Log Analytics (Azure Monitor) Azure-Microsoft.OperationalInsights

operationNameDescriptionSampleRule
anyCatch-all for Azure-Microsoft.OperationalInsights rules that match the resource provider but no specific operation.NN
Microsoft.OperationalInsights/clusters/deleteDelete ClusterNN
Microsoft.OperationalInsights/clusters/writeCreate or updates a ClusterNN
Microsoft.OperationalInsights/locations/workspaces/failover/actionInitiates workspace failover to replication location.NN
Microsoft.OperationalInsights/querypacks/actionPerform Query Pack Action.NN
Microsoft.OperationalInsights/querypacks/deleteDelete Query Pack.YN
Microsoft.OperationalInsights/querypacks/queries/actionPerform Action on Queries in Query Pack.NN
Microsoft.OperationalInsights/querypacks/queries/deleteDelete Query Pack Queries.NN
Microsoft.OperationalInsights/querypacks/queries/writeCreate or update Query Pack Queries.NN
Microsoft.OperationalInsights/querypacks/writeCreate or update Query Pack.YN
Microsoft.OperationalInsights/register/actionRegister a subscription to a resource provider.NN
Microsoft.OperationalInsights/unregister/actionUnRegister a subscription to a resource provider.NN
Microsoft.OperationalInsights/workspaces/analytics/query/actionSearch using new engine.NN
Microsoft.OperationalInsights/workspaces/api/query/actionSearch using new engine.NN
Microsoft.OperationalInsights/workspaces/configurationscopes/deleteDelete configuration scope in a workspace.NN
Microsoft.OperationalInsights/workspaces/configurationscopes/writeCreate configuration scope in a workspace.NN
Microsoft.OperationalInsights/workspaces/customfields/actionExtract custom fields.NN
Microsoft.OperationalInsights/workspaces/customfields/deleteDelete a custom field.NN
Microsoft.OperationalInsights/workspaces/customfields/writeCreate or update a custom field.NN
Microsoft.OperationalInsights/workspaces/dataexports/deleteDelete specific Data Export/NN
Microsoft.OperationalInsights/workspaces/dataexports/writeCreate or update specific data export.NN
Microsoft.OperationalInsights/workspaces/datasources/deleteDelete data source under a workspace.NN
Microsoft.OperationalInsights/workspaces/datasources/writeUpsert Data SourceNN
Microsoft.OperationalInsights/workspaces/deleteDeletes a workspace. If the workspace was linked to an existing workspace at creation time then the workspace it was linked to is not deleted.YY
Microsoft.OperationalInsights/workspaces/failback/actionInitiates workspace failback.NN
Microsoft.OperationalInsights/workspaces/gateways/deleteRemoves a gateway configured for the workspace.NN
Microsoft.OperationalInsights/workspaces/intelligencepacks/disable/actionDisables an intelligence pack for a given workspace.NN
Microsoft.OperationalInsights/workspaces/intelligencepacks/enable/actionEnables an intelligence pack for a given workspace.NN
Microsoft.OperationalInsights/workspaces/linkedservices/deleteDelete linked services under given workspace.NN
Microsoft.OperationalInsights/workspaces/linkedservices/writeCreate or update linked services under given workspace.NN
Microsoft.OperationalInsights/workspaces/linkedstorageaccounts/deleteDelete a Log Analytics Workspace Linked Storage Account.NN
Microsoft.OperationalInsights/workspaces/linkedstorageaccounts/writePut a Log Analytics Workspace Linked Storage Account.NN
Microsoft.OperationalInsights/workspaces/listKeys/actionRetrieves the list keys for the workspace. These keys are used to connect Microsoft Operational Insights agents to the workspace.NN
Microsoft.OperationalInsights/workspaces/networkSecurityPerimeterAssociationProxies/deleteDelete Network Security Perimeter Association Proxies.NN
Microsoft.OperationalInsights/workspaces/networkSecurityPerimeterAssociationProxies/writeWrite Network Security Perimeter Association Proxies.NN
Microsoft.OperationalInsights/workspaces/networkSecurityPerimeterConfigurations/reconcile/actionReconcile operation for Network Security Perimeter Configurations.NN
Microsoft.OperationalInsights/workspaces/notificationsettings/deleteDelete the user's notification settings for the workspace.NN
Microsoft.OperationalInsights/workspaces/notificationsettings/writeSet the user's notification settings for the workspace.NN
Microsoft.OperationalInsights/workspaces/providers/Microsoft.Insights/diagnosticSettings/WriteCreates or updates the diagnostic setting for the resourceNN
Microsoft.OperationalInsights/workspaces/purge/actionDelete specified data by query from workspace.NN
Microsoft.OperationalInsights/workspaces/regenerateSharedKey/actionRegenerates the specified workspace shared keyNN
Microsoft.OperationalInsights/workspaces/restoreLogs/writeRestore data from a table.NN
Microsoft.OperationalInsights/workspaces/savedSearches/deleteDeletes a saved search queryNN
Microsoft.OperationalInsights/workspaces/savedSearches/schedules/actions/deleteCreate or update scheduled search action.NN
Microsoft.OperationalInsights/workspaces/savedSearches/schedules/actions/writeDelete Management Configuration action.NN
Microsoft.OperationalInsights/workspaces/savedSearches/schedules/deleteDelete scheduled saved search.NN
Microsoft.OperationalInsights/workspaces/savedSearches/schedules/writeCreate or update scheduled saved search.NN
Microsoft.OperationalInsights/workspaces/savedSearches/writeCreates a saved search queryNN
Microsoft.OperationalInsights/workspaces/scopedprivatelinkproxies/deleteDelete Scoped Private Link ProxyNN
Microsoft.OperationalInsights/workspaces/scopedprivatelinkproxies/writePut Scoped Private Link ProxyNN
Microsoft.OperationalInsights/workspaces/search/actionExecutes a search queryNN
Microsoft.OperationalInsights/workspaces/searchJobs/writeRun a search job.NN
Microsoft.OperationalInsights/workspaces/sharedkeys/actionRetrieves the shared keys for the workspace. These keys are used to connect Microsoft Operational Insights agents to the workspace.NN
Microsoft.OperationalInsights/workspaces/storageinsightconfigs/deleteDeletes a storage configuration. This will stop Microsoft Operational Insights from reading data from the storage account.NN
Microsoft.OperationalInsights/workspaces/storageinsightconfigs/writeCreates a new storage configuration. These configurations are used to pull data from a location in an existing storage account.NN
Microsoft.OperationalInsights/workspaces/summarylogs/deleteDelete a log analytics summary rule.NN
Microsoft.OperationalInsights/workspaces/summarylogs/start/actionStarting a suspended summary rule.NN
Microsoft.OperationalInsights/workspaces/summarylogs/stop/actionSuspending a summary rule.NN
Microsoft.OperationalInsights/workspaces/summarylogs/writeCreate or update a log analytics table.NN
Microsoft.OperationalInsights/workspaces/tables/deleteDelete a log analytics table.NN
Microsoft.OperationalInsights/workspaces/tables/deleteData/actionDelete Data from log analytics workspace.NN
Microsoft.OperationalInsights/workspaces/tables/migrate/actionMigrating a log analytics V1 table to V2 variation.NN
Microsoft.OperationalInsights/workspaces/tables/protectionLevel/writeSet or change the protection level of a Log Analytics table.NN
Microsoft.OperationalInsights/workspaces/tables/writeCreate or update a log analytics table.NN
Microsoft.OperationalInsights/workspaces/views/deleteDelete workspace view.NN
Microsoft.OperationalInsights/workspaces/views/writeCreate or update workspace view.NN
Microsoft.OperationalInsights/workspaces/writeCreates a new workspace or links to an existing workspace by providing the customer id from the existing workspace.YN

any: Log Analytics (Azure Monitor) (catch-all)

#
Namespace
Microsoft.OperationalInsights

Description

Catch-all for Azure-Microsoft.OperationalInsights rules that match the resource provider but no specific operation.

Microsoft.OperationalInsights/clusters/delete

#
Namespace
Microsoft.OperationalInsights

Description

Delete Cluster

Microsoft.OperationalInsights/clusters/write

#
Namespace
Microsoft.OperationalInsights

Description

Create or updates a Cluster

Microsoft.OperationalInsights/locations/workspaces/failover/action

#
Namespace
Microsoft.OperationalInsights

Description

Initiates workspace failover to replication location.

Microsoft.OperationalInsights/querypacks/action

#
Namespace
Microsoft.OperationalInsights

Description

Perform Query Pack Action.

Microsoft.OperationalInsights/querypacks/delete

#
Namespace
Microsoft.OperationalInsights

Description

Delete Query Pack.

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/queryPacks/dwh2220afquerypacks",
    "action": "Microsoft.OperationalInsights/queryPacks/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/queryPacks/dwh2220afquerypacks",
    "action": "Microsoft.OperationalInsights/queryPacks/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "2322f576-5aef-49d0-9726-1446daeedb7b",
  "EventDataId": "af59c1db-413b-f8ff-cc05-328a2f1742db",
  "EventSubmissionTimestamp": "2026-07-02T18:35:37.8948205Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.OPERATIONALINSIGHTS/QUERYPACKS/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/querypacks/dwh2220afquerypacks",
    "message": "Microsoft.OperationalInsights/querypacks/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "af59c1db-413b-f8ff-cc05-328a2f1742db",
    "eventSubmissionTimestamp": "2026-07-02T18:35:37.8948205Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afquerypacks",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/querypacks/dwh2220afquerypacks",
    "message": "Microsoft.OperationalInsights/querypacks/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "af59c1db-413b-f8ff-cc05-328a2f1742db",
    "eventSubmissionTimestamp": "2026-07-02T18:35:37.8948205Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afquerypacks",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.OperationalInsights/querypacks/queries/action

#
Namespace
Microsoft.OperationalInsights

Description

Perform Action on Queries in Query Pack.

Microsoft.OperationalInsights/querypacks/queries/delete

#
Namespace
Microsoft.OperationalInsights

Description

Delete Query Pack Queries.

Microsoft.OperationalInsights/querypacks/queries/write

#
Namespace
Microsoft.OperationalInsights

Description

Create or update Query Pack Queries.

Microsoft.OperationalInsights/querypacks/write

#
Namespace
Microsoft.OperationalInsights

Description

Create or update Query Pack.

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "Created",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/queryPacks/dwh2220afquerypacks",
    "action": "Microsoft.OperationalInsights/queryPacks/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/queryPacks/dwh2220afquerypacks",
    "action": "Microsoft.OperationalInsights/queryPacks/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "4ce9b326-b99c-4ba8-88c5-d3f793ebdedd",
  "EventDataId": "e840c5ac-5a33-92f8-9429-68887e354818",
  "EventSubmissionTimestamp": "2026-07-02T18:25:35.8815881Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.OPERATIONALINSIGHTS/QUERYPACKS/WRITE",
  "Properties": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/queryPacks/dwh2220afquerypacks",
    "message": "Microsoft.OperationalInsights/queryPacks/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "e840c5ac-5a33-92f8-9429-68887e354818",
    "eventSubmissionTimestamp": "2026-07-02T18:25:35.8815881Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afquerypacks",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "Created"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/queryPacks/dwh2220afquerypacks",
    "message": "Microsoft.OperationalInsights/queryPacks/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "e840c5ac-5a33-92f8-9429-68887e354818",
    "eventSubmissionTimestamp": "2026-07-02T18:25:35.8815881Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afquerypacks",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "Created",
    "serviceRequestId": "",
    "activitySubstatusValue": "Created"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.OperationalInsights/register/action

#
Namespace
Microsoft.OperationalInsights

Description

Register a subscription to a resource provider.

Microsoft.OperationalInsights/unregister/action

#
Namespace
Microsoft.OperationalInsights

Description

UnRegister a subscription to a resource provider.

Microsoft.OperationalInsights/workspaces/analytics/query/action

#
Namespace
Microsoft.OperationalInsights

Description

Search using new engine.

Microsoft.OperationalInsights/workspaces/api/query/action

#
Namespace
Microsoft.OperationalInsights

Description

Search using new engine.

Microsoft.OperationalInsights/workspaces/configurationscopes/delete

#
Namespace
Microsoft.OperationalInsights

Description

Delete configuration scope in a workspace.

Microsoft.OperationalInsights/workspaces/configurationscopes/write

#
Namespace
Microsoft.OperationalInsights

Description

Create configuration scope in a workspace.

Microsoft.OperationalInsights/workspaces/customfields/action

#
Namespace
Microsoft.OperationalInsights

Description

Extract custom fields.

Microsoft.OperationalInsights/workspaces/customfields/delete

#
Namespace
Microsoft.OperationalInsights

Description

Delete a custom field.

Microsoft.OperationalInsights/workspaces/customfields/write

#
Namespace
Microsoft.OperationalInsights

Description

Create or update a custom field.

Microsoft.OperationalInsights/workspaces/dataexports/delete

#
Namespace
Microsoft.OperationalInsights

Description

Delete specific Data Export/

Microsoft.OperationalInsights/workspaces/dataexports/write

#
Namespace
Microsoft.OperationalInsights

Description

Create or update specific data export.

Microsoft.OperationalInsights/workspaces/datasources/delete

#
Namespace
Microsoft.OperationalInsights

Description

Delete data source under a workspace.

Microsoft.OperationalInsights/workspaces/datasources/write

#
Namespace
Microsoft.OperationalInsights

Description

Upsert Data Source

Microsoft.OperationalInsights/workspaces/delete

#
Namespace
Microsoft.OperationalInsights

Description

Deletes a workspace. If the workspace was linked to an existing workspace at creation time then the workspace it was linked to is not deleted.

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dwh2220afworkspaces",
    "action": "Microsoft.OperationalInsights/workspaces/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dwh2220afworkspaces",
    "action": "Microsoft.OperationalInsights/workspaces/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783031172",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "correlationid": "c6a9c8bf-f7a5-4cbd-9871-7aa2e0aad1b7"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783031172",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "correlationid": "c6a9c8bf-f7a5-4cbd-9871-7aa2e0aad1b7"
  },
  "CorrelationId": "c6a9c8bf-f7a5-4cbd-9871-7aa2e0aad1b7",
  "EventDataId": "fae22d15-92bf-26df-d91d-9707101d63d0",
  "EventSubmissionTimestamp": "2026-07-02T18:26:34.181936Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.OPERATIONALINSIGHTS/WORKSPACES/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dwh2220afworkspaces",
    "message": "Microsoft.OperationalInsights/workspaces/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "fae22d15-92bf-26df-d91d-9707101d63d0",
    "eventSubmissionTimestamp": "2026-07-02T18:26:34.181936Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afworkspaces",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dwh2220afworkspaces",
    "message": "Microsoft.OperationalInsights/workspaces/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "fae22d15-92bf-26df-d91d-9707101d63d0",
    "eventSubmissionTimestamp": "2026-07-02T18:26:34.1819360Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afworkspaces",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

Microsoft.OperationalInsights/workspaces/failback/action

#
Namespace
Microsoft.OperationalInsights

Description

Initiates workspace failback.

Microsoft.OperationalInsights/workspaces/gateways/delete

#
Namespace
Microsoft.OperationalInsights

Description

Removes a gateway configured for the workspace.

Microsoft.OperationalInsights/workspaces/intelligencepacks/disable/action

#
Namespace
Microsoft.OperationalInsights

Description

Disables an intelligence pack for a given workspace.

Microsoft.OperationalInsights/workspaces/intelligencepacks/enable/action

#
Namespace
Microsoft.OperationalInsights

Description

Enables an intelligence pack for a given workspace.

Microsoft.OperationalInsights/workspaces/linkedservices/delete

#
Namespace
Microsoft.OperationalInsights

Description

Delete linked services under given workspace.

Microsoft.OperationalInsights/workspaces/linkedservices/write

#
Namespace
Microsoft.OperationalInsights

Description

Create or update linked services under given workspace.

Microsoft.OperationalInsights/workspaces/linkedstorageaccounts/delete

#
Namespace
Microsoft.OperationalInsights

Description

Delete a Log Analytics Workspace Linked Storage Account.

Microsoft.OperationalInsights/workspaces/linkedstorageaccounts/write

#
Namespace
Microsoft.OperationalInsights

Description

Put a Log Analytics Workspace Linked Storage Account.

Microsoft.OperationalInsights/workspaces/listKeys/action

#
Namespace
Microsoft.OperationalInsights

Description

Retrieves the list keys for the workspace. These keys are used to connect Microsoft Operational Insights agents to the workspace.

Microsoft.OperationalInsights/workspaces/networkSecurityPerimeterAssociationProxies/delete

#
Namespace
Microsoft.OperationalInsights

Description

Delete Network Security Perimeter Association Proxies.

Microsoft.OperationalInsights/workspaces/networkSecurityPerimeterAssociationProxies/write

#
Namespace
Microsoft.OperationalInsights

Description

Write Network Security Perimeter Association Proxies.

Microsoft.OperationalInsights/workspaces/networkSecurityPerimeterConfigurations/reconcile/action

#
Namespace
Microsoft.OperationalInsights

Description

Reconcile operation for Network Security Perimeter Configurations.

Microsoft.OperationalInsights/workspaces/notificationsettings/delete

#
Namespace
Microsoft.OperationalInsights

Description

Delete the user's notification settings for the workspace.

Microsoft.OperationalInsights/workspaces/notificationsettings/write

#
Namespace
Microsoft.OperationalInsights

Description

Set the user's notification settings for the workspace.

Microsoft.OperationalInsights/workspaces/providers/Microsoft.Insights/diagnosticSettings/Write

#
Namespace
Microsoft.OperationalInsights

Description

Creates or updates the diagnostic setting for the resource

Microsoft.OperationalInsights/workspaces/purge/action

#
Namespace
Microsoft.OperationalInsights

Description

Delete specified data by query from workspace.

Microsoft.OperationalInsights/workspaces/regenerateSharedKey/action

#
Namespace
Microsoft.OperationalInsights

Description

Regenerates the specified workspace shared key

Microsoft.OperationalInsights/workspaces/restoreLogs/write

#
Namespace
Microsoft.OperationalInsights

Description

Restore data from a table.

Microsoft.OperationalInsights/workspaces/savedSearches/delete

#
Namespace
Microsoft.OperationalInsights

Description

Deletes a saved search query

Microsoft.OperationalInsights/workspaces/savedSearches/schedules/actions/delete

#
Namespace
Microsoft.OperationalInsights

Description

Create or update scheduled search action.

Microsoft.OperationalInsights/workspaces/savedSearches/schedules/actions/write

#
Namespace
Microsoft.OperationalInsights

Description

Delete Management Configuration action.

Microsoft.OperationalInsights/workspaces/savedSearches/schedules/delete

#
Namespace
Microsoft.OperationalInsights

Description

Delete scheduled saved search.

Microsoft.OperationalInsights/workspaces/savedSearches/schedules/write

#
Namespace
Microsoft.OperationalInsights

Description

Create or update scheduled saved search.

Microsoft.OperationalInsights/workspaces/savedSearches/write

#
Namespace
Microsoft.OperationalInsights

Description

Creates a saved search query

Microsoft.OperationalInsights/workspaces/scopedprivatelinkproxies/delete

#
Namespace
Microsoft.OperationalInsights

Description

Delete Scoped Private Link Proxy

Microsoft.OperationalInsights/workspaces/scopedprivatelinkproxies/write

#
Namespace
Microsoft.OperationalInsights

Description

Put Scoped Private Link Proxy

Microsoft.OperationalInsights/workspaces/search/action

#
Namespace
Microsoft.OperationalInsights

Description

Executes a search query

Microsoft.OperationalInsights/workspaces/searchJobs/write

#
Namespace
Microsoft.OperationalInsights

Description

Run a search job.

Microsoft.OperationalInsights/workspaces/sharedkeys/action

#
Namespace
Microsoft.OperationalInsights

Description

Retrieves the shared keys for the workspace. These keys are used to connect Microsoft Operational Insights agents to the workspace.

Microsoft.OperationalInsights/workspaces/storageinsightconfigs/delete

#
Namespace
Microsoft.OperationalInsights

Description

Deletes a storage configuration. This will stop Microsoft Operational Insights from reading data from the storage account.

Microsoft.OperationalInsights/workspaces/storageinsightconfigs/write

#
Namespace
Microsoft.OperationalInsights

Description

Creates a new storage configuration. These configurations are used to pull data from a location in an existing storage account.

Microsoft.OperationalInsights/workspaces/summarylogs/delete

#
Namespace
Microsoft.OperationalInsights

Description

Delete a log analytics summary rule.

Microsoft.OperationalInsights/workspaces/summarylogs/start/action

#
Namespace
Microsoft.OperationalInsights

Description

Starting a suspended summary rule.

Microsoft.OperationalInsights/workspaces/summarylogs/stop/action

#
Namespace
Microsoft.OperationalInsights

Description

Suspending a summary rule.

Microsoft.OperationalInsights/workspaces/summarylogs/write

#
Namespace
Microsoft.OperationalInsights

Description

Create or update a log analytics table.

Microsoft.OperationalInsights/workspaces/tables/delete

#
Namespace
Microsoft.OperationalInsights

Description

Delete a log analytics table.

Microsoft.OperationalInsights/workspaces/tables/deleteData/action

#
Namespace
Microsoft.OperationalInsights

Description

Delete Data from log analytics workspace.

Microsoft.OperationalInsights/workspaces/tables/migrate/action

#
Namespace
Microsoft.OperationalInsights

Description

Migrating a log analytics V1 table to V2 variation.

Microsoft.OperationalInsights/workspaces/tables/protectionLevel/write

#
Namespace
Microsoft.OperationalInsights

Description

Set or change the protection level of a Log Analytics table.

Microsoft.OperationalInsights/workspaces/tables/write

#
Namespace
Microsoft.OperationalInsights

Description

Create or update a log analytics table.

Microsoft.OperationalInsights/workspaces/views/delete

#
Namespace
Microsoft.OperationalInsights

Description

Delete workspace view.

Microsoft.OperationalInsights/workspaces/views/write

#
Namespace
Microsoft.OperationalInsights

Description

Create or update workspace view.

Microsoft.OperationalInsights/workspaces/write

#
Namespace
Microsoft.OperationalInsights

Description

Creates a new workspace or links to an existing workspace by providing the customer id from the existing workspace.

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dwh2220afworkspaces",
    "action": "Microsoft.OperationalInsights/workspaces/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dwh2220afworkspaces",
    "action": "Microsoft.OperationalInsights/workspaces/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783031139",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "correlationid": "92e14111-ba90-4c2c-954e-744fdf7b492b"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783031139",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "correlationid": "92e14111-ba90-4c2c-954e-744fdf7b492b"
  },
  "CorrelationId": "92e14111-ba90-4c2c-954e-744fdf7b492b",
  "EventDataId": "376eab80-9953-972a-8afd-5d052763287f",
  "EventSubmissionTimestamp": "2026-07-02T18:25:59.7962141Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.OPERATIONALINSIGHTS/WORKSPACES/WRITE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dwh2220afworkspaces",
    "message": "Microsoft.OperationalInsights/workspaces/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "376eab80-9953-972a-8afd-5d052763287f",
    "eventSubmissionTimestamp": "2026-07-02T18:25:59.7962141Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afworkspaces",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dwh2220afworkspaces",
    "message": "Microsoft.OperationalInsights/workspaces/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "376eab80-9953-972a-8afd-5d052763287f",
    "eventSubmissionTimestamp": "2026-07-02T18:25:59.7962141Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwh2220afworkspaces",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #