Forum Discussion

Juval's avatar
Juval
Brass Contributor
Jun 30, 2020
Solved

Easy way to exclude a resource from a Log analytics query alert?

If I have a query setup that checks high CPU from all VMs reporting to that log analytics workspace and i want to suppress one or two VMs for a while since i'm doing some operations to them. I know i can edit the query but would be nice if i could suppress or edit on the go to exclude a few resources.

  • Action Rules allow this using the payload option.
    https://docs.microsoft.com/en-us/azure/azure-monitor/platform/alerts-action-rules

5 Replies

  • Billy York's avatar
    Billy York
    Iron Contributor

    Juval you can do action rules. or you can use dimensions in the alert to only select resources you want.

    • Juval's avatar
      Juval
      Brass Contributor
      Hi! But i guess in that scenario i would need a new Action rules? I'm thinking if i already have alerts defined through a log analytics workspace and then i'm having a few misbehaving resources i would like to suppress the alerts from just those resources. If i understood pvyver right, i could just suppress those and see those values later what i did and even schedule it. I believe this is what i need.
      • pvyver's avatar
        pvyver
        Brass Contributor
        Yes, add a new Action Rule, scope to the workspace and specify the computer name in the payload.
        Specify the schedule, and you are good to go.
  • pvyver's avatar
    pvyver
    Brass Contributor
    Action Rules allow this using the payload option.
    https://docs.microsoft.com/en-us/azure/azure-monitor/platform/alerts-action-rules
    • Juval's avatar
      Juval
      Brass Contributor

      pvyver 
      Hi, ok so instead of messing with the original alert and adding basically a exemption list i could do a value or a list in the payload filter and suppress it that way. I like this cause this way i can see if i forgot it on or if i just need it to be suppressed for half a day. Awesome! Thanks!

Resources