Dimensions in webhook payload

%3CLINGO-SUB%20id%3D%22lingo-sub-1556502%22%20slang%3D%22en-US%22%3EDimensions%20in%20webhook%20payload%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1556502%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Azure%20Monitor%20team!%3CBR%20%2F%3ERecent%20blog%20update%20from%2024%20June%20mentions%20dimensions%20in%20fired%20alerts%20now%20showing%20better%20what%20was%20affected.%20When%20using%20common%20alert%20schema%2C%20it%20appears%20I'm%20starting%20to%20consistently%20see%20the%20actual%20affected%20device%20from%20a%20searchquery%20result%20in%20AffectedConfigurationItems.%20Is%20AffectedConfigurationItems%20the%20%22best%22%20place%20searchresults%20always%20will%20be%20placed%20in%3F%20I'm%20asking%20so%20that%20I%20know%20what%20part%20of%20the%20json%20webhook%20payload%20I%20need%20to%20go%20through%20to%20see%20what%20device%20the%20alert%20is%20for.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1556502%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAlerts%20%26amp%3B%20Actions%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1556571%22%20slang%3D%22en-US%22%3ERe%3A%20Dimensions%20in%20webhook%20payload%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1556571%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F611509%22%20target%3D%22_blank%22%3E%40Michael_Milirud%3C%2FA%3E%26nbsp%3B%20I've%20had%20that%20page%20sort%20of%20like%20a%20bible%20bookmarked%20and%20read%20it%20a%20number%20of%20times%2C%20but%20no%2C%20it%20doesn't%20say%20everything%20I%20need%20to%20know.%20With%20a%20Log%20Analytics%20query%20based%20alert%2C%20I%20would%20like%20to%20know%20if%20the%20AffectedConfigurationItems%20section%20will%20always%20hold%20the%20data%20of%20affected%20servers.%20I've%20noticed%20a%20few%20times%20that%20section%20in%20the%20json%20was%20empty%2C%20but%20there%20was%20data%20in%20the%20search%20results%20table.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ebtw%2C%20I%20mentioned%20a%20blog%2C%20%3CA%20href%3D%22https%3A%2F%2Fazure.microsoft.com%2Fen-us%2Fupdates%2Fimprovements-to-azure-monitor-log-alerts-include-new-links-and-added-dimensions%2F%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Ethis%20one%3C%2FA%3E%20was%20it.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAlso%2C%20Log%20analytics%20links%20to%20the%20portal%20are%20supposed%20to%20be%20compressed%2C%20but%20I'm%20still%20seeing%20very%20long%20links%20in%20the%20json%20data.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1556539%22%20slang%3D%22en-US%22%3ERe%3A%20Dimensions%20in%20webhook%20payload%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1556539%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F671042%22%20target%3D%22_blank%22%3E%40-Akos-%3C%2FA%3E%26nbsp%3Bstandard%20schema%20definition%20is%20service%20specific.%20Here%20are%20samples%20for%20each%20of%20the%20services.%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Falerts-common-schema-definitions%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Falerts-common-schema-definitions%3C%2FA%3E.%20Please%20let%20us%20know%20if%20this%20doesn't%20answer%20your%20question.%3CBR%20%2F%3E%3CBR%20%2F%3EBest%2C%26nbsp%3B%20Michael%3CBR%20%2F%3E-Azure%20Monitor%20Product%20Management%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

Hi Azure Monitor team!
Recent blog update from 24 June mentions dimensions in fired alerts now showing better what was affected. When using common alert schema, it appears I'm starting to consistently see the actual affected device from a searchquery result in AffectedConfigurationItems. Is AffectedConfigurationItems the "best" place searchresults always will be placed in? I'm asking so that I know what part of the json webhook payload I need to go through to see what device the alert is for.

6 Replies

@-Akos- standard schema definition is service specific. Here are samples for each of the services. https://docs.microsoft.com/en-us/azure/azure-monitor/platform/alerts-common-schema-definitions. Please let us know if this doesn't answer your question.

Best,  Michael
-Azure Monitor Product Management

@Michael_Milirud  I've had that page sort of like a bible bookmarked and read it a number of times, but no, it doesn't say everything I need to know. With a Log Analytics query based alert, I would like to know if the AffectedConfigurationItems section will always hold the data of affected servers. I've noticed a few times that section in the json was empty, but there was data in the search results table.

 

btw, I mentioned a blog, this one was it.

 

Also, Log analytics links to the portal are supposed to be compressed, but I'm still seeing very long links in the json data.

@-Akos- I've reached out to our alerting team to get an answer for you on this. If you are still seeing uncompressed links we should take a look at your repro. Can you share a sample JSON that you are seeing with issues highlighted?

Best,  Michael

@Michael_Milirud I will send you a message offline with some json data. I may need to redact some sensitive data, but the data will be intact otherwise

@-Akos- The post was about the new 'Dimensions' section in the payload for metric measure log alert type that you control, that split the alerts and provide the context of the fired alerts.

AffectedConfigurationItems is an old and only partly reliable feature that uses heuristics of column names.  Future API version will not have AffectedConfigurationItems, but will make it easier to define dimensions even for simple count of rows.

 

There is an example here (and in the common schema definition page you have):

https://docs.microsoft.com/en-us/azure/azure-monitor/platform/alerts-log-webhook#log-alert-for-log-a...

Hi @yalavi 

Thank you for your answer, but that is a bit of a shame. Currently I'm using this piece of code then to parse Log Analytics queries to get a list of affected machines:

        if($WebhookBody.SearchResult -ne $null){
            $SearchResultRows = $WebhookBody.SearchResult.tables[0].rows
            $SearchResultColumns = $WebhookBody.SearchResult.tables[0].columns;
            $Records = @()
            foreach ($SearchResultRow in $SearchResultRows){
                $Column = 0
                $Record = New-Object –TypeName PSObject
                foreach ($SearchResultColumn in $SearchResultColumns){
                    $Name = $SearchResultColumn.name
                    $ColumnValue = $SearchResultRow[$Column]
                    $Record | Add-Member –MemberType NoteProperty –Name $name –Value $ColumnValue -Force
                    $Column++
                }
                $Records += $Record
            }

But if I just could read out a single entry like $WebhookBody.data.alertContext.AffectedConfigurationItems it would have made life somewhat easier. 

 

The link you are referring to shows all sorts of examples that are not in the Common Alert Schema, which is what I want to avoid. I want to be able to properly parse json data, and I find it difficult enough as is. 

 

You mention a future API version; I hope enough examples will be put online on what the output will look like :smile: