Forum Discussion

cxmelga's avatar
cxmelga
Copper Contributor
Feb 18, 2022

Can I some how add the 'RenderedDescription' content from Log Analytics to Email Body of Alert

Hello

My Azure Monitor is working and I receive the Alert Email OK.

This is triggered from a Log Analytics query for a Windows Event log entry 

 

However the body of the email alert contains the following (see screenshot at link below)

https://1drv.ms/u/s!AqL5zUwOWToZge8hFLkgp7745b7MDw?e=0lV3jF

 

Which is not very useful, I need the RenderedDescription content from the Log shown in the email body as this field contains useful information in plain text (like the serial number of the certificate which has been revoked) 

 

Therefore can anyone tell me please how can my Azure Monitor email alerts shoe the text from the RenderedDescription from the Log Analytics logs entry that triggered the alert in the first instance.

 

Thank you in advance

Charlie

 

 

 

    • cxmelga's avatar
      cxmelga
      Copper Contributor

      yalavi 

       

      Thank you very much for taking the time to reply

      I will checkout the link you provided πŸ™‚

       

      CXMelga

  • cxmelga you can add this field as a dimension to get it in the email as context for the alert.

  • cxmelga's avatar
    cxmelga
    Copper Contributor
    Hi All
    Can someone please help me with the above πŸ™‚

    To clarify, what I want to achieve seems simple on the surface, but it does not appear to be available with Azure Monitor out of the box without via via a Logic App (which seems odd), So perhaps I am missing something

    What I want to do is include the text from the RenderedDescription field (as seen in Log Analytics when querying an Event from the Windows Event Log taken from a standard Windows computer)
    in the email body of an Azure Monitor Alert. So then the email arrives it shows the contents/text/message of the Windows Event Log entry (e.g. the one which was alerted on).

    My Alert is working OK, in that it fires and I get an email all good. However none of the information/fields in the email alert show the text from the actual Windows Event Log message (aka RenderedDescription from log analytics). The Azure Monitor logic fires on the KQL query (which includes RenderedDescription) but it is not surfaced in the actual email alert body.

    Please advise if there is a simply way to include the RenderedDescription text in the email alert body when using Azure Monitor for alerting.

    Thanks All
    Charlie

Resources