Log Analytics (Azure Monitor) Azure-Microsoft.OperationalInsights
any: Log Analytics (Azure Monitor) (catch-all)
#Description
Catch-all for Azure-Microsoft.OperationalInsights rules that match the resource provider but no specific operation.
Microsoft.OperationalInsights/clusters/delete
#Description
Delete Cluster
Microsoft.OperationalInsights/clusters/write
#Description
Create or updates a Cluster
Microsoft.OperationalInsights/locations/workspaces/failover/action
#Description
Initiates workspace failover to replication location.
Microsoft.OperationalInsights/querypacks/action
#Description
Perform Query Pack Action.
Microsoft.OperationalInsights/querypacks/delete
#Description
Delete Query Pack.
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/queryPacks/dwh2220afquerypacks",
"action": "Microsoft.OperationalInsights/queryPacks/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/queryPacks/dwh2220afquerypacks",
"action": "Microsoft.OperationalInsights/queryPacks/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "2322f576-5aef-49d0-9726-1446daeedb7b",
"EventDataId": "af59c1db-413b-f8ff-cc05-328a2f1742db",
"EventSubmissionTimestamp": "2026-07-02T18:35:37.8948205Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.OPERATIONALINSIGHTS/QUERYPACKS/DELETE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/querypacks/dwh2220afquerypacks",
"message": "Microsoft.OperationalInsights/querypacks/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "af59c1db-413b-f8ff-cc05-328a2f1742db",
"eventSubmissionTimestamp": "2026-07-02T18:35:37.8948205Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afquerypacks",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/querypacks/dwh2220afquerypacks",
"message": "Microsoft.OperationalInsights/querypacks/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "af59c1db-413b-f8ff-cc05-328a2f1742db",
"eventSubmissionTimestamp": "2026-07-02T18:35:37.8948205Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afquerypacks",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
Microsoft.OperationalInsights/querypacks/queries/action
#Description
Perform Action on Queries in Query Pack.
Microsoft.OperationalInsights/querypacks/queries/delete
#Description
Delete Query Pack Queries.
Microsoft.OperationalInsights/querypacks/queries/write
#Description
Create or update Query Pack Queries.
Microsoft.OperationalInsights/querypacks/write
#Description
Create or update Query Pack.
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"ActivitySubstatusValue": "Created",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/queryPacks/dwh2220afquerypacks",
"action": "Microsoft.OperationalInsights/queryPacks/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/queryPacks/dwh2220afquerypacks",
"action": "Microsoft.OperationalInsights/queryPacks/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783017701",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
},
"CorrelationId": "4ce9b326-b99c-4ba8-88c5-d3f793ebdedd",
"EventDataId": "e840c5ac-5a33-92f8-9429-68887e354818",
"EventSubmissionTimestamp": "2026-07-02T18:25:35.8815881Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.OPERATIONALINSIGHTS/QUERYPACKS/WRITE",
"Properties": {
"statusCode": "Created",
"serviceRequestId": "",
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/queryPacks/dwh2220afquerypacks",
"message": "Microsoft.OperationalInsights/queryPacks/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "e840c5ac-5a33-92f8-9429-68887e354818",
"eventSubmissionTimestamp": "2026-07-02T18:25:35.8815881Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afquerypacks",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"activitySubstatusValue": "Created"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/queryPacks/dwh2220afquerypacks",
"message": "Microsoft.OperationalInsights/queryPacks/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "e840c5ac-5a33-92f8-9429-68887e354818",
"eventSubmissionTimestamp": "2026-07-02T18:25:35.8815881Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afquerypacks",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success",
"statusCode": "Created",
"serviceRequestId": "",
"activitySubstatusValue": "Created"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
Microsoft.OperationalInsights/register/action
#Description
Register a subscription to a resource provider.
Microsoft.OperationalInsights/unregister/action
#Description
UnRegister a subscription to a resource provider.
Microsoft.OperationalInsights/workspaces/analytics/query/action
#Description
Search using new engine.
Microsoft.OperationalInsights/workspaces/api/query/action
#Description
Search using new engine.
Microsoft.OperationalInsights/workspaces/configurationscopes/delete
#Description
Delete configuration scope in a workspace.
Microsoft.OperationalInsights/workspaces/configurationscopes/write
#Description
Create configuration scope in a workspace.
Microsoft.OperationalInsights/workspaces/customfields/action
#Description
Extract custom fields.
Microsoft.OperationalInsights/workspaces/customfields/delete
#Description
Delete a custom field.
Microsoft.OperationalInsights/workspaces/customfields/write
#Description
Create or update a custom field.
Microsoft.OperationalInsights/workspaces/dataexports/delete
#Description
Delete specific Data Export/
Microsoft.OperationalInsights/workspaces/dataexports/write
#Description
Create or update specific data export.
Microsoft.OperationalInsights/workspaces/datasources/delete
#Description
Delete data source under a workspace.
Microsoft.OperationalInsights/workspaces/datasources/write
#Description
Upsert Data Source
Microsoft.OperationalInsights/workspaces/delete
#Description
Deletes a workspace. If the workspace was linked to an existing workspace at creation time then the workspace it was linked to is not deleted.
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dwh2220afworkspaces",
"action": "Microsoft.OperationalInsights/workspaces/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dwh2220afworkspaces",
"action": "Microsoft.OperationalInsights/workspaces/delete",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783031172",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"correlationid": "c6a9c8bf-f7a5-4cbd-9871-7aa2e0aad1b7"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783031172",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"correlationid": "c6a9c8bf-f7a5-4cbd-9871-7aa2e0aad1b7"
},
"CorrelationId": "c6a9c8bf-f7a5-4cbd-9871-7aa2e0aad1b7",
"EventDataId": "fae22d15-92bf-26df-d91d-9707101d63d0",
"EventSubmissionTimestamp": "2026-07-02T18:26:34.181936Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.OPERATIONALINSIGHTS/WORKSPACES/DELETE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dwh2220afworkspaces",
"message": "Microsoft.OperationalInsights/workspaces/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "fae22d15-92bf-26df-d91d-9707101d63d0",
"eventSubmissionTimestamp": "2026-07-02T18:26:34.181936Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afworkspaces",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dwh2220afworkspaces",
"message": "Microsoft.OperationalInsights/workspaces/delete",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "fae22d15-92bf-26df-d91d-9707101d63d0",
"eventSubmissionTimestamp": "2026-07-02T18:26:34.1819360Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afworkspaces",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1485, T1562.008
Microsoft.OperationalInsights/workspaces/failback/action
#Description
Initiates workspace failback.
Microsoft.OperationalInsights/workspaces/gateways/delete
#Description
Removes a gateway configured for the workspace.
Microsoft.OperationalInsights/workspaces/intelligencepacks/disable/action
#Description
Disables an intelligence pack for a given workspace.
Microsoft.OperationalInsights/workspaces/intelligencepacks/enable/action
#Description
Enables an intelligence pack for a given workspace.
Microsoft.OperationalInsights/workspaces/linkedservices/delete
#Description
Delete linked services under given workspace.
Microsoft.OperationalInsights/workspaces/linkedservices/write
#Description
Create or update linked services under given workspace.
Microsoft.OperationalInsights/workspaces/linkedstorageaccounts/delete
#Description
Delete a Log Analytics Workspace Linked Storage Account.
Microsoft.OperationalInsights/workspaces/linkedstorageaccounts/write
#Description
Put a Log Analytics Workspace Linked Storage Account.
Microsoft.OperationalInsights/workspaces/listKeys/action
#Description
Retrieves the list keys for the workspace. These keys are used to connect Microsoft Operational Insights agents to the workspace.
Microsoft.OperationalInsights/workspaces/networkSecurityPerimeterAssociationProxies/delete
#Description
Delete Network Security Perimeter Association Proxies.
Microsoft.OperationalInsights/workspaces/networkSecurityPerimeterAssociationProxies/write
#Description
Write Network Security Perimeter Association Proxies.
Microsoft.OperationalInsights/workspaces/networkSecurityPerimeterConfigurations/reconcile/action
#Description
Reconcile operation for Network Security Perimeter Configurations.
Microsoft.OperationalInsights/workspaces/notificationsettings/delete
#Description
Delete the user's notification settings for the workspace.
Microsoft.OperationalInsights/workspaces/notificationsettings/write
#Description
Set the user's notification settings for the workspace.
Microsoft.OperationalInsights/workspaces/providers/Microsoft.Insights/diagnosticSettings/Write
#Description
Creates or updates the diagnostic setting for the resource
Microsoft.OperationalInsights/workspaces/purge/action
#Description
Delete specified data by query from workspace.
Microsoft.OperationalInsights/workspaces/restoreLogs/write
#Description
Restore data from a table.
Microsoft.OperationalInsights/workspaces/savedSearches/delete
#Description
Deletes a saved search query
Microsoft.OperationalInsights/workspaces/savedSearches/schedules/actions/delete
#Description
Create or update scheduled search action.
Microsoft.OperationalInsights/workspaces/savedSearches/schedules/actions/write
#Description
Delete Management Configuration action.
Microsoft.OperationalInsights/workspaces/savedSearches/schedules/delete
#Description
Delete scheduled saved search.
Microsoft.OperationalInsights/workspaces/savedSearches/schedules/write
#Description
Create or update scheduled saved search.
Microsoft.OperationalInsights/workspaces/savedSearches/write
#Description
Creates a saved search query
Microsoft.OperationalInsights/workspaces/scopedprivatelinkproxies/delete
#Description
Delete Scoped Private Link Proxy
Microsoft.OperationalInsights/workspaces/scopedprivatelinkproxies/write
#Description
Put Scoped Private Link Proxy
Microsoft.OperationalInsights/workspaces/search/action
#Description
Executes a search query
Microsoft.OperationalInsights/workspaces/searchJobs/write
#Description
Run a search job.
Microsoft.OperationalInsights/workspaces/storageinsightconfigs/delete
#Description
Deletes a storage configuration. This will stop Microsoft Operational Insights from reading data from the storage account.
Microsoft.OperationalInsights/workspaces/storageinsightconfigs/write
#Description
Creates a new storage configuration. These configurations are used to pull data from a location in an existing storage account.
Microsoft.OperationalInsights/workspaces/summarylogs/delete
#Description
Delete a log analytics summary rule.
Microsoft.OperationalInsights/workspaces/summarylogs/start/action
#Description
Starting a suspended summary rule.
Microsoft.OperationalInsights/workspaces/summarylogs/stop/action
#Description
Suspending a summary rule.
Microsoft.OperationalInsights/workspaces/summarylogs/write
#Description
Create or update a log analytics table.
Microsoft.OperationalInsights/workspaces/tables/delete
#Description
Delete a log analytics table.
Microsoft.OperationalInsights/workspaces/tables/deleteData/action
#Description
Delete Data from log analytics workspace.
Microsoft.OperationalInsights/workspaces/tables/migrate/action
#Description
Migrating a log analytics V1 table to V2 variation.
Microsoft.OperationalInsights/workspaces/tables/protectionLevel/write
#Description
Set or change the protection level of a Log Analytics table.
Microsoft.OperationalInsights/workspaces/tables/write
#Description
Create or update a log analytics table.
Microsoft.OperationalInsights/workspaces/views/delete
#Description
Delete workspace view.
Microsoft.OperationalInsights/workspaces/views/write
#Description
Create or update workspace view.
Microsoft.OperationalInsights/workspaces/write
#Description
Creates a new workspace or links to an existing workspace by providing the customer id from the existing workspace.
Example Resource Log Record #
{
"ActivityStatusValue": "Success",
"Authorization": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dwh2220afworkspaces",
"action": "Microsoft.OperationalInsights/workspaces/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Authorization_d": {
"scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dwh2220afworkspaces",
"action": "Microsoft.OperationalInsights/workspaces/write",
"evidence": {
"role": "Owner",
"roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
"roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
"roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
"principalId": "aaaaaaaa000000000000000000000001",
"principalType": "User"
}
},
"Caller": "adminuser@example.onmicrosoft.com",
"CallerIpAddress": "203.0.113.10",
"CategoryValue": "Administrative",
"Claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783031139",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"idtyp": "user",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"puid": "1111111111111111",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"correlationid": "92e14111-ba90-4c2c-954e-744fdf7b492b"
},
"Claims_d": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
"iat": "1783012099",
"nbf": "1783012099",
"exp": "1783031139",
"aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"appidacr": "0",
"idtyp": "user",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
"rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
"http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
"uti": "eyUvMswr6EqJhPARR0x4AA",
"ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
"xms_act_fct": "5 3",
"xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
"xms_idrel": "24 1",
"xms_sub_fct": "3 4",
"xms_tcdt": "1768616282",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"acrs": "p1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
"groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
"ipaddr": "203.0.113.10",
"name": "Admin User",
"puid": "1111111111111111",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"sid": "0022840a-e4ab-884c-587f-d20d24637227",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
"correlationid": "92e14111-ba90-4c2c-954e-744fdf7b492b"
},
"CorrelationId": "92e14111-ba90-4c2c-954e-744fdf7b492b",
"EventDataId": "376eab80-9953-972a-8afd-5d052763287f",
"EventSubmissionTimestamp": "2026-07-02T18:25:59.7962141Z",
"HTTPRequest": {
"clientIpAddress": "203.0.113.10"
},
"Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"Level": "Information",
"OperationNameValue": "MICROSOFT.OPERATIONALINSIGHTS/WORKSPACES/WRITE",
"Properties": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dwh2220afworkspaces",
"message": "Microsoft.OperationalInsights/workspaces/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "376eab80-9953-972a-8afd-5d052763287f",
"eventSubmissionTimestamp": "2026-07-02T18:25:59.7962141Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afworkspaces",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"Properties_d": {
"eventCategory": "Administrative",
"entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dwh2220afworkspaces",
"message": "Microsoft.OperationalInsights/workspaces/write",
"hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
"caller": "adminuser@example.onmicrosoft.com",
"eventDataId": "376eab80-9953-972a-8afd-5d052763287f",
"eventSubmissionTimestamp": "2026-07-02T18:25:59.7962141Z",
"httpRequest": {
"clientIpAddress": "203.0.113.10"
},
"resource": "dwh2220afworkspaces",
"resourceGroup": "rg-logcapture-gen",
"resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
"subscriptionId": "22222222-2222-2222-2222-222222222222",
"activityStatusValue": "Success"
},
"ResourceGroup": "rg-logcapture-gen",
"ResourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
"SubscriptionId": "22222222-2222-2222-2222-222222222222"
}