Alert rule without state that triggers on a matching Activity log event, deleting a management lock for instance. A scope, a condition and an action group are required; a Log Analytics workspace is not.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Activity log alert in context, with comparison tables and the common traps.
Terms in this definition
- Alert rule
Azure Monitor definition made up of a scope naming the target resources, a condition setting the signal and logic, and optionally action groups. A separate rule is needed for every signal that has different recipients.
- State
A parameter in OAuth that carries custom data through the authorisation flow and back, as with the "Support state parameter" option in APIM.
- Activity log
Record, held for 90 days, of control-plane operations in a subscription such as deployments and Policy events. Data-plane actions, Key Vault reads for example, are not captured.
- Event
Table in Log Analytics where entries from Windows event logs are kept.
- Scope
Where an access or policy assignment takes effect. It can be set on a single resource, a resource group, a subscription or a management group, and settings flow down from higher levels.
- Action group
Azure Monitor's reusable definition of contacts and automated responses for when an alert or budget fires. Contacts can be reached by email, SMS, push or voice; responses include webhooks, Functions, Logic Apps and Automation runbooks. Budgets alone can only send notifications.
- Log Analytics workspace
Where Azure Monitor keeps log data for querying with KQL. Microsoft Sentinel, VM insights and workspace-based Application Insights all depend on one.