Azure Monitor definition made up of a scope naming the target resources, a condition setting the signal and logic, and optionally action groups. A separate rule is needed for every signal that has different recipients.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-104AI-300AZ-900DP-750AZ-802
Each book explains Alert rule in context, with comparison tables and the common traps.
Terms in this definition
- Azure Monitor
Observability platform for Azure that brings together metrics, logs and traces from both Azure and hybrid resources so they can be analysed and alerted on.
- Scope
Where an access or policy assignment takes effect. It can be set on a single resource, a resource group, a subscription or a management group, and settings flow down from higher levels.
- Target resources
What a Conditional Access policy applies to: apps in the cloud, actions users take, authentication contexts, or traffic profiles in Global Secure Access.
- Action groups
Sets of notification and automation targets in Azure Monitor that an alert calls when it fires. Detecting the problem is the alert rule's job, not theirs.
Related terms
- Activity log alert
Alert rule without state that triggers on a matching Activity log event, deleting a management lock for instance. A scope, a condition and an action group are required; a Log Analytics workspace is not.
- Alert processing rules
Rules applied after an alert fires that attach or suppress action groups, on a schedule if required. Only notifications are affected; the alert rule stays in place and keeps firing.
- Log search alert
Scheduled Azure Monitor alert rule built on a KQL query; it evaluates Log Analytics data either for an entire workspace or for just one resource.
- Metric alert
Alert rule in Azure Monitor that checks numerical metrics from a resource at a regular frequency. Log entries are invisible to it.