Sets of notification and automation targets in Azure Monitor that an alert calls when it fires. Detecting the problem is the alert rule's job, not theirs.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Action groups in context, with comparison tables and the common traps.
Terms in this definition
- Azure Monitor
Observability platform for Azure that brings together metrics, logs and traces from both Azure and hybrid resources so they can be analysed and alerted on.
- Alert rule
Azure Monitor definition made up of a scope naming the target resources, a condition setting the signal and logic, and optionally action groups. A separate rule is needed for every signal that has different recipients.
- Job
A sequence of steps executed together on one agent or runner, or on the server for agentless work. While running, each occupies one of your parallel jobs.
Related terms
- Alert processing rule
Acts on already-fired Azure Monitor alerts at scale, suppressing notifications (during planned maintenance, say) or attaching action groups.
- Alert processing rules
Rules applied after an alert fires that attach or suppress action groups, on a schedule if required. Only notifications are affected; the alert rule stays in place and keeps firing.
- AUDIT_CHANGE_GROUP
Fires when someone creates, alters or drops an audit or audit specification, so it captures changes to the auditing setup itself; logins and queries are covered by other action groups.
- Azure Monitor Baseline Alerts
A collection of recommended alerts for landing zone components, covering metrics, activity logs and logs, maintained by Microsoft. They are rolled out with Azure Policy using DeployIfNotExists, alongside action groups and alert processing rules.
- Database audit specification
Says which database-level actions or action groups SQL Server Audit should record, for example
SELECT ON SCHEMA::HR BY public; each database can have one per audit. Server-level groups go in a server audit specification. - IT Service Management Connector
Lets action groups in Azure Monitor open tickets or other work items in an external ITSM tool; it is set up inside a Log Analytics workspace, where it establishes the ITSM connection.
- ITSM
Discipline of handling incidents and work items, along with the products that support it, such as ServiceNow or SCSM. Azure Monitor action groups connect to these systems with an ITSM action or a Secure Webhook.
- Monitoring Contributor
Built-in Azure role able to read every kind of monitoring data and change monitoring configuration such as alerts, action groups and diagnostic settings. It cannot alter other resources or locks.