily cap for Application Insights component

Microsoft.Insights/Components/DailyCapWarningThresholdReached/Action

#
Namespace
Microsoft.Insights

Description

Reached the daily cap warning threshold for Application Insights component

Microsoft.Insights/Components/Delete

#
Namespace
Microsoft.Insights

Description

Deleting an application insights component configuration

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/components/dwhc6a93dappinsights",
    "action": "Microsoft.Insights/components/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/components/dwhc6a93dappinsights",
    "action": "Microsoft.Insights/components/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "c7ffb16b-7e03-405f-811b-5d1b43c880f1",
  "EventDataId": "58a10880-1899-b537-e31a-27f1253b20a2",
  "EventSubmissionTimestamp": "2026-07-03T02:26:12.9041359Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.INSIGHTS/COMPONENTS/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Insights/components/dwhc6a93dappinsights",
    "message": "Microsoft.Insights/components/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "58a10880-1899-b537-e31a-27f1253b20a2",
    "eventSubmissionTimestamp": "2026-07-03T02:26:12.9041359Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93dappinsights",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.INSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Insights/components/dwhc6a93dappinsights",
    "message": "Microsoft.Insights/components/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "58a10880-1899-b537-e31a-27f1253b20a2",
    "eventSubmissionTimestamp": "2026-07-03T02:26:12.9041359Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93dappinsights",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.INSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.INSIGHTS",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Insights/Components/ExportConfiguration/Action

#
Namespace
Microsoft.Insights

Description

Application Insights export settings action

Microsoft.Insights/Components/ExportConfiguration/Delete

#
Namespace
Microsoft.Insights

Description

Deleting Application Insights export settings

Microsoft.Insights/Components/ExportConfiguration/Write

#
Namespace
Microsoft.Insights

Description

Writing Application Insights export settings

Microsoft.Insights/Components/Favorites/Delete

#
Namespace
Microsoft.Insights

Description

Deleting an Application Insights favorite

Microsoft.Insights/Components/Favorites/Write

#
Namespace
Microsoft.Insights

Description

Writing an Application Insights favorite

Microsoft.Insights/Components/linkedStorageAccounts/Write

#
Namespace
Microsoft.Insights

Description

Create or modify linked storage account

Microsoft.Insights/Components/Move/Action

#
Namespace
Microsoft.Insights

Description

Move an Application Insights Component to another resource group or subscription

Microsoft.Insights/Components/MyAnalyticsItems/Delete

#
Namespace
Microsoft.Insights

Description

Deleting an Application Insights personal analytics item

Microsoft.Insights/Components/MyAnalyticsItems/Write

#
Namespace
Microsoft.Insights

Description

Writing an Application Insights personal analytics item

Microsoft.Insights/Components/PricingPlans/Write

#
Namespace
Microsoft.Insights

Description

Writing an Application Insights component pricing plan

Microsoft.Insights/Components/ProactiveDetectionConfigs/Write

#
Namespace
Microsoft.Insights

Description

Writing Application Insights proactive detection configuration

Microsoft.Insights/Components/providers/Microsoft.Insights/diagnosticSettings/Write

#
Namespace
Microsoft.Insights

Description

Create or update a resource diagnostic setting

Microsoft.Insights/Components/Purge/Action

#
Namespace
Microsoft.Insights

Description

Purging data from Application Insights

Microsoft.Insights/Components/WorkItemConfigs/Delete

#
Namespace
Microsoft.Insights

Description

Deleting an Application Insights ALM integration configuration

Microsoft.Insights/Components/WorkItemConfigs/Write

#
Namespace
Microsoft.Insights

Description

Writing an Application Insights ALM integration configuration

Microsoft.Insights/Components/Write

#
Namespace
Microsoft.Insights

Description

Writing to an application insights component configuration

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "OK",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/components/dwhc6a93dappinsights",
    "action": "Microsoft.Insights/components/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/components/dwhc6a93dappinsights",
    "action": "Microsoft.Insights/components/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783059369",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "correlationid": "8b954797-dd76-4f9e-a599-9313c9f4beeb"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783059369",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "correlationid": "8b954797-dd76-4f9e-a599-9313c9f4beeb"
  },
  "CorrelationId": "8b954797-dd76-4f9e-a599-9313c9f4beeb",
  "EventDataId": "e34e64cc-7f04-95f1-92f2-635c460f8355",
  "EventSubmissionTimestamp": "2026-07-03T02:16:10.9068058Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.INSIGHTS/COMPONENTS/WRITE",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/components/dwhc6a93dappinsights",
    "message": "Microsoft.Insights/components/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "e34e64cc-7f04-95f1-92f2-635c460f8355",
    "eventSubmissionTimestamp": "2026-07-03T02:16:10.9068058Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93dappinsights",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.INSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/components/dwhc6a93dappinsights",
    "message": "Microsoft.Insights/components/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "e34e64cc-7f04-95f1-92f2-635c460f8355",
    "eventSubmissionTimestamp": "2026-07-03T02:16:10.9068058Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93dappinsights",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.INSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.INSIGHTS",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Insights/CreateNotifications/Write

#
Namespace
Microsoft.Insights

Description

Send test notifications to the provided receiver list

Microsoft.Insights/DataCollectionEndpoints/Delete

#
Namespace
Microsoft.Insights

Description

Delete a data collection endpoint

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/dataCollectionEndpoints/dwhc6a93ddcendpoint",
    "action": "Microsoft.Insights/dataCollectionEndpoints/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/dataCollectionEndpoints/dwhc6a93ddcendpoint",
    "action": "Microsoft.Insights/dataCollectionEndpoints/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "89a2a8a6-f3d1-4ef8-a7ae-9be55d31329a",
  "EventDataId": "72ab3977-13b3-5d84-14a8-61b602bc7e0a",
  "EventSubmissionTimestamp": "2026-07-03T02:26:07.9372506Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.INSIGHTS/DATACOLLECTIONENDPOINTS/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Insights/dataCollectionEndpoints/dwhc6a93ddcendpoint",
    "message": "Microsoft.Insights/dataCollectionEndpoints/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "72ab3977-13b3-5d84-14a8-61b602bc7e0a",
    "eventSubmissionTimestamp": "2026-07-03T02:26:07.9372506Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93ddcendpoint",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.INSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Insights/dataCollectionEndpoints/dwhc6a93ddcendpoint",
    "message": "Microsoft.Insights/dataCollectionEndpoints/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "72ab3977-13b3-5d84-14a8-61b602bc7e0a",
    "eventSubmissionTimestamp": "2026-07-03T02:26:07.9372506Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93ddcendpoint",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.INSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.INSIGHTS",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Insights/DataCollectionEndpoints/NetworkSecurityPerimeterAssociationProxies/Delete

#
Namespace
Microsoft.Insights

Description

Delete a data collection endpoint NSP association proxy

Microsoft.Insights/DataCollectionEndpoints/NetworkSecurityPerimeterAssociationProxies/Write

#
Namespace
Microsoft.Insights

Description

Create or update a data collection endpoint NSP association proxy

Microsoft.Insights/DataCollectionEndpoints/NetworkSecurityPerimeterConfigurations/Reconcile/Action

#
Namespace
Microsoft.Insights

Description

Reconcile data collection endpoint NSP configuration

Microsoft.Insights/DataCollectionEndpoints/ScopedPrivateLinkProxies/Delete

#
Namespace
Microsoft.Insights

Description

Delete a data collection endpoint private link proxy

Microsoft.Insights/DataCollectionEndpoints/ScopedPrivateLinkProxies/Write

#
Namespace
Microsoft.Insights

Description

Create or update a data collection endpoint private link proxy

Microsoft.Insights/DataCollectionEndpoints/TriggerFailback/Action

#
Namespace
Microsoft.Insights

Description

Trigger failback on a data collection endpoint

Microsoft.Insights/DataCollectionEndpoints/TriggerFailover/Action

#
Namespace
Microsoft.Insights

Description

Trigger failover on a data collection endpoint

Microsoft.Insights/DataCollectionEndpoints/Write

#
Namespace
Microsoft.Insights

Description

Create or update a data collection endpoint

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "OK",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/dataCollectionEndpoints/dwhc6a93ddcendpoint",
    "action": "Microsoft.Insights/dataCollectionEndpoints/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/dataCollectionEndpoints/dwhc6a93ddcendpoint",
    "action": "Microsoft.Insights/dataCollectionEndpoints/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783059363",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "correlationid": "0088c8b5-cc1c-4c1b-871e-f9524f329182"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783059363",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "correlationid": "0088c8b5-cc1c-4c1b-871e-f9524f329182"
  },
  "CorrelationId": "0088c8b5-cc1c-4c1b-871e-f9524f329182",
  "EventDataId": "6def0f04-addb-deaf-a9c1-86c8429218f5",
  "EventSubmissionTimestamp": "2026-07-03T02:16:05.1121772Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.INSIGHTS/DATACOLLECTIONENDPOINTS/WRITE",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/dataCollectionEndpoints/dwhc6a93ddcendpoint",
    "message": "Microsoft.Insights/dataCollectionEndpoints/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "6def0f04-addb-deaf-a9c1-86c8429218f5",
    "eventSubmissionTimestamp": "2026-07-03T02:16:05.1121772Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93ddcendpoint",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.INSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Insights/dataCollectionEndpoints/dwhc6a93ddcendpoint",
    "message": "Microsoft.Insights/dataCollectionEndpoints/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "6def0f04-addb-deaf-a9c1-86c8429218f5",
    "eventSubmissionTimestamp": "2026-07-03T02:16:05.1121772Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93ddcendpoint",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.INSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.INSIGHTS",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Insights/DataCollectionRuleAssociations/Delete

#
Namespace
Microsoft.Insights

Description

Delete a resource's association with a data collection rule

Microsoft.Insights/DataCollectionRuleAssociations/Write

#
Namespace
Microsoft.Insights

Description

Create or update a resource's association with a data collection rule

Microsoft.Insights/DataCollectionRules/Delete

#
Namespace
Microsoft.Insights

Description

Delete a data collection rule

Microsoft.Insights/DataCollectionRules/Write

#
Namespace
Microsoft.Insights

Description

Create or update a data collection rule

Microsoft.Insights/DiagnosticSettings/Delete

#
Namespace
Microsoft.Insights

Description

Delete a resource diagnostic setting

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Kusto #

  • Azure Diagnostic settings removed from a resource source medium: This query looks for diagnostic settings that are removed from a resource. This could indicate an attacker or malicious internal trying to evade detection before malicious act is performed. If the diagnostic settings are being deleted as part of a parent resource deletion, the event is ignores.T1562, T1562.008

Panther #

Microsoft.Insights/DiagnosticSettings/Write

#
Namespace
Microsoft.Insights

Description

Create or update a resource diagnostic setting

Example Resource Log Record #

{
  "ActivityStatus": "",
  "ActivityStatusValue": "Failure",
  "ActivitySubstatus": "",
  "ActivitySubstatusValue": "Conflict",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/microsoft.insights/diagnosticSettings/ds-activity-law",
    "action": "microsoft.insights/diagnosticSettings/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/microsoft.insights/diagnosticSettings/ds-activity-law",
    "action": "microsoft.insights/diagnosticSettings/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "Category": "",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "REDACTED",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "REDACTED",
    "rh": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782752670",
    "nbf": "1782752670",
    "exp": "1782756583",
    "aio": "REDACTED",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "REDACTED",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "REDACTED",
    "ver": "1.0",
    "wids": "REDACTED",
    "xms_act_fct": "3 5",
    "xms_ftd": "Qm3VI9ndhO4eGa9PlO2ooXp_lItcoAEfvdN1STz6NOIBdXNlYXN0LWRzbXM",
    "xms_idrel": "1 2",
    "xms_sub_fct": "2 3",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "REDACTED",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "36cd279a-8b0f-4968-a146-f0d5139a9aa0",
  "EventDataId": "3785540e-1413-da5a-18f2-6fed02440c71",
  "EventSubmissionTimestamp": "2026-06-29T17:17:35.9549633Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Error",
  "OperationId": "",
  "OperationName": "",
  "OperationNameValue": "MICROSOFT.INSIGHTS/DIAGNOSTICSETTINGS/WRITE",
  "Properties": {
    "statusCode": "Conflict",
    "serviceRequestId": "",
    "statusMessage": {
      "code": "InvalidAuthenticationToken",
      "message": "Please register the subscription '22222222-2222-2222-2222-222222222222' with Microsoft.Insights."
    },
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/microsoft.insights/diagnosticSettings/ds-activity-law",
    "message": "microsoft.insights/diagnosticSettings/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "3785540e-1413-da5a-18f2-6fed02440c71",
    "eventSubmissionTimestamp": "2026-06-29T17:17:35.9549633Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "ds-activity-law",
    "resourceProviderValue": "MICROSOFT.INSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Failure",
    "activitySubstatusValue": "Conflict"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/microsoft.insights/diagnosticSettings/ds-activity-law",
    "message": "microsoft.insights/diagnosticSettings/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "3785540e-1413-da5a-18f2-6fed02440c71",
    "eventSubmissionTimestamp": "2026-06-29T17:17:35.9549633Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "ds-activity-law",
    "resourceProviderValue": "MICROSOFT.INSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Failure",
    "statusCode": "Conflict",
    "serviceRequestId": "",
    "activitySubstatusValue": "Conflict",
    "statusMessage": {
      "code": "InvalidAuthenticationToken",
      "message": "Please register the subscription '22222222-2222-2222-2222-222222222222' with Microsoft.Insights."
    }
  },
  "Resource": "",
  "ResourceGroup": "",
  "ResourceId": "",
  "ResourceProvider": "",
  "ResourceProviderValue": "MICROSOFT.INSIGHTS",
  "SourceSystem": "Azure",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222",
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T17:17:35.9549633Z",
  "Type": "AzureActivity",
  "_ResourceId": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/microsoft.insights/diagnosticsettings/ds-activity-law"
}

Microsoft.Insights/ExtendedDiagnosticSettings/Delete

#
Namespace
Microsoft.Insights

Description

Delete a network flow log diagnostic setting

Microsoft.Insights/ExtendedDiagnosticSettings/Write

#
Namespace
Microsoft.Insights

Description

Create or update a network flow log diagnostic setting

Microsoft.Insights/ListMigrationDate/Action

#
Namespace
Microsoft.Insights

Description

Get back Subscription migration date

Microsoft.Insights/LogProfiles/Delete

#
Namespace
Microsoft.Insights

Description

Delete an Activity Log log profile

Microsoft.Insights/LogProfiles/Write

#
Namespace
Microsoft.Insights

Description

Create or update an Activity Log log profile

Microsoft.Insights/MetricAlerts/Delete

#
Namespace
Microsoft.Insights

Description

Delete a metric alert

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
resultType (panther rule field)inSucceeded1 rulepanther
resultType (panther rule field)inSuccess1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

Microsoft.Insights/MetricAlerts/Write

#
Namespace
Microsoft.Insights

Description

Create or update a metric alert

Microsoft.Insights/Metrics/Action

#
Namespace
Microsoft.Insights

Description

Metric Action

Microsoft.Insights/MigrateToNewpricingModel/Action

#
Namespace
Microsoft.Insights

Description

Migrate subscription to new pricing model

Microsoft.Insights/MonitoredObjects/Delete

#
Namespace
Microsoft.Insights

Description

Delete a monitored object

Microsoft.Insights/MonitoredObjects/Write

#
Namespace
Microsoft.Insights

Description

Create or update a monitored object

Microsoft.Insights/PrivateLinkScopes/Delete

#
Namespace
Microsoft.Insights

Description

Delete a private link scope

Microsoft.Insights/PrivateLinkScopes/PrivateEndpointConnectionProxies/Delete

#
Namespace
Microsoft.Insights

Description

Delete a private endpoint connection proxy

Microsoft.Insights/PrivateLinkScopes/PrivateEndpointConnectionProxies/Validate/Action

#
Namespace
Microsoft.Insights

Description

Validate a private endpoint connection proxy

Microsoft.Insights/PrivateLinkScopes/PrivateEndpointConnectionProxies/Write

#
Namespace
Microsoft.Insights

Description

Create or update a private endpoint connection proxy

Microsoft.Insights/PrivateLinkScopes/PrivateEndpointConnections/Delete

#
Namespace
Microsoft.Insights

Description

Delete a private endpoint connection

Microsoft.Insights/PrivateLinkScopes/PrivateEndpointConnections/Write

#
Namespace
Microsoft.Insights

Description

Create or update a private endpoint connection

Microsoft.Insights/PrivateLinkScopes/PrivateEndpointConnectionsApproval/action

#
Namespace
Microsoft.Insights

Description

Approve or reject a connection to a Private Endpoint resource of Microsoft.Network provider

Microsoft.Insights/PrivateLinkScopes/ScopedResources/Delete

#
Namespace
Microsoft.Insights

Description

Delete a private link scoped resource

Microsoft.Insights/PrivateLinkScopes/ScopedResources/Write

#
Namespace
Microsoft.Insights

Description

Create or update a private link scoped resource

Microsoft.Insights/PrivateLinkScopes/Write

#
Namespace
Microsoft.Insights

Description

Create or update a private link scope

Microsoft.Insights/Register/Action

#
Namespace
Microsoft.Insights

Description

Register the Microsoft Insights provider

Microsoft.Insights/RollbackToLegacyPricingModel/Action

#
Namespace
Microsoft.Insights

Description

Rollback subscription to legacy pricing model

Microsoft.Insights/ScheduledQueryRules/Delete

#
Namespace
Microsoft.Insights

Description

Deleting a scheduled query rule

Microsoft.Insights/ScheduledQueryRules/NetworkSecurityPerimeterAssociationProxies/Delete

#
Namespace
Microsoft.Insights

Description

Deleting a network security perimeter association proxy for scheduled query rules

Microsoft.Insights/ScheduledQueryRules/NetworkSecurityPerimeterAssociationProxies/Write

#
Namespace
Microsoft.Insights

Description

Writing a network security perimeter association proxy for scheduled query rules

Microsoft.Insights/ScheduledQueryRules/networkSecurityPerimeterConfigurations/Reconcile/Action

#
Namespace
Microsoft.Insights

Description

Reconciling network security perimeter configuration for scheduled query rules

Microsoft.Insights/ScheduledQueryRules/Write

#
Namespace
Microsoft.Insights

Description

Writing a scheduled query rule

Microsoft.Insights/TenantActionGroups/Delete

#
Namespace
Microsoft.Insights

Description

Delete a tenant action group

Microsoft.Insights/TenantActionGroups/Write

#
Namespace
Microsoft.Insights

Description

Create or update a tenant action group

Microsoft.Insights/Tenants/Register/Action

#
Namespace
Microsoft.Insights

Description

Initializes the Microsoft Insights provider

Microsoft.Insights/Unregister/Action

#
Namespace
Microsoft.Insights

Description

Register the Microsoft Insights provider

Microsoft.Insights/Webtests/Delete

#
Namespace
Microsoft.Insights

Description

Deleting a webtest configuration

Microsoft.Insights/Webtests/Write

#
Namespace
Microsoft.Insights

Description

Writing to a webtest configuration

Microsoft.Insights/Workbooks/Delete

#
Namespace
Microsoft.Insights

Description

Delete a workbook

Microsoft.Insights/Workbooks/Write

#
Namespace
Microsoft.Insights

Description

Create or update a workbook

Microsoft.Insights/WorkbookTemplates/Delete

#
Namespace
Microsoft.Insights

Description

Delete a workbook template

Microsoft.Insights/WorkbookTemplates/Write

#
Namespace
Microsoft.Insights

Description

Create or update a workbook template

References #