通过ARM模板部署Azure Firewall诊断设置时遇嵌套资源段数错误
Fixing "A nested resource type must have identical number of segments as its resource name" Error for Azure Firewall Diagnostic Settings
I see exactly what's causing this error - it boils down to a mismatch between your nested resource's type structure and its name format. Let's break this down and fix it:
The error message tells us that the number of segments in the resource type has to match the segments in the resource name. Your resource type is Microsoft.Network/azureFirewalls/diagnosticSettings (3 segments total), but your current name includes an extra, unnecessary Microsoft.Insights/ segment that breaks this alignment.
Issues in Your Original Code
- The name incorrectly includes
Microsoft.Insights/- diagnostic settings are a direct child resource of Azure Firewall, so this segment doesn't belong in the name. - There's a typo:
dignosticinstead ofdiagnosticin the concatenated name. - The inner
nameproperty underpropertiesis redundant since the top-levelnamefield already defines the diagnostic setting's name.
Corrected ARM Template Snippet
{ "$schema": "https://schema.management.azure.com/schemas/2015-01-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "parameters": {}, "variables": { "workspaceId": "[Concat('/subscriptions/', subscription().subscriptionId, '/resourceGroups/', resourceGroup().name, '/providers/Microsoft.OperationalInsights/workspaces/', 'Fw-LA')]" }, "resources": [ { "type": "Microsoft.Network/azureFirewalls/diagnosticSettings", "apiVersion": "2017-05-01-preview", "name": "[concat('FWHM/', 'diagnostic')]", "properties": { "workspaceId": "[variables('workspaceId')]", "logs": [ { "category": "AzureFirewallApplicationRule", "enabled": true, "retentionPolicy": { "days": 10, "enabled": false } } ], "metrics": [ { "category": "AllMetrics", "enabled": true, "retentionPolicy": { "enabled": false, "days": 0 } } ] } } ] }
Key Fixes Explained
- Aligned Resource Name: The name is now
[concat('FWHM/', 'diagnostic')], which matches the 3-segment resource type:Microsoft.Network/azureFirewalls/diagnosticSettings(parent resource: Azure Firewall namedFWHM, child resource: diagnostic setting nameddiagnostic). - Removed Unnecessary Segment:
Microsoft.Insights/was removed from the name - this isn't part of the nested hierarchy for Azure Firewall diagnostic settings. - Fixed Typo: Corrected
dignostictodiagnosticfor consistency. - Removed Redundant Property: The inner
namefield underpropertieswas deleted since the top-level name already defines the setting's identifier.
内容的提问来源于stack exchange,提问作者Sachin Kalia
相关产品推荐
相关产品推荐

