Forum Discussion
weslowsk
Jul 03, 2024Copper Contributor
No results when creating alert rule
I've been following this documentation for creating emergency users:
https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/security-emergency-access#monitor-sign-in-and-audit-logs
However, I'm unable to get any results when I'm creating and testing the alert rule.
What am I missing?
2 Replies
Please locate the cause by following steps:
-
Check Alert Processing Rule:
-
Email Notifications:
-
Additional Troubleshooting such as firewall rules, etc.
- weslowskCopper ContributorThe sign in logs aren't streamed into the log analytics workspace by default. Once I explicitly set that up, it started working, albeit not right away (i.e. it started working the next morning).
-