You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在ARM模板中创建针对Application Insights的Azure活动日志警报?

如何在ARM模板中创建Application Insights自定义日志搜索警报(Scheduled Query Rule)

我太懂这种困扰了——Azure门户的自动化脚本有时候确实会漏掉microsoft.insights/scheduledqueryrules这类资源,尤其是针对Application Insights的自定义日志搜索警报。别担心,我给你准备了完整的ARM模板示例,拆解关键配置,帮你顺利部署。

首先要明确:你提到的“活动日志警报”其实属于另一种资源类型(microsoft.insights/activitylogalerts),而针对Application Insights自定义日志搜索的警报,对应的正确资源类型是microsoft.insights/scheduledqueryrules,这也是门户自动化脚本没捕获到它的原因之一。

下面是可直接复用的ARM模板,包含必要的参数和配置:

{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "alertName": {
      "type": "string",
      "metadata": {
        "description": "名称 of the custom log search alert rule"
      }
    },
    "applicationInsightsResourceId": {
      "type": "string",
      "metadata": {
        "description": "Resource ID of your target Application Insights instance"
      }
    },
    "actionGroupResourceId": {
      "type": "string",
      "metadata": {
        "description": "Resource ID of the action group to notify when alert triggers"
      }
    },
    "customSearchQuery": {
      "type": "string",
      "metadata": {
        "description": "Your custom log search query (same as the one you used in the portal)"
      }
    },
    "queryFrequencyInMinutes": {
      "type": "int",
      "defaultValue": 5,
      "metadata": {
        "description": "How often the alert runs the query (minimum 1 minute)"
      }
    },
    "queryTimeWindowInMinutes": {
      "type": "int",
      "defaultValue": 15,
      "metadata": {
        "description": "Time range the query covers (must be >= frequency)"
      }
    },
    "alertThreshold": {
      "type": "int",
      "defaultValue": 1,
      "metadata": {
        "description": "Number of results needed to trigger the alert"
      }
    }
  },
  "resources": [
    {
      "type": "microsoft.insights/scheduledqueryrules",
      "apiVersion": "2021-08-01",
      "name": "[parameters('alertName')]",
      "location": "[resourceGroup().location]",
      "properties": {
        "description": "Custom log search alert for Application Insights",
        "enabled": true,
        "source": {
          "query": "[parameters('customSearchQuery')]",
          "dataSourceId": "[parameters('applicationInsightsResourceId')]",
          "queryType": "ResultCount"
        },
        "schedule": {
          "frequencyInMinutes": "[parameters('queryFrequencyInMinutes')]",
          "timeWindowInMinutes": "[parameters('queryTimeWindowInMinutes')]"
        },
        "action": {
          "odata.type": "Microsoft.WindowsAzure.Management.Monitoring.Alerts.Models.Microsoft.AppInsights.Nexus.DataContracts.Resources.ScheduledQueryRules.AlertingAction",
          "severity": "1",
          "aznsAction": {
            "actionGroup": "[array(parameters('actionGroupResourceId'))]"
          },
          "trigger": {
            "thresholdOperator": "GreaterThan",
            "threshold": "[parameters('alertThreshold')]"
          }
        }
      }
    }
  ]
}

关键配置说明:

  • 资源类型与API版本:必须使用microsoft.insights/scheduledqueryrules,API版本推荐用2021-08-01(稳定版,兼容性好)
  • 数据源配置:dataSourceId要填你的Application Insights实例的完整资源ID,query就是你在门户里用的自定义搜索语句
  • 调度规则:frequencyInMinutes是查询执行间隔,timeWindowInMinutes是查询覆盖的时间范围,注意后者必须大于等于前者
  • 触发条件:queryType设为ResultCount表示基于查询结果数量触发;如果是基于指标计算(比如平均响应时间),可以改成Metric;thresholdOperator支持GreaterThan/LessThan等,根据需求调整
  • 操作组配置:aznsAction.actionGroup需要传入数组类型,所以用array()包裹你的操作组ID,这样就能复用你已配置好的通知渠道
  • 位置:建议和Application Insights实例同区域,这里用资源组位置简化配置,如果AI在其他区域,直接替换成对应区域字符串即可

部署这个模板后,你可以在Azure门户的「警报规则」列表里找到它,测试一下是否能正常触发和通知——和你手动创建的效果完全一致。

内容的提问来源于stack exchange,提问作者Jonas K

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 06:58:14