Azure AI Search Azure-Microsoft.Search

operationNameDescriptionSampleRule
anyCatch-all for Azure-Microsoft.Search rules that match the resource provider but no specific operation.NN
Microsoft.Search/checkNameAvailability/actionChecks availability of the service name.NN
Microsoft.Search/locations/notifyNetworkSecurityPerimeterUpdatesAvailable/writeCheck if the configuration of the Network Security Perimeter needs updating.NN
Microsoft.Search/register/actionRegisters the subscription for the search resource provider and enables the creation of search services.YN
Microsoft.Search/searchServices/agents/deleteDelete an agent.NN
Microsoft.Search/searchServices/agents/writeCreate new agents or modify existing agent configurations.NN
Microsoft.Search/searchServices/aliases/deleteDelete an alias.NN
Microsoft.Search/searchServices/aliases/writeCreate an alias or modify its properties.NN
Microsoft.Search/searchServices/createQueryKey/actionCreates the query key.NN
Microsoft.Search/searchServices/dataSources/deleteDelete a data source.NN
Microsoft.Search/searchServices/dataSources/writeCreate a data source or modify its properties.NN
Microsoft.Search/searchServices/debugSessions/deleteDelete a debug session.NN
Microsoft.Search/searchServices/debugSessions/execute/actionUse a debug session, get execution data, or evaluate expressions on it.NN
Microsoft.Search/searchServices/debugSessions/writeCreate a debug session or modify its properties.NN
Microsoft.Search/searchServices/deleteDeletes the search service.YN
Microsoft.Search/searchServices/deleteQueryKey/deleteDeletes the query key.NN
Microsoft.Search/searchServices/diagnosticSettings/writeCreates or updates the diagnostic setting for the resourceNN
Microsoft.Search/searchServices/indexers/deleteDelete an indexer.NN
Microsoft.Search/searchServices/indexers/writeCreate an indexer, modify its properties, or manage its execution.NN
Microsoft.Search/searchServices/indexes/deleteDelete an index.NN
Microsoft.Search/searchServices/indexes/writeCreate an index or modify its properties.NN
Microsoft.Search/searchServices/knowledgeBases/deleteDelete a knowledge base.NN
Microsoft.Search/searchServices/knowledgeBases/writeCreate a knowledge base or modify its properties.NN
Microsoft.Search/searchServices/knowledgeSources/deleteDelete a knowledge source.NN
Microsoft.Search/searchServices/knowledgeSources/writeCreate new knowledge sources or modify existing knowledge sources.NN
Microsoft.Search/searchServices/listAdminKeys/actionReads the admin keys.NN
Microsoft.Search/searchServices/listQueryKeys/actionReturns the list of query API keys for the given Azure Search service.NN
Microsoft.Search/searchServices/networkSecurityPerimeterAssociationProxies/deleteDelete an association proxy to a Network Security Perimeter resource of Microsoft.Network provider.NN
Microsoft.Search/searchServices/networkSecurityPerimeterAssociationProxies/writeChange the state of an association to a Network Security Perimeter resource of Microsoft.Network providerNN
Microsoft.Search/searchServices/networkSecurityPerimeterConfigurations/reconcile/actionReconcile the Network Security Perimeter configuration with NRP's (Microsoft.Network Resource Provider) copy.NN
Microsoft.Search/searchServices/privateEndpointConnectionProxies/deleteDeletes an existing private endpoint connection proxyNN
Microsoft.Search/searchServices/privateEndpointConnectionProxies/validate/actionValidates a private endpoint connection create call from NRP sideNN
Microsoft.Search/searchServices/privateEndpointConnectionProxies/writeCreates a private endpoint connection proxy with the specified parameters or updates the properties or tags for the specified private endpoint connection proxyNN
Microsoft.Search/searchServices/privateEndpointConnections/deleteDeletes an existing private endpoint connectionsNN
Microsoft.Search/searchServices/privateEndpointConnections/writeCreates a private endpoint connections with the specified parameters or updates the properties or tags for the specified private endpoint connectionsNN
Microsoft.Search/searchServices/privateEndpointConnectionsApproval/actionApprove Private Endpoint ConnectionNN
Microsoft.Search/searchServices/regenerateAdminKey/actionRegenerates the admin key.NN
Microsoft.Search/searchServices/sharedPrivateLinkResources/deleteDeletes an existing shared private link resourceNN
Microsoft.Search/searchServices/sharedPrivateLinkResources/writeCreates a new shared private link resource with the specified parameters or updates the properties for the specified shared private link resourceNN
Microsoft.Search/searchServices/skillsets/deleteDelete a skillset.NN
Microsoft.Search/searchServices/skillsets/writeCreate a skillset or modify its properties.NN
Microsoft.Search/searchServices/start/actionStarts the search service.NN
Microsoft.Search/searchServices/stop/actionStops the search service.NN
Microsoft.Search/searchServices/synonymMaps/deleteDelete a synonym map.NN
Microsoft.Search/searchServices/synonymMaps/writeCreate a synonym map or modify its properties.NN
Microsoft.Search/searchServices/writeCreates or updates the search service.YN

any: Azure AI Search (catch-all)

#
Namespace
Microsoft.Search

Description

Catch-all for Azure-Microsoft.Search rules that match the resource provider but no specific operation.

Microsoft.Search/checkNameAvailability/action

#
Namespace
Microsoft.Search

Description

Checks availability of the service name.

Microsoft.Search/locations/notifyNetworkSecurityPerimeterUpdatesAvailable/write

#
Namespace
Microsoft.Search

Description

Check if the configuration of the Network Security Perimeter needs updating.

Microsoft.Search/register/action

#
Namespace
Microsoft.Search

Description

Registers the subscription for the search resource provider and enables the creation of search services.

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "OK",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
    "action": "Microsoft.Search/register/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222",
    "action": "Microsoft.Search/register/action",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783012099",
    "nbf": "1783012099",
    "exp": "1783017701",
    "aio": "AXQAi/8cAAAAICIgGVONYdaNx/1snvX3s8KrpUMqKU1iXqIadxiu82gVEJAvHYNrOvXG+NHHfGfTck3ZHLhiYCsr3drrAIpgGkm+UY127NHbcWpDIvfua4QF6MoSbbj2Q8ekvpSlCw6WzLP3HwxTyNn70TNCRgq2Mg==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "eyUvMswr6EqJhPARR0x4AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "_yYfS1Dsz6HFh8q4mYaAf6M93yk_I-vt3b84gSLpQ4UBdXNub3J0aC1kc21z",
    "xms_idrel": "24 1",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "f21143ed-c884-40b9-8a59-b555594ceaee",
  "EventDataId": "b1a16111-a0b2-9137-33a3-74fa14cf3aa4",
  "EventSubmissionTimestamp": "2026-07-02T17:30:04.3890543Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.SEARCH/REGISTER/ACTION",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Search",
    "message": "Microsoft.Search/register/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "b1a16111-a0b2-9137-33a3-74fa14cf3aa4",
    "eventSubmissionTimestamp": "2026-07-02T17:30:04.3890543Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resourceProviderValue": "MICROSOFT.SEARCH",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/providers/Microsoft.Search",
    "message": "Microsoft.Search/register/action",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "b1a16111-a0b2-9137-33a3-74fa14cf3aa4",
    "eventSubmissionTimestamp": "2026-07-02T17:30:04.3890543Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resourceProviderValue": "MICROSOFT.SEARCH",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "OK",
    "serviceRequestId": "",
    "activitySubstatusValue": "OK"
  },
  "ResourceProviderValue": "MICROSOFT.SEARCH",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Search/searchServices/agents/delete

#
Namespace
Microsoft.Search

Description

Delete an agent.

Microsoft.Search/searchServices/agents/write

#
Namespace
Microsoft.Search

Description

Create new agents or modify existing agent configurations.

Microsoft.Search/searchServices/aliases/delete

#
Namespace
Microsoft.Search

Description

Delete an alias.

Microsoft.Search/searchServices/aliases/write

#
Namespace
Microsoft.Search

Description

Create an alias or modify its properties.

Microsoft.Search/searchServices/createQueryKey/action

#
Namespace
Microsoft.Search

Description

Creates the query key.

Microsoft.Search/searchServices/dataSources/delete

#
Namespace
Microsoft.Search

Description

Delete a data source.

Microsoft.Search/searchServices/dataSources/write

#
Namespace
Microsoft.Search

Description

Create a data source or modify its properties.

Microsoft.Search/searchServices/debugSessions/delete

#
Namespace
Microsoft.Search

Description

Delete a debug session.

Microsoft.Search/searchServices/debugSessions/execute/action

#
Namespace
Microsoft.Search

Description

Use a debug session, get execution data, or evaluate expressions on it.

Microsoft.Search/searchServices/debugSessions/write

#
Namespace
Microsoft.Search

Description

Create a debug session or modify its properties.

Microsoft.Search/searchServices/delete

#
Namespace
Microsoft.Search

Description

Deletes the search service.

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Search/searchServices/dwhc6a93dsearchservice",
    "action": "Microsoft.Search/searchServices/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Search/searchServices/dwhc6a93dsearchservice",
    "action": "Microsoft.Search/searchServices/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "4d71d4be-8c9c-44ec-b7cf-7c9878306ff9",
  "EventDataId": "f1b6b7c6-9cb2-3208-b3de-63fc4fa58dd8",
  "EventSubmissionTimestamp": "2026-07-03T02:25:59.387858Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.SEARCH/SEARCHSERVICES/DELETE",
  "Properties": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Search/searchServices/dwhc6a93dsearchservice",
    "message": "Microsoft.Search/searchServices/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "f1b6b7c6-9cb2-3208-b3de-63fc4fa58dd8",
    "eventSubmissionTimestamp": "2026-07-03T02:25:59.387858Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93dsearchservice",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.SEARCH",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourcegroups/rg-logcapture-gen/providers/Microsoft.Search/searchServices/dwhc6a93dsearchservice",
    "message": "Microsoft.Search/searchServices/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "f1b6b7c6-9cb2-3208-b3de-63fc4fa58dd8",
    "eventSubmissionTimestamp": "2026-07-03T02:25:59.3878580Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93dsearchservice",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.SEARCH",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.SEARCH",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

Microsoft.Search/searchServices/deleteQueryKey/delete

#
Namespace
Microsoft.Search

Description

Deletes the query key.

Microsoft.Search/searchServices/diagnosticSettings/write

#
Namespace
Microsoft.Search

Description

Creates or updates the diagnostic setting for the resource

Microsoft.Search/searchServices/indexers/delete

#
Namespace
Microsoft.Search

Description

Delete an indexer.

Microsoft.Search/searchServices/indexers/write

#
Namespace
Microsoft.Search

Description

Create an indexer, modify its properties, or manage its execution.

Microsoft.Search/searchServices/indexes/delete

#
Namespace
Microsoft.Search

Description

Delete an index.

Microsoft.Search/searchServices/indexes/write

#
Namespace
Microsoft.Search

Description

Create an index or modify its properties.

Microsoft.Search/searchServices/knowledgeBases/delete

#
Namespace
Microsoft.Search

Description

Delete a knowledge base.

Microsoft.Search/searchServices/knowledgeBases/write

#
Namespace
Microsoft.Search

Description

Create a knowledge base or modify its properties.

Microsoft.Search/searchServices/knowledgeSources/delete

#
Namespace
Microsoft.Search

Description

Delete a knowledge source.

Microsoft.Search/searchServices/knowledgeSources/write

#
Namespace
Microsoft.Search

Description

Create new knowledge sources or modify existing knowledge sources.

Microsoft.Search/searchServices/listAdminKeys/action

#
Namespace
Microsoft.Search

Description

Reads the admin keys.

Microsoft.Search/searchServices/listQueryKeys/action

#
Namespace
Microsoft.Search

Description

Returns the list of query API keys for the given Azure Search service.

Microsoft.Search/searchServices/networkSecurityPerimeterAssociationProxies/delete

#
Namespace
Microsoft.Search

Description

Delete an association proxy to a Network Security Perimeter resource of Microsoft.Network provider.

Microsoft.Search/searchServices/networkSecurityPerimeterAssociationProxies/write

#
Namespace
Microsoft.Search

Description

Change the state of an association to a Network Security Perimeter resource of Microsoft.Network provider

Microsoft.Search/searchServices/networkSecurityPerimeterConfigurations/reconcile/action

#
Namespace
Microsoft.Search

Description

Reconcile the Network Security Perimeter configuration with NRP's (Microsoft.Network Resource Provider) copy.

Microsoft.Search/searchServices/privateEndpointConnectionProxies/delete

#
Namespace
Microsoft.Search

Description

Deletes an existing private endpoint connection proxy

Microsoft.Search/searchServices/privateEndpointConnectionProxies/validate/action

#
Namespace
Microsoft.Search

Description

Validates a private endpoint connection create call from NRP side

Microsoft.Search/searchServices/privateEndpointConnectionProxies/write

#
Namespace
Microsoft.Search

Description

Creates a private endpoint connection proxy with the specified parameters or updates the properties or tags for the specified private endpoint connection proxy

Microsoft.Search/searchServices/privateEndpointConnections/delete

#
Namespace
Microsoft.Search

Description

Deletes an existing private endpoint connections

Microsoft.Search/searchServices/privateEndpointConnections/write

#
Namespace
Microsoft.Search

Description

Creates a private endpoint connections with the specified parameters or updates the properties or tags for the specified private endpoint connections

Microsoft.Search/searchServices/privateEndpointConnectionsApproval/action

#
Namespace
Microsoft.Search

Description

Approve Private Endpoint Connection

Microsoft.Search/searchServices/regenerateAdminKey/action

#
Namespace
Microsoft.Search

Description

Regenerates the admin key.

Microsoft.Search/searchServices/sharedPrivateLinkResources/delete

#
Namespace
Microsoft.Search

Description

Deletes an existing shared private link resource

Microsoft.Search/searchServices/sharedPrivateLinkResources/write

#
Namespace
Microsoft.Search

Description

Creates a new shared private link resource with the specified parameters or updates the properties for the specified shared private link resource

Microsoft.Search/searchServices/skillsets/delete

#
Namespace
Microsoft.Search

Description

Delete a skillset.

Microsoft.Search/searchServices/skillsets/write

#
Namespace
Microsoft.Search

Description

Create a skillset or modify its properties.

Microsoft.Search/searchServices/start/action

#
Namespace
Microsoft.Search

Description

Starts the search service.

Microsoft.Search/searchServices/stop/action

#
Namespace
Microsoft.Search

Description

Stops the search service.

Microsoft.Search/searchServices/synonymMaps/delete

#
Namespace
Microsoft.Search

Description

Delete a synonym map.

Microsoft.Search/searchServices/synonymMaps/write

#
Namespace
Microsoft.Search

Description

Create a synonym map or modify its properties.

Microsoft.Search/searchServices/write

#
Namespace
Microsoft.Search

Description

Creates or updates the search service.

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "Created",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Search/searchServices/dwhc6a93dsearchservice",
    "action": "Microsoft.Search/searchServices/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Search/searchServices/dwhc6a93dsearchservice",
    "action": "Microsoft.Search/searchServices/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783041418",
    "nbf": "1783041418",
    "exp": "1783045937",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAFIBIEdHXWN3pylNjmPLeQhWfcQ14ANLMkCfF9E8NqZtiUHdHNiO4QKChB+m3872z7F73QjwZK8qIldMrqscbefkaL+FBLWCt9JK9djz/ONZSfAxBzNSQV2uzP3xMJVD4RnM7NXOM1v57WDtsGbmO1g==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "tUdFU6nO4UmtUjpbHDqEAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "Jy-cEgg_SioO6K76SbtPp6tIHeVnjtpmAf1GT_VpKMsBdXNzb3V0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 4",
    "xms_tcdt": "1768616282"
  },
  "CorrelationId": "935f8e8d-d96a-4a9d-a1d0-2eb3c65b9485",
  "EventDataId": "87f404a0-be71-6de1-afe8-2744031406b9",
  "EventSubmissionTimestamp": "2026-07-03T02:15:57.539639Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.SEARCH/SEARCHSERVICES/WRITE",
  "Properties": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Search/searchServices/dwhc6a93dsearchservice",
    "message": "Microsoft.Search/searchServices/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "87f404a0-be71-6de1-afe8-2744031406b9",
    "eventSubmissionTimestamp": "2026-07-03T02:15:57.539639Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93dsearchservice",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.SEARCH",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "Created"
  },
  "Properties_d": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.Search/searchServices/dwhc6a93dsearchservice",
    "message": "Microsoft.Search/searchServices/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "87f404a0-be71-6de1-afe8-2744031406b9",
    "eventSubmissionTimestamp": "2026-07-03T02:15:57.5396390Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dwhc6a93dsearchservice",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.SEARCH",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "Created"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.SEARCH",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #