如何定位停止Azure关键VM的操作用户?
Hey Usha, sorry to hear your critical Azure VM went down unexpectedly—let’s walk through the steps you can take to track down the responsible user, even without a standalone monitoring tool configured:
Start with the Azure Activity Log
This is your first and most reliable stop. Azure automatically logs all control-plane operations (like starting/stopping VMs) by default, and these logs are retained for 90 days. Here’s how to access them:- In the Azure Portal: Navigate to your VM → Under "Monitoring", select "Activity log". Filter for the
Microsoft.Compute/virtualMachines/powerOff/actionoperation, and check the Caller column—it will show the user ID or UPN of the person who initiated the stop. - Using Azure CLI: Run this command to pull the relevant logs directly:
az monitor activity-log list --resource-group <your-resource-group-name> --resource-type Microsoft.Compute/virtualMachines --filter "operationName eq 'Microsoft.Compute/virtualMachines/powerOff/action'" --output table
- In the Azure Portal: Navigate to your VM → Under "Monitoring", select "Activity log". Filter for the
Cross-Reference with Azure AD Audit Logs
If the operation was performed by an Azure AD user, you can get more context (like the user’s full name, IP address, or other related actions) by checking Azure AD’s audit logs:- Go to the Azure AD portal → Under "Monitoring", select "Audit logs". Filter for actions related to "Azure Resources" or specifically for the VM stop event. This will tie the Activity Log’s caller ID to a full user profile.
Check VM Boot Diagnostics (if enabled)
While boot diagnostics primarily capture startup logs, if your VM had this feature enabled, it might contain timestamped logs that align with the stop event. This won’t directly give you the user, but it can help confirm the exact time of the stop and rule out any internal VM issues that might have caused a crash (as opposed to a manual stop).Verify Resource Lock Changes
If you had a resource lock on the VM, check the Activity Log for anyMicrosoft.Authorization/locks/deleteoperations around the time the VM stopped—someone might have removed the lock before initiating the stop.
Even without Application Insights or dedicated monitoring, Azure’s built-in logging should have the information you need. Start with the Activity Log—it’s the most straightforward way to find the caller.
内容的提问来源于stack exchange,提问作者usha chokka

