SOLVED

LogAnalytics Workspaces - Suppression of alarms from specific Resources

%3CLINGO-SUB%20id%3D%22lingo-sub-1592573%22%20slang%3D%22en-US%22%3ELogAnalytics%20Workspaces%20-%20Suppression%20of%20alarms%20from%20specific%20Resources%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1592573%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all%20just%20a%20quick%20question.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20currently%20have%20a%20suppress%20rule%20for%20the%20resource%20group%20with%20all%20of%20the%20resources%20in%20that%20RG%20suppressed.%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20also%20have%20another%20RG%20with%20log%20analytics%20workspace%2C%20and%20this%20workspace%20is%20getting%20all%20the%20PERF%20counters%20from%20all%20the%20machines%2C%20like%20a%20bucket%20from%20all%20%22Perf%22%20counters.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20want%20to%20suppress%20only%20the%20alarms%20from%20that%20machines%20on%20that%20resource%20group%20that%20is%20currently%20suppressed.%3C%2FP%3E%0A%3CP%3EIs%20it%20possible%3F%26nbsp%3B%3C%2FP%3E%0A%3CP%3Eor%20do%20I%20have%20to%20suppress%20all%20the%20alarms%20from%20that%20Log%20Analytics%20workspace%3F%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIs%20there%20any%20way%20I%20can%20only%20suppress%20some%20alarms%20from%20log%20analytics%3F%26nbsp%3B%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThanks%20in%20advance%20for%20your%20time%20and%20help.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EBest%20Regards.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1592573%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAlerts%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1596001%22%20slang%3D%22en-US%22%3ERe%3A%20LogAnalytics%20Workspaces%20-%20Suppression%20of%20alarms%20from%20specific%20Resources%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1596001%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F714167%22%20target%3D%22_blank%22%3E%40loadedlouie27%3C%2FA%3E%26nbsp%3Bthe%20best%20was%20is%20if%20you%20use%20'Aggregated%20on'%2C%20in%20a%20metric%20measure%20log%20alert%20rule%2C%20on%20'_ResourceId'.%20Then%20use%20Action%20Rules%20to%20suppress%20based%20on%20the%20alert%20content%2C%20setting%20the%20relevant%20resource%20group%20from%20the%20VM%20ARM%20resource%20ID.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EExample%20of%20VM%20resource%20ID%3A%3C%2FP%3E%0A%3CP%3E%3CSPAN%3E%2Fsubscriptions%2F%7BsubscriptionId%7D%2F%3CSTRONG%3EresourceGroups%2F%7BresourceGroupName%7D%3C%2FSTRONG%3E%2Fproviders%2FMicrosoft.Compute%2FvirtualMachines%2F%7BvmName%7D%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAction%20rules%20context%20filter%3A%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22yalavi_0-1597759422062.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F213071i1A4135C432FCD464%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22yalavi_0-1597759422062.png%22%20alt%3D%22yalavi_0-1597759422062.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1599175%22%20slang%3D%22en-US%22%3ERe%3A%20LogAnalytics%20Workspaces%20-%20Suppression%20of%20alarms%20from%20specific%20Resources%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1599175%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F390831%22%20target%3D%22_blank%22%3E%40yalavi%3C%2FA%3E%26nbsp%3BFirst%20of%20all%20thanks%20for%20your%20reply...%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20will%20try%20that%20approach.%20and%20provide%20feedback%20in%20the%20next%20couple%20of%20days.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1600816%22%20slang%3D%22en-US%22%3ERe%3A%20LogAnalytics%20Workspaces%20-%20Suppression%20of%20alarms%20from%20specific%20Resources%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1600816%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F390831%22%20target%3D%22_blank%22%3E%40yalavi%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20for%20the%20help%20that%20worked.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThumbs%20UP%20%3AD%3C%2Fimg%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hi all just a quick question. 

 

I currently have a suppress rule for the resource group with all of the resources in that RG suppressed. 

I also have another RG with log analytics workspace, and this workspace is getting all the PERF counters from all the machines, like a bucket from all "Perf" counters. 

 

I want to suppress only the alarms from that machines on that resource group that is currently suppressed.

Is it possible? 

or do I have to suppress all the alarms from that Log Analytics workspace? 

Is there any way I can only suppress some alarms from log analytics?  

 

Thanks in advance for your time and help. 

 

Best Regards.

 

3 Replies
Best Response confirmed by loadedlouie27 (Occasional Contributor)
Solution

@loadedlouie27 the best was is if you use 'Aggregated on', in a metric measure log alert rule, on '_ResourceId'. Then use Action Rules to suppress based on the alert content, setting the relevant resource group from the VM ARM resource ID. 

 

Example of VM resource ID:

/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Compute/virtualMachines/{vmName}

 

 

Action rules context filter:

yalavi_0-1597759422062.png

 

@yalavi First of all thanks for your reply... 

 

I will try that approach. and provide feedback in the next couple of days. 

 

 

 

@yalavi

 

Thanks for the help that worked. 

 

Thumbs UP :D