SOLVED
Home

Create OMS Alert throug ARM template

%3CLINGO-SUB%20id%3D%22lingo-sub-293989%22%20slang%3D%22en-US%22%3ECreate%20OMS%20Alert%20throug%20ARM%20template%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-293989%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%20all%3C%2FP%3E%3CP%3EI%20am%20trying%20to%20create%20an%20oms%20workspace%20with%20alerts%20attached%20to%20it%20through%20ARM%20templates.%20I%20already%20created%20an%20OMS%20workspace%20and%20for%20the%20alert%20part%20I%20followed%20the%20following%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fabcdazure.azurewebsites.net%2Fhow-to-deploy-oms-alerts-with-arm-template%2F%22%20target%3D%22_blank%22%20rel%3D%22noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Etutorial%3C%2FA%3E.%20After%20some%20struggle%20why%20my%20alert%20won't%20deploy%20i%20saw%20in%20the%20commands%20of%20the%20same%20tuturial%20following%20note.%3C%2FP%3E%3CP%3EThe%20%22Action%22%20scheme%20has%20been%20changed%20and%20additionally%20the%20alerts%20are%20in%20the%20Azure%20Monitor%3A)%20Here%20is%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fnl-nl%2Fazure%2Fazure-monitor%2Finsights%2Fsolutions-resources-searches-alerts%23actions%22%20target%3D%22_blank%22%20rel%3D%22noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Elink%3C%2FA%3E%22%3C%2FP%3E%3CP%3EWhen%20I%20tried%20to%20read%20the%20documentation%20and%20get%20any%20smarter%20I%20just%20got%20stuck%20in%20a%20endless%20loop%20of%20reference%20links%3A%3C%2FP%3E%3CP%3EThe%20link%20provided%20in%20the%20tutorial%20said%20that%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3EBeginning%20May%2014%2C%202018%2C%20all%20alerts%20in%20an%20Azure%20public%20cloud%20instance%20of%20Log%20Analytics%20workspace%20began%20to%20extend%20into%20Azure.%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3EAfter%20some%20time%20I%20found%20following%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fnl-nl%2Fazure%2Fmonitoring-and-diagnostics%2Fmonitoring-create-action-group-with-resource-manager-template%22%20target%3D%22_blank%22%20rel%3D%22noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Elink%3C%2FA%3E.%20Where%20I%20thought%20I%20finaly%20found%20how%20the%20new%20alert%20will%20be%20explained.%20But%20this%20is%20for%20application%20insights%20not%20for%20log%20analytics.%3C%2FP%3E%3CP%3ETO%20my%20question%20than%3A%20Is%20there%20someone%20who%20can%20help%20me%20out%20try%20to%20find%20how%20the%20new%20Alert%20scheme%20works%20or%20try%20to%20guide%20me%20in%20the%20right%20direction.%3C%2FP%3E%3CP%3EPS%3A%20the%20arm%20template%20of%20my%20first%20tutorial%20gave%20me%20following%20error%20%3A%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fstackoverflow.com%2Fquestions%2F53554346%2Fdeploying-oms-alerts-through-arm-templates-give-bad-gateway%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Edeploying%20OMS%20Alerts%20through%20ARM%20templates%20give%20bad%20gateway%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-293989%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20Log%20Analytics%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-325021%22%20slang%3D%22en-US%22%3ERe%3A%20Create%20OMS%20Alert%20throug%20ARM%20template%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-325021%22%20slang%3D%22en-US%22%3E%3CP%3EThe%20solution%20is%20example%20in%20case%20you%20want%20to%20wrap%20more%20than%20alert%20into%20a%20solution.%20It%20is%20a%20matter%20of%20preference.%20I%20avoid%20using%20wrapping%20Azure%20Monitor%20resources%20into%20solution%20these%20days.%20So%20it%20is%20ok%20to%20remove%20that%20part%20of%20the%20code.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-324955%22%20slang%3D%22en-US%22%3ERe%3A%20Create%20OMS%20Alert%20throug%20ARM%20template%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-324955%22%20slang%3D%22en-US%22%3E%3CP%3EThank%20you%20Stan!%20it%20works%20like%20a%20charm.%20But%20i%20have%20a%20doubt.%20what%20is%20the%20solution%20here%20and%20why%20it%20is%20mandatory.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%22SolutionName%22%3A%20%22MySolution%22%2C%3CBR%20%2F%3E%22SolutionVersion%22%3A%20%221.0%22%2C%3CBR%20%2F%3E%22SolutionPublisher%22%3A%20%22Contoso%22%2C%3CBR%20%2F%3E%22ProductName%22%3A%20%22SampleSolution%22%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ein%20real%20time%20should%20we%20change%20the%20above%20fields.%20Sorry%2C%20i%20mean%20we%20have%20to%20use%20the%20same%20publisher%2Fproduct%20names%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-301445%22%20slang%3D%22en-US%22%3ERe%3A%20Create%20OMS%20Alert%20throug%20ARM%20template%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-301445%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%0A%3CP%3ETo%20have%20performance%20data%20from%20servers%20appearing%20in%20Log%20Analytics%20and%20being%20able%20to%20alert%20on%20it%20with%20Log%20Analytics%20queries%20you%20will%20need%20to%20add%20the%20desired%20performance%20counters.%20This%20is%20explained%20here%3A%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fdata-sources-performance-counters%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fdata-sources-performance-counters%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-301407%22%20slang%3D%22en-US%22%3ERe%3A%20Create%20OMS%20Alert%20throug%20ARM%20template%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-301407%22%20slang%3D%22en-US%22%3E%3CP%3EI%20am%20sorry%20for%20the%20bad%20explanation.%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20i%20mean%20is%20that%20in%20my%20query%20i%20can%20use%20%22Heartbeat%22%26nbsp%3B%20and%20get%20results.%20But%20i%20can%20ask%20for%20performance%20logs.%20So%20therefore%20i%20asked%20if%20i%20need%20some%20extra%20resource%20so%20that%20every%20log%20of%20the%20virtual%20machine%20will%20be%20pushed%20to%20the%20log%20analytics.%20So%20that%20i%20can%20run%20the%20%22Perf%22%20query%20on%20my%20log%20analytics.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-295402%22%20slang%3D%22en-US%22%3ERe%3A%20Create%20OMS%20Alert%20throug%20ARM%20template%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-295402%22%20slang%3D%22en-US%22%3E%3CP%3EThese%20are%20Log%20Analytics%20alerts.%20They%20are%20general%20in%20nature%20and%20are%20not%20linked%20to%20any%20Azure%20resource.%20Log%20Analytics%20can%20store%20data%20from%20Azure%20and%20non-Azure%20resources.%20The%20main%20part%20of%20the%20alert%20is%20the%20query%20and%20the%20query%20can%20be%20scoped%20for%20example%20to%20specific%20group%20of%20computers%20or%20to%20apply%20to%20all%20computers%20that%20report%20data%20to%20Log%20Analytics.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-295396%22%20slang%3D%22en-US%22%3ERe%3A%20Create%20OMS%20Alert%20throug%20ARM%20template%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-295396%22%20slang%3D%22en-US%22%3E%3CP%3EWhat%20I%20don't%20understand%20%2C%20is%20how%20my%20alerts%20that%20I%20create%20being%20connected%20to%20the%20virtual%20machine.%3CBR%20%2F%3EIf%20i%20create%20an%20alert%20under%20%3A%20workspaces%5Csavedsearch%5Cshedule%5Cactions%26nbsp%3B%20%26nbsp%3Bthe%20alerts%20in%20the%20portal%20are%20shown%20under%20the%20workspace%20resource%20and%20not%20under%20the%20virtual%20machine.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-294483%22%20slang%3D%22en-US%22%3ERe%3A%20Create%20OMS%20Alert%20throug%20ARM%20template%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-294483%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%0A%3CP%3EThe%20blog%20post%20you%20reference%20is%20old%20as%20there%20are%20changes%20in%20the%20API.%20Log%20Analytics%20alerts%20no%20longer%20use%20their%20own%20actions%20rather%20they%20reference%20Action%20Group.%20So%20you%20first%20you%20have%20to%20have%20Action%20Group%20to%20reference.%20You've%20found%20the%20link%20for%20creating%20Action%20Group%20via%20ARM%20template.%20You've%20also%20find%20the%20template%20for%20creating%20Log%20Analytics%20alerts.%20You%20still%20have%20to%20create%20saved%20search%2C%20schedule%20and%20action%20resources.%20The%20main%20difference%20in%20the%20action%20you%20have%20to%20reference%20the%20Action%20Group.%20The%20extending%20alerts%20to%20Azure%20means%20that%20if%20you%20had%20created%20previously%20alerts%20that%20were%20using%20the%20api%20referenced%20in%20the%20blog%20post%20you've%20provided%20will%20be%20converted%20to%20using%20Action%20Group%20automatically.%20In%20short%20the%20only%20differences%20are%20the%20API%20version%20is%20increased%20and%20this%20part%20of%20action%20resources%3A%3C%2FP%3E%0A%3CPRE%3E%20%22EmailNotification%22%3A%20%7B%0A%20%20%20%20%20%20%20%20%20%20%20%20%22Recipients%22%3A%20%5B%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%22%5Bparameters('EmailRecipients')%5D%22%0A%20%20%20%20%20%20%20%20%20%20%20%20%5D%2C%0A%20%20%20%20%20%20%20%20%20%20%20%20%22Subject%22%3A%20%22%5Bparameters('DisplayNameOfSearch')%5D%22%0A%20%20%20%20%20%20%20%20%7D%3C%2FPRE%3E%0A%3CP%3Ecannot%20be%20used%20but%20instead%20you%20have%20to%20references%20action%20group.%3C%2FP%3E%0A%3CPRE%3E%22AzNsNotification%22%3A%20%7B%0A%20%20%20%20%20%20%20%20%22GroupIds%22%3A%20%22%5Bvariables('MyAlert').AzNsNotification.GroupIds%5D%22%2C%0A%20%20%20%20%20%20%20%20%22CustomEmailSubject%22%3A%20%22%5Bvariables('MyAlert').AzNsNotification.CustomEmailSubject%5D%22%2C%0A%20%20%20%20%20%20%20%20%22CustomWebhookPayload%22%3A%20%22%5Bvariables('MyAlert').AzNsNotification.CustomWebhookPayload%5D%22%0A%20%20%20%20%20%20%20%20%7D%3C%2FPRE%3E%0A%3CP%3ECustomEmailSubject%20and%20CustomWebhookPayload%20are%20not%20mandatory%20parameters%20and%20if%20they%20are%20not%20used%20you%20can%20skip%20them.%20You%20can%20also%20see%20GroupIds%20is%20actually%20array%20so%20you%20can%20reference%20multiple%20resource%20groups%20if%20needed.%20Look%20at%20the%20full%20sample%20to%20help%20you%20understand%20better%3A%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Finsights%2Fsolutions-resources-searches-alerts%23sample%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Finsights%2Fsolutions-resources-searches-alerts%23sample%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Bilal_Achahbar
Occasional Contributor

Hi  all

I am trying to create an oms workspace with alerts attached to it through ARM templates. I already created an OMS workspace and for the alert part I followed the following tutorial. After some struggle why my alert won't deploy i saw in the commands of the same tuturial following note.

The "Action" scheme has been changed and additionally the alerts are in the Azure Monitor:) Here is link"

When I tried to read the documentation and get any smarter I just got stuck in a endless loop of reference links:

The link provided in the tutorial said that Beginning May 14, 2018, all alerts in an Azure public cloud instance of Log Analytics workspace began to extend into Azure. After some time I found following link. Where I thought I finaly found how the new alert will be explained. But this is for application insights not for log analytics.

TO my question than: Is there someone who can help me out try to find how the new Alert scheme works or try to guide me in the right direction.

PS: the arm template of my first tutorial gave me following error : deploying OMS Alerts through ARM templates give bad gateway

7 Replies
Solution

Hi,

The blog post you reference is old as there are changes in the API. Log Analytics alerts no longer use their own actions rather they reference Action Group. So you first you have to have Action Group to reference. You've found the link for creating Action Group via ARM template. You've also find the template for creating Log Analytics alerts. You still have to create saved search, schedule and action resources. The main difference in the action you have to reference the Action Group. The extending alerts to Azure means that if you had created previously alerts that were using the api referenced in the blog post you've provided will be converted to using Action Group automatically. In short the only differences are the API version is increased and this part of action resources:

 "EmailNotification": {
            "Recipients": [
                "[parameters('EmailRecipients')]"
            ],
            "Subject": "[parameters('DisplayNameOfSearch')]"
        }

cannot be used but instead you have to references action group.

"AzNsNotification": {
        "GroupIds": "[variables('MyAlert').AzNsNotification.GroupIds]",
        "CustomEmailSubject": "[variables('MyAlert').AzNsNotification.CustomEmailSubject]",
        "CustomWebhookPayload": "[variables('MyAlert').AzNsNotification.CustomWebhookPayload]"
        }

CustomEmailSubject and CustomWebhookPayload are not mandatory parameters and if they are not used you can skip them. You can also see GroupIds is actually array so you can reference multiple resource groups if needed. Look at the full sample to help you understand better:

https://docs.microsoft.com/en-us/azure/azure-monitor/insights/solutions-resources-searches-alerts#sa...

 

What I don't understand , is how my alerts that I create being connected to the virtual machine.
If i create an alert under : workspaces\savedsearch\shedule\actions   the alerts in the portal are shown under the workspace resource and not under the virtual machine.

These are Log Analytics alerts. They are general in nature and are not linked to any Azure resource. Log Analytics can store data from Azure and non-Azure resources. The main part of the alert is the query and the query can be scoped for example to specific group of computers or to apply to all computers that report data to Log Analytics.

I am sorry for the bad explanation. 

What i mean is that in my query i can use "Heartbeat"  and get results. But i can ask for performance logs. So therefore i asked if i need some extra resource so that every log of the virtual machine will be pushed to the log analytics. So that i can run the "Perf" query on my log analytics.

Hi,

To have performance data from servers appearing in Log Analytics and being able to alert on it with Log Analytics queries you will need to add the desired performance counters. This is explained here:

https://docs.microsoft.com/en-us/azure/azure-monitor/platform/data-sources-performance-counters

Thank you Stan! it works like a charm. But i have a doubt. what is the solution here and why it is mandatory.

 

"SolutionName": "MySolution",
"SolutionVersion": "1.0",
"SolutionPublisher": "Contoso",
"ProductName": "SampleSolution",

 

in real time should we change the above fields. Sorry, i mean we have to use the same publisher/product names?

The solution is example in case you want to wrap more than alert into a solution. It is a matter of preference. I avoid using wrapping Azure Monitor resources into solution these days. So it is ok to remove that part of the code.