Record, held for 90 days, of control-plane operations in a subscription such as deployments and Policy events. Data-plane actions, Key Vault reads for example, are not captured.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104AZ-700SC-500AZ-900SC-200AZ-400
Each book explains Activity log in context, with comparison tables and the common traps.
Terms in this definition
- subscription
Entitlement bought for a product under VCF 9.0 licensing, carrying a set capacity. Where active ones share the same site, unit and product, their capacity is combined into licences, which are then allocated to vCenters.
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
- Access policies
Older permission model for Key Vault, now superseded by the Azure RBAC model.
Related terms
- Activity log alert
Alert rule without state that triggers on a matching Activity log event, deleting a management lock for instance. A scope, a condition and an action group are required; a Log Analytics workspace is not.
- Administrative (Activity log category)
Category of Activity log entries covering every create, update, delete and action call made via Resource Manager, for example adding a tag, attaching a disk or creating a resource group.
- Audit
Policy effect that lets a request proceed but flags the resource as non-compliant and logs a warning to the activity log. Microsoft suggests beginning there and later moving to something enforcing, like Deny.
- Azure Activity
Connector for Microsoft Sentinel that streams each subscription's activity log, via diagnostic settings, into the AzureActivity table. A subscription that was hooked up the older, legacy way needs disconnecting before you switch over.
- Azure Monitor alerts
Rules in Azure Monitor that send notifications or trigger actions once a condition on metrics, logs or the activity log is satisfied.
- AzureActivity
Table in Log Analytics where a subscription's activity log is stored.
- Host data
Monitoring data about the Hyper-V host side of a virtual machine, including CPU, disk and network metrics, the activity log and boot diagnostics, which is gathered automatically without any agent.
- Monitor condition
Whether the condition behind a fired alert is still true determines this value, which Azure sets to Fired or Resolved. For activity log alerts it never leaves Fired.