SOLVED

Add Email to Smart Detect action group

%3CLINGO-SUB%20id%3D%22lingo-sub-1820666%22%20slang%3D%22en-US%22%3EAdd%20Email%20to%20Smart%20Detect%20action%20group%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1820666%22%20slang%3D%22en-US%22%3E%3CP%3EStruggling%20to%20find%20details%20on%20Smart%20Detect%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EIt%20is%20automatically%20enabled%20with%20Application%20insights%3F%20Where%20is%20the%20default%20creation%20location%3F%20Where%20can%20I%20find%20documentation%20for%20this%20behaviour%3F%26nbsp%3B%3C%2FLI%3E%0A%3CLI%3EIt%20creates%20Action%20groups%20and%20enabled%20the%20Monitor%20Contributor%20and%20Reader%20to%20receive%20mails.%20Doc%20on%20this%20Action%20group%20creation%3F%3C%2FLI%3E%0A%3CLI%3EIs%20there%20a%20PowerShell%20module%20for%20it%3F%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3ESince%20the%20Smart%20Detect%20enabled%20Failure%20anomalies%20alert%20rules%20on%20all%20Applications%20insights%20instances%20and%20connects%20it%20to%20the%20Action%20group%20%22%3CSPAN%3Eapplication%20insights%20smart%20detection%22%20that%20has%20mails%20sent%20to%20Roles%20monitor%20contributor%20and%20monitor%20reader.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EI%20am%20looking%20to%20add%20additional%20mail%20to%20this%20Action%20group%20with%20ARM%20or%20PowerShell.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3EThis%20is%20the%20docs%20for%20ARM...%20but%20it%20does%20not%20state%20how%20to%20add%20mail%20to%20the%20action%20group%2C%20just%20to%20the%20Alert%20rules....%3F%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fapp%2Fproactive-arm-config%3FWT.mc_id%3DAZ-MVP-5003531%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Eproactive-arm-config%3C%2FA%3E%3CBR%20%2F%3EThe%20section%20%22%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fapp%2Fproactive-arm-config%23add-additional-email-recipients-for-a-smart-detection-rule%3FWT.mc_id%3DAZ-MVP-5003531%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EAdd%20additional%20email%20recipient%20for%20smart%20detection%20rule%3C%2FA%3E%22%20sounds%20like%20a%20perfect%20fit%20but%20the%20example%20does%20not%20work%2C%20opened%20a%20%3CA%20href%3D%22https%3A%2F%2Fgithub.com%2FMicrosoftDocs%2Fazure-docs%2Fissues%2F64939%3FWT.mc_id%3DAZ-MVP-5003531%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Egithub%20issue.%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EAnyone%20able%20to%20advise%20on%20this%20matter%20and%20maybe%20point%20to%20more%20docs%3F%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F68580%22%20target%3D%22_blank%22%3E%40Harel%20Broitman%3C%2FA%3E%26nbsp%3Bmaybe%3F%3CBR%20%2F%3EThanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1824062%22%20slang%3D%22en-US%22%3ERe%3A%20Add%20Email%20to%20Smart%20Detect%20action%20group%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1824062%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F79760%22%20target%3D%22_blank%22%3E%40Michael%20Jonsson%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHi%20Michael%2C%20thanks%20for%20reaching%20out!%3C%2FP%3E%0A%3CP%3EYou%20may%20have%20received%20an%20answer%20already%20on%20a%20separate%20email%20but%20I%20will%20repeat%20the%20main%20points%20here%20for%20the%20community%20interest.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EEvery%20new%20Application%20Insights%20gets%2C%20by%20default%2C%20both%20Smart%20Detections%20and%20Failure%20Anomalies.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFailure%20Anomalies%20is%20an%20alert%20rule%20that%20is%20automatically%20created%20in%20the%20same%20resource%20group%20as%20the%20Application%20Insights%20resource.%20The%20Action%20group%20%E2%80%93%20%E2%80%9CApplication%20Insights%20Smart%20Detection%E2%80%9D%20%E2%80%93%20is%20created%20once%20per%20subscription%20and%20is%20shared%20by%20all%20alert%20rules%20in%20the%20same%20subscription.%20And%20yes%2C%20it%E2%80%99s%20resource%20group%20is%20determined%20by%20the%20first%20Application%20Insights%20resource%20created%20in%20the%20subscription.%3C%2FP%3E%0A%3CP%3EAside%20from%20Failure%20Anomalies%20there%20are%20other%20types%20of%20Smart%20Detections%2C%20however%20these%20types%20are%20not%20implemented%20as%20alerts%20and%20no%20alert%20rules%20are%20created%20for%20them.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ETo%20modify%20the%20action%20group%2C%20please%20follow%20%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fdocs.microsoft.com%252Fen-us%252Fazure%252Fazure-monitor%252Fsamples%252Fresource-manager-action-groups%26amp%3Bdata%3D04%257C01%257CYair.Gil%2540microsoft.com%257C0a0b9324f2794b1bf26908d87a711ed2%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C637393973547486860%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C1000%26amp%3Bsdata%3DPsNdrB0bhAnHKgs8%252BsiLoVhBM9LjsqwXyjjfPCccZRY%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ethis%20example%3C%2FA%3E.%20The%20example%20in%20your%20email%20below%20is%20for%20configuring%20Smart%20Detections%2C%20which%20are%20not%20alert%20and%20do%20not%20trigger%20the%20action%20group%2C%20so%20it%E2%80%99s%20not%20the%20correct%20one.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ERegarding%20Smart%20Detections%20which%20are%20not%20alerts%2C%20some%20of%20them%20are%20generating%20email%20notifications%2C%20but%20not%20using%20action%20groups.%20By%20default%20these%20notifications%20are%20sent%20to%20the%20subscription's%20monitoring%20contributors%20and%20monitoring%20readers.%20You%20can%20modify%20the%20email%20default%20through%20the%20Application%20Insights%20Smart%20Detections%20settings%20screen.%20You%20can%20enable%2Fdisable%20the%20default%20notification%20and%2For%20add%20new%20email%20destinations%20of%20your%20choice.%20Note%20that%20Smart%20Detections%20which%20are%20in%20preview%20status%20do%20not%20support%20email%20notification%2C%20you%20can%20only%20view%20these%20detections%20by%20checking%20out%20the%20Smart%20Detections%20in%20the%20portal.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20hope%20this%20is%20clear%20%E2%80%93%20please%20let%20me%20know%20if%20you%20have%20any%20questions.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ERegards%2C%20Yair%20Gil%2C%20Azure%20Monitor%20Program%20Manager%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1824606%22%20slang%3D%22en-US%22%3ERe%3A%20Add%20Email%20to%20Smart%20Detect%20action%20group%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1824606%22%20slang%3D%22en-US%22%3EHi%20Yair%3CBR%20%2F%3EThank%20you%20for%20the%20reply!%3CBR%20%2F%3EGreat%20to%20have%20this%20insight%20in%20the%20community%20space%20also.%3CBR%20%2F%3E%3CBR%20%2F%3EBr%3CBR%20%2F%3EMichael%3C%2FLINGO-BODY%3E
MVP

Struggling to find details on Smart Detect

 

  • It is automatically enabled with Application insights? Where is the default creation location? Where can I find documentation for this behaviour? 
  • It creates Action groups and enabled the Monitor Contributor and Reader to receive mails. Doc on this Action group creation?
  • Is there a PowerShell module for it?

Since the Smart Detect enabled Failure anomalies alert rules on all Applications insights instances and connects it to the Action group "application insights smart detection" that has mails sent to Roles monitor contributor and monitor reader. 

I am looking to add additional mail to this Action group with ARM or PowerShell.


This is the docs for ARM... but it does not state how to add mail to the action group, just to the Alert rules....? proactive-arm-config
The section "Add additional email recipient for smart detection rule" sounds like a perfect fit but the example does not work, opened a github issue.

Anyone able to advise on this matter and maybe point to more docs?

@Harel Broitman maybe?
Thanks

2 Replies
Best Response confirmed by Michael Jonsson (MVP)
Solution

@Michael Jonsson 

Hi Michael, thanks for reaching out!

You may have received an answer already on a separate email but I will repeat the main points here for the community interest.

 

Every new Application Insights gets, by default, both Smart Detections and Failure Anomalies.

 

Failure Anomalies is an alert rule that is automatically created in the same resource group as the Application Insights resource. The Action group – “Application Insights Smart Detection” – is created once per subscription and is shared by all alert rules in the same subscription. And yes, it’s resource group is determined by the first Application Insights resource created in the subscription.

Aside from Failure Anomalies there are other types of Smart Detections, however these types are not implemented as alerts and no alert rules are created for them.

 

To modify the action group, please follow this example. The example in your email below is for configuring Smart Detections, which are not alert and do not trigger the action group, so it’s not the correct one.

 

Regarding Smart Detections which are not alerts, some of them are generating email notifications, but not using action groups. By default these notifications are sent to the subscription's monitoring contributors and monitoring readers. You can modify the email default through the Application Insights Smart Detections settings screen. You can enable/disable the default notification and/or add new email destinations of your choice. Note that Smart Detections which are in preview status do not support email notification, you can only view these detections by checking out the Smart Detections in the portal.

 

I hope this is clear – please let me know if you have any questions.

 

Regards, Yair Gil, Azure Monitor Program Manager

Hi Yair
Thank you for the reply!
Great to have this insight in the community space also.

Br
Michael