Including the result of log search query for Log based alert rule

AnuragSingh-MSFT 21,076 Reputation points
2024-06-27T16:36:04.9266667+00:00

How to include result of log search in alert generated by log based alert rule. Specifically, how do we include results from KQL queries, such as computer names, rows of result returned etc. directly in Azure email notifications sent for Azure Monitor Alerts?

PS - Based on the issues that we have seen from multiple customers and sources, we are posting these questions to help the Azure community.

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,960 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Monalla-MSFT 12,761 Reputation points
    2024-06-27T17:51:29.0633333+00:00

    @AnuragSingh-MSFT - Thanks for reaching out to us.

    To resolve this issue, consider using a logic app to generate a custom payload in the email, which can include the desired details such as recovery vault names. You've successfully created V1 alerts using the API method and are exploring customizing V2 alerts with logic apps.

    Please take a look at this doc for more reference

    Hope this helps. and please feel free to reach out if you have any further questions.


    Please don't forget to "Accept as Answer" and click "Yes" if the above response is helpful, so it can be beneficial to the community.

    0 comments No comments