AzureActivity

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index


Reference for AzureActivity table in Azure Monitor Logs.

Attribute Value
Category Audit, Azure Resources, Security
Basic Logs Eligible ✗ No
Supports Transformations ✗ No
Ingestion API Supported ✗ No
Lake-Only Ingestion ✗ No (source)
Azure Monitor Tables Reference View Documentation

Contents

Schema (37 columns)

Source: Azure Monitor documentation

Column Name Type Description
_BilledSize real The record size in bytes
_IsBillable string Specifies whether ingesting the data is billable. When _IsBillable is false ingestion isn't billed to your Azure account
_ResourceId string A unique identifier for the resource that the record is associated with
_SubscriptionId string A unique identifier for the subscription that the record is associated with
ActivityStatus string
ActivityStatusValue string Status of the operation in display-friendly format. Common values include Started, In Progress, Succeeded, Failed, Active, Resolved.
ActivitySubstatus string
ActivitySubstatusValue string Substatus of the operation in display-friendly format. E.g. OK (HTTP Status Code: 200).
Authorization string Blob of RBAC properties of the event. Usually includes the "action", "role" and "scope" properties. Stored as string. The use of Authorization_d should be preferred going forward.
Authorization_d dynamic Blob of RBAC properties of the event. Usually includes the "action", "role" and "scope" properties. Stored as dynamic column.
Caller string GUID of the caller.
CallerIpAddress string IP address of the user who has performed the operation UPN claim or SPN claim based on availability.
Category string
CategoryValue string Category of the activity log e.g. Administrative, Policy, Security.
Claims string The JWT token used by Active Directory to authenticate the user or application to perform this operation in Resource Manager. The use of claims_d should be preferred going forward.
Claims_d dynamic The JWT token used by Active Directory to authenticate the user or application to perform this operation in Resource Manager.
CorrelationId string Usually a GUID in the string format. Events that share a correlationId belong to the same uber action.
EventDataId string Unique identifier of an event.
EventSubmissionTimestamp datetime Timestamp when the event became available for querying.
Hierarchy string Management group hierarchy of the management group or subscription that event belongs to.
HTTPRequest string Blob describing the Http Request. Usually includes the "clientRequestId", "clientIpAddress" and "method" (HTTP method. For example, PUT).
Level string Level of the event. One of the following values: Critical, Error, Warning, Informational and Verbose.
OperationId string GUID of the operation
OperationName string
OperationNameValue string Identifier of the operation e.g. Microsoft.Storage/storageAccounts/listAccountSas/action.
Properties string Set of <Key Value> pairs (i.e. Dictionary) describing the details of the event. Stored as string. Usage of Properties_d is recommended instead.
Properties_d dynamic Set of <Key Value> pairs (i.e. Dictionary) describing the details of the event. Stored as dynamic column.
Resource string
ResourceGroup string Resource group name of the impacted resource.
ResourceId string
ResourceProvider string
ResourceProviderValue string Id of the resource provider for the impacted resource - e.g. Microsoft.Storage.
SourceSystem string The type of agent the event was collected by. For example, OpsManager for Windows agent, either direct connect or Operations Manager, Linux for all Linux agents, or Azure for Azure Diagnostics
SubscriptionId string Subscription ID of the impacted resource.
TenantId string The Log Analytics workspace ID
TimeGenerated datetime Timestamp when the event was generated by the Azure service processing the request corresponding the event.
Type string The name of the table

Schema References

Official Microsoft Learn documentation for field/column information:

Solutions (21)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Azure Activity

Content Items Using This Table (71)

Analytic Rules (22)

In solution Apache Log4j Vulnerability Detection:

Analytic Rule Selection Criteria
Log4j vulnerability exploit aka Log4Shell IP IOC

In solution Azure Activity:

Analytic Rule Selection Criteria
Azure Machine Learning Write Operations OperationNameValue !contains "MICROSOFT.AUTHORIZATION/ROLEASSIGNMENTS/WRITE"
OperationNameValue contains "write"
ResourceProviderValue == "MICROSOFT.MACHINELEARNINGSERVICES"
Creation of expensive computes in Azure ActivityStatusValue startswith "Accept"
Properties has "vmSize"
Mass Cloud resource deletions Time Series Anomaly OperationNameValue endswith "delete"
Microsoft Entra ID Hybrid Health AD FS New Server CategoryValue == "Administrative"
OperationNameValue == "Microsoft.ADHybridHealthService/services/servicemembers/action"
ResourceProviderValue == "Microsoft.ADHybridHealthService"
_ResourceId has "AdFederationService"
Microsoft Entra ID Hybrid Health AD FS Service Delete CategoryValue == "Administrative"
OperationNameValue == "Microsoft.ADHybridHealthService/services/delete"
ResourceProviderValue == "Microsoft.ADHybridHealthService"
_ResourceId has "AdFederationService"
Microsoft Entra ID Hybrid Health AD FS Suspicious Application CategoryValue == "Administrative"
ResourceProviderValue == "Microsoft.ADHybridHealthService"
_ResourceId has "AdFederationService"
NRT Creation of expensive computes in Azure ActivityStatusValue startswith "Accept"
Properties has "vmSize"
NRT Microsoft Entra ID Hybrid Health AD FS New Server CategoryValue == "Administrative"
OperationNameValue == "Microsoft.ADHybridHealthService/services/servicemembers/action"
ResourceProviderValue == "Microsoft.ADHybridHealthService"
_ResourceId has "AdFederationService"
New CloudShell User ActivityStatusValue == "Success"
OperationNameValue in "Microsoft.Storage/storageAccounts/listKeys/action,Microsoft.Storage/storageAccounts/write"
ResourceGroup has "cloud-shell"
Rare subscription-level operations in Azure
Subscription moved to another tenant CategoryValue == "Security"
OperationNameValue == "Microsoft.Subscription/updateTenant/action"
Suspicious Resource deployment
Suspicious granting of permissions to an account
Suspicious number of resource creation or deployment activities

In solution MaturityModelForEventLogManagementM2131: ActivityStatusValue == "Succeeded"
OperationNameValue contains "Microsoft.SecurityInsights/dataConnectors/"

Analytic Rule
M2131_DataConnectorAddedChangedRemoved

In solution SecurityThreatEssentialSolution: OperationNameValue endswith "delete"

Analytic Rule
Threat Essentials - Mass Cloud resource deletions Time Series Anomaly

In solution Threat Intelligence:

Analytic Rule Selection Criteria
TI Map IP Entity to AzureActivity
TI map Email entity to AzureActivity

In solution Threat Intelligence (NEW):

Analytic Rule Selection Criteria
TI Map Email entity to AzureActivity
TI Map IP Entity to AzureActivity

In solution eDCRule: Authorization has "virtualMachines"
Caller contains "@"
OperationNameValue == "MICROSOFT.COMPUTE/VIRTUALMACHINES/RUNCOMMAND/ACTION"

Analytic Rule
[AzureSubscription] Suspicious Azure VM Run Command Execution Detected

Hunting Queries (33)

In solution Azure Activity:

Hunting Query Selection Criteria
Anomalous Azure Operation Hunting Model
Azure Machine Learning Write Operations OperationNameValue !contains "MICROSOFT.AUTHORIZATION/ROLEASSIGNMENTS/WRITE"
OperationNameValue contains "write"
ResourceProviderValue == "MICROSOFT.MACHINELEARNINGSERVICES"
Azure Network Security Group NSG Administrative Operations ActivitySubstatusValue in "Accepted,Created,OK"
Azure VM Run Command executed from Azure IP address Authorization has "virtualMachines"
OperationNameValue == "Microsoft.Compute/virtualMachines/runCommand/action"
Azure Virtual Network Subnets Administrative Operations ActivitySubstatusValue in "Accepted,Created"
CategoryValue == "Administrative"
Azure storage key enumeration ActivityStatusValue == "Succeeded"
OperationNameValue == "microsoft.storage/storageaccounts/listkeys/action"
AzureActivity Administration From VPS Providers CategoryValue == "Administrative"
Common deployed resources ActivityStatusValue == "Succeeded"
Creation of an anomalous number of resources ActivityStatusValue == "Succeeded"
OperationNameValue in "microsoft.compute/virtualMachines/write,microsoft.resources/deployments/write"
Granting permissions to account ActivityStatus == "Succeeded"
OperationName == "Create role assignment"
Microsoft Sentinel Analytics Rules Administrative Operations ActivitySubstatusValue in "Created,OK"
CategoryValue == "Administrative"
Microsoft Sentinel Connectors Administrative Operations ActivitySubstatusValue in "Created,OK"
Microsoft Sentinel Workbooks Administrative Operations ActivitySubstatusValue in "Created,OK"
Port opened for an Azure Resource ActivityStatusValue == "Accepted"
OperationNameValue endswith "write"
OperationNameValue has_any "ipfilterrules"
Rare Custom Script Extension OperationName == "Create or Update Virtual Machine Extension"

In solution Cloud Service Threat Protection Essentials: ActivityStatusValue has_any "Succeeded"
Properties contains "publicipaddress"

Hunting Query
Azure Resources Assigned Public IP Addresses

In solution Hybrid Attack - Cloud & Identity:

Hunting Query Selection Criteria
Appliance management session followed by RBAC write
Cloud Run Command followed by kernel persistence indicators on target servers
Cross-subscription and resource-group enumeration sweep by single identity
IAM and subscription enumeration followed by Key Vault operations
IAM reconnaissance followed by role assignment write attempt
Identity and app enumeration followed by novel non-interactive tuple
Key Vault discovery followed by data-store access enumeration
Key Vault harvest to SPN sign-in then out-of-scope resource access
Key Vault secret harvest followed by novel SPN sign-in from non-1P IP
Key Vault secret read then Storage key-auth pivot
Key Vault secret read then partial storage exfil
Multi-service network exposure followed by key and data access
Novel SPN sign-in followed by Azure RBAC write
Novel identity then Key Vault secret burst
Novel sign-in context followed by IAM reconnaissance burst
Suspicious sign-in followed by cloud network exposure writes

In solution MicrosoftPurviewInsiderRiskManagement: OperationName contains "delete"
OperationName contains "remove"

Hunting Query
Insider Risk_Possible Sabotage

Workbooks (15)

In solution Azure Activity:

Workbook Selection Criteria
AzureActivity Level in "Error,Informational,Warning"
AzureServiceHealthWorkbook CategoryValue == "ServiceHealth"
Level in "Error,Information,Warning"

In solution Azure SQL Database solution for sentinel: ActivityStatusValue == "Succeeded"
Caller has "@"

Workbook
Workbook-AzureSQLSecurity

In solution AzureSecurityBenchmark: ActivityStatusValue in "Succeeded,Success"
OperationName in "Add member to role,Add user,AzureFirewallIDSLog,NetworkSecurityGroupEvents,Reset user password,Update user"
OperationName contains "PIM"
OperationName contains "create"
OperationName contains "delete"
OperationName contains "lockbox"
OperationName contains "remove"
OperationName contains "update"
OperationNameValue contains "recovery"
OperationNameValue startswith "Microsoft.KeyVault"
OperationNameValue startswith "Microsoft.Logic"

Workbook
AzureSecurityBenchmark

In solution ContinuousDiagnostics&Mitigation: OperationName contains "PIM"

Workbook
ContinuousDiagnostics&Mitigation

In solution CybersecurityMaturityModelCertification(CMMC)2.0: OperationName in "Add member to role,Add user,NetworkSecurityGroupEvents,Reset user password,Update user"
OperationName contains "Add"
OperationName contains "Audit"
OperationName contains "Change"
OperationName contains "Create"
OperationName contains "Delete"
OperationName contains "Log"
OperationName contains "Monitor"
OperationName contains "PIM"
OperationName contains "Remove"
OperationName contains "Update"
OperationName contains "Write"
OperationName contains "reset"
OperationNameValue contains "Insights"

Workbook
CybersecurityMaturityModelCertification_CMMCV2

In solution Hybrid Attack - Cloud & Identity: ActivityStatusValue == "Success"
Caller contains "@"
OperationNameValue == "Microsoft.Authorization/roleAssignments/delete"
OperationNameValue contains "WebApplicationFirewall"
OperationNameValue contains "azureFirewall"
OperationNameValue contains "firewallPolicies"
OperationNameValue contains "networkSecurityGroup"
OperationNameValue contains "roleAssignments"
OperationNameValue contains "routeTable"
OperationNameValue contains "routes/"
OperationNameValue contains "subnets"
OperationNameValue contains "virtualNetworkGateway"

Workbook
HybridAttack-Cloud&Identity

In solution Lumen Defender Threat Feed:

Workbook Selection Criteria
Lumen-Threat-Feed-Overview

In solution MaturityModelForEventLogManagementM2131: ActivityStatusValue == "Success"
ActivitySubstatusValue in "Created,OK"
OperationName in "Add member to role,Add user,ApplicationGatewayFirewall,AzureFirewallIDSLog,Reset user password,Update user"
OperationName !contains "external"
OperationName !contains "invite"
OperationName !contains "licnense"
OperationName contains "group"
OperationName contains "member"
OperationName contains "principal"
OperationName contains "role"
OperationName contains "user"
OperationNameValue contains "Microsoft.Network/loadBalancers/"
OperationNameValue contains "Network"
ResourceProviderValue in "MICROSOFT.CONTAINERSERVICE,MICROSOFT.LOGIC"

Workbook
MaturityModelForEventLogManagement_M2131

In solution MicrosoftPurviewInsiderRiskManagement: ActivityStatus in "Accepted,Succeeded"
ActivitySubstatusValue in "Created,OK"
OperationName in "Add member to role,Add user,Consent to application,Create Deployment,Create or Update Virtual Machine,Create role assignment,List Storage Account Keys,Reset user password,Update user"
OperationName in "Set domain authentication,Set federation settings on domain,Sign-in activity"
OperationName != "Consent to application"
OperationName contains "Create"
OperationName contains "Delete"
OperationName contains "Update"
OperationName contains "delet"
OperationName contains "delete"
OperationName contains "remove"
OperationName has "Create"
OperationName has_any "Create,Update"
OperationName has_any "Ip,Security Rule"

Workbook
InsiderRiskManagement

In solution NISTSP80053: ActivityStatusValue in "Succeeded,Success"
OperationName contains "Delete"
OperationName contains "PIM"
OperationName contains "Remove"
OperationNameValue contains "cluster"
OperationNameValue contains "insights"
OperationNameValue contains "storage"
OperationNameValue startswith "Microsoft.Logic"

Workbook
NISTSP80053

In solution SOC Handbook: OperationName == "Consent to application"
OperationName == "Disable Strong Authentication"
OperationName contains "password"

Workbook
InvestigationInsights

In solution SOX IT Compliance:

Workbook Selection Criteria
SOXITCompliance

In solution ThreatAnalysis&Response:

Workbook Selection Criteria
DynamicThreatModeling&Response

In solution ZeroTrust(TIC3.0): ActivityStatusValue in "Succeeded,Success"
OperationName in "Add member to role,Add user,ApplicationGatewayFirewall,AzureFirewallIDSLog,AzureFirewallThreatIntelLog,NetworkSecurityGroupEvents,Reset user password,Update user"
OperationName contains "PIM"
OperationNameValue startswith "Microsoft.Logic"

Workbook
ZeroTrustTIC3

Parsers Using This Table (1)

ASIM Parsers (1) — Selection Criteria: CategoryValue == "Administrative"

Parser Schema Product
ASimAuditEventAzureActivity AuditEvent Microsoft Azure

Resource Types

This table collects data from the following Azure resource types:

Selection Criteria Summary (36 criteria, 42 total references)

References by type: 0 connectors, 41 content items, 1 ASIM parsers, 0 other parsers.

Selection Criteria Connectors Content Items ASIM Parsers Other Parsers Total
CategoryValue == "Administrative"
OperationNameValue == "Microsoft.ADHybridHealthService/services/servicemembers/action"
ResourceProviderValue == "Microsoft.ADHybridHealthService"
_ResourceId has "AdFederationService"
- 2 - - 2
ActivityStatusValue startswith "Accept"
Properties has "vmSize"
- 2 - - 2
OperationNameValue !contains "MICROSOFT.AUTHORIZATION/ROLEASSIGNMENTS/WRITE"
OperationNameValue contains "write"
ResourceProviderValue == "MICROSOFT.MACHINELEARNINGSERVICES"
- 2 - - 2
OperationNameValue endswith "delete" - 2 - - 2
CategoryValue == "Administrative" - 1 1 - 2
ActivitySubstatusValue in "Created,OK" - 2 - - 2
CategoryValue == "Administrative"
OperationNameValue == "Microsoft.ADHybridHealthService/services/delete"
ResourceProviderValue == "Microsoft.ADHybridHealthService"
_ResourceId has "AdFederationService"
- 1 - - 1
CategoryValue == "Administrative"
ResourceProviderValue == "Microsoft.ADHybridHealthService"
_ResourceId has "AdFederationService"
- 1 - - 1
ActivityStatusValue == "Success"
OperationNameValue in "Microsoft.Storage/storageAccounts/listKeys/action,Microsoft.Storage/storageAccounts/write"
ResourceGroup has "cloud-shell"
- 1 - - 1
CategoryValue == "Security"
OperationNameValue == "Microsoft.Subscription/updateTenant/action"
- 1 - - 1
Authorization has "virtualMachines"
Caller contains "@"
OperationNameValue == "MICROSOFT.COMPUTE/VIRTUALMACHINES/RUNCOMMAND/ACTION"
- 1 - - 1
ActivityStatusValue == "Succeeded"
OperationNameValue contains "Microsoft.SecurityInsights/dataConnectors/"
- 1 - - 1
ActivitySubstatusValue in "Created,OK"
CategoryValue == "Administrative"
- 1 - - 1
ActivityStatusValue == "Succeeded"
OperationNameValue == "microsoft.storage/storageaccounts/listkeys/action"
- 1 - - 1
ActivitySubstatusValue in "Accepted,Created,OK" - 1 - - 1
Authorization has "virtualMachines"
OperationNameValue == "Microsoft.Compute/virtualMachines/runCommand/action"
- 1 - - 1
ActivitySubstatusValue in "Accepted,Created"
CategoryValue == "Administrative"
- 1 - - 1
ActivityStatusValue == "Succeeded" - 1 - - 1
ActivityStatusValue == "Succeeded"
OperationNameValue in "microsoft.compute/virtualMachines/write,microsoft.resources/deployments/write"
- 1 - - 1
ActivityStatus == "Succeeded"
OperationName == "Create role assignment"
- 1 - - 1
ActivityStatusValue == "Accepted"
OperationNameValue endswith "write"
OperationNameValue has_any "ipfilterrules"
- 1 - - 1
OperationName == "Create or Update Virtual Machine Extension" - 1 - - 1
ActivityStatusValue has_any "Succeeded"
Properties contains "publicipaddress"
- 1 - - 1
OperationName contains "delete"
OperationName contains "remove"
- 1 - - 1
Level in "Error,Informational,Warning" - 1 - - 1
CategoryValue == "ServiceHealth"
Level in "Error,Information,Warning"
- 1 - - 1
ActivityStatusValue == "Succeeded"
Caller has "@"
- 1 - - 1
ActivityStatusValue in "Succeeded,Success"
OperationName in "Add member to role,Add user,AzureFirewallIDSLog,NetworkSecurityGroupEvents,Reset user password,Update user"
OperationName contains "PIM"
OperationName contains "create"
OperationName contains "delete"
OperationName contains "lockbox"
OperationName contains "remove"
OperationName contains "update"
OperationNameValue contains "recovery"
OperationNameValue startswith "Microsoft.KeyVault"
OperationNameValue startswith "Microsoft.Logic"
- 1 - - 1
OperationName contains "PIM" - 1 - - 1
OperationName in "Add member to role,Add user,NetworkSecurityGroupEvents,Reset user password,Update user"
OperationName contains "Add"
OperationName contains "Audit"
OperationName contains "Change"
OperationName contains "Create"
OperationName contains "Delete"
OperationName contains "Log"
OperationName contains "Monitor"
OperationName contains "PIM"
OperationName contains "Remove"
OperationName contains "Update"
OperationName contains "Write"
OperationName contains "reset"
OperationNameValue contains "Insights"
- 1 - - 1
ActivityStatusValue == "Success"
Caller contains "@"
OperationNameValue == "Microsoft.Authorization/roleAssignments/delete"
OperationNameValue contains "WebApplicationFirewall"
OperationNameValue contains "azureFirewall"
OperationNameValue contains "firewallPolicies"
OperationNameValue contains "networkSecurityGroup"
OperationNameValue contains "roleAssignments"
OperationNameValue contains "routeTable"
OperationNameValue contains "routes/"
OperationNameValue contains "subnets"
OperationNameValue contains "virtualNetworkGateway"
- 1 - - 1
ActivityStatusValue == "Success"
ActivitySubstatusValue in "Created,OK"
OperationName in "Add member to role,Add user,ApplicationGatewayFirewall,AzureFirewallIDSLog,Reset user password,Update user"
OperationName !contains "external"
OperationName !contains "invite"
OperationName !contains "licnense"
OperationName contains "group"
OperationName contains "member"
OperationName contains "principal"
OperationName contains "role"
OperationName contains "user"
OperationNameValue contains "Microsoft.Network/loadBalancers/"
OperationNameValue contains "Network"
ResourceProviderValue in "MICROSOFT.CONTAINERSERVICE,MICROSOFT.LOGIC"
- 1 - - 1
ActivityStatus in "Accepted,Succeeded"
ActivitySubstatusValue in "Created,OK"
OperationName in "Add member to role,Add user,Consent to application,Create Deployment,Create or Update Virtual Machine,Create role assignment,List Storage Account Keys,Reset user password,Update user"
OperationName in "Set domain authentication,Set federation settings on domain,Sign-in activity"
OperationName != "Consent to application"
OperationName contains "Create"
OperationName contains "Delete"
OperationName contains "Update"
OperationName contains "delet"
OperationName contains "delete"
OperationName contains "remove"
OperationName has "Create"
OperationName has_any "Create,Update"
OperationName has_any "Ip,Security Rule"
- 1 - - 1
ActivityStatusValue in "Succeeded,Success"
OperationName contains "Delete"
OperationName contains "PIM"
OperationName contains "Remove"
OperationNameValue contains "cluster"
OperationNameValue contains "insights"
OperationNameValue contains "storage"
OperationNameValue startswith "Microsoft.Logic"
- 1 - - 1
OperationName == "Consent to application"
OperationName == "Disable Strong Authentication"
OperationName contains "password"
- 1 - - 1
ActivityStatusValue in "Succeeded,Success"
OperationName in "Add member to role,Add user,ApplicationGatewayFirewall,AzureFirewallIDSLog,AzureFirewallThreatIntelLog,NetworkSecurityGroupEvents,Reset user password,Update user"
OperationName contains "PIM"
OperationNameValue startswith "Microsoft.Logic"
- 1 - - 1
Total 0 41 1 0 42

ActivityStatus

Value Connectors Content Items ASIM Parsers Other Parsers Total
Succeeded - 2 - - 2
Accepted - 1 - - 1

ActivityStatusValue

Value Connectors Content Items ASIM Parsers Other Parsers Total
Succeeded - 8 - - 8
Success - 6 - - 6
startswith Accept - 2 - - 2
Accepted - 1 - - 1
has_any Succeeded - 1 - - 1

ActivitySubstatusValue

Value Connectors Content Items ASIM Parsers Other Parsers Total
Created - 7 - - 7
OK - 6 - - 6
Accepted - 2 - - 2

Authorization

Value Connectors Content Items ASIM Parsers Other Parsers Total
has virtualMachines - 2 - - 2

Caller

Value Connectors Content Items ASIM Parsers Other Parsers Total
contains @ - 2 - - 2
has @ - 1 - - 1

CategoryValue

Value Connectors Content Items ASIM Parsers Other Parsers Total
Administrative - 7 1 - 8
Security - 1 - - 1
ServiceHealth - 1 - - 1

Level

Value Connectors Content Items ASIM Parsers Other Parsers Total
Error - 2 - - 2
Warning - 2 - - 2
Informational - 1 - - 1
Information - 1 - - 1

OperationName

Value Connectors Content Items ASIM Parsers Other Parsers Total
Add member to role - 5 - - 5
Add user - 5 - - 5
Reset user password - 5 - - 5
Update user - 5 - - 5
contains PIM - 5 - - 5
contains delete - 3 - - 3
contains remove - 3 - - 3
AzureFirewallIDSLog - 3 - - 3
NetworkSecurityGroupEvents - 3 - - 3
contains Delete - 3 - - 3
Create role assignment - 2 - - 2
contains Create - 2 - - 2
contains Remove - 2 - - 2
contains Update - 2 - - 2
ApplicationGatewayFirewall - 2 - - 2
Consent to application - 2 - - 2
Create or Update Virtual Machine Extension - 1 - - 1
contains create - 1 - - 1
contains lockbox - 1 - - 1
contains update - 1 - - 1
contains Add - 1 - - 1
contains Audit - 1 - - 1
contains Change - 1 - - 1
contains Log - 1 - - 1
contains Monitor - 1 - - 1
contains Write - 1 - - 1
contains reset - 1 - - 1
!contains external - 1 - - 1
!contains invite - 1 - - 1
!contains licnense - 1 - - 1
contains group - 1 - - 1
contains member - 1 - - 1
contains principal - 1 - - 1
contains role - 1 - - 1
contains user - 1 - - 1
Create Deployment - 1 - - 1
Create or Update Virtual Machine - 1 - - 1
List Storage Account Keys - 1 - - 1
Set domain authentication - 1 - - 1
Set federation settings on domain - 1 - - 1
Sign-in activity - 1 - - 1
!= Consent to application - 1 - - 1
contains delet - 1 - - 1
has Create - 1 - - 1
has_any Create - 1 - - 1
has_any Update - 1 - - 1
has_any Ip - 1 - - 1
has_any Security Rule - 1 - - 1
Disable Strong Authentication - 1 - - 1
contains password - 1 - - 1
AzureFirewallThreatIntelLog - 1 - - 1

OperationNameValue

Value Connectors Content Items ASIM Parsers Other Parsers Total
startswith Microsoft.Logic - 3 - - 3
Microsoft.ADHybridHealthService/services/servicemembers/action - 2 - - 2
!contains MICROSOFT.AUTHORIZATION/ROLEASSIGNMENTS/WRITE - 2 - - 2
contains write - 2 - - 2
endswith delete - 2 - - 2
Microsoft.ADHybridHealthService/services/delete - 1 - - 1
Microsoft.Storage/storageAccounts/listKeys/action - 1 - - 1
Microsoft.Storage/storageAccounts/write - 1 - - 1
Microsoft.Subscription/updateTenant/action - 1 - - 1
MICROSOFT.COMPUTE/VIRTUALMACHINES/RUNCOMMAND/ACTION - 1 - - 1
contains Microsoft.SecurityInsights/dataConnectors/ - 1 - - 1
microsoft.storage/storageaccounts/listkeys/action - 1 - - 1
Microsoft.Compute/virtualMachines/runCommand/action - 1 - - 1
microsoft.compute/virtualMachines/write - 1 - - 1
microsoft.resources/deployments/write - 1 - - 1
endswith write - 1 - - 1
has_any ipfilterrules - 1 - - 1
contains recovery - 1 - - 1
startswith Microsoft.KeyVault - 1 - - 1
contains Insights - 1 - - 1
Microsoft.Authorization/roleAssignments/delete - 1 - - 1
contains WebApplicationFirewall - 1 - - 1
contains azureFirewall - 1 - - 1
contains firewallPolicies - 1 - - 1
contains networkSecurityGroup - 1 - - 1
contains roleAssignments - 1 - - 1
contains routeTable - 1 - - 1
contains routes/ - 1 - - 1
contains subnets - 1 - - 1
contains virtualNetworkGateway - 1 - - 1
contains Microsoft.Network/loadBalancers/ - 1 - - 1
contains Network - 1 - - 1
contains cluster - 1 - - 1
contains insights - 1 - - 1
contains storage - 1 - - 1

Properties

Value Connectors Content Items ASIM Parsers Other Parsers Total
has vmSize - 2 - - 2
contains publicipaddress - 1 - - 1

ResourceGroup

Value Connectors Content Items ASIM Parsers Other Parsers Total
has cloud-shell - 1 - - 1

ResourceProviderValue

Value Connectors Content Items ASIM Parsers Other Parsers Total
Microsoft.ADHybridHealthService - 4 - - 4
MICROSOFT.MACHINELEARNINGSERVICES - 2 - - 2
MICROSOFT.CONTAINERSERVICE - 1 - - 1
MICROSOFT.LOGIC - 1 - - 1

_ResourceId

Value Connectors Content Items ASIM Parsers Other Parsers Total
has AdFederationService - 4 - - 4

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index