如何在ARM模板中创建针对Application Insights的Azure活动日志警报?
如何在ARM模板中创建Application Insights自定义日志搜索警报(Scheduled Query Rule)
我太懂这种困扰了——Azure门户的自动化脚本有时候确实会漏掉microsoft.insights/scheduledqueryrules这类资源,尤其是针对Application Insights的自定义日志搜索警报。别担心,我给你准备了完整的ARM模板示例,拆解关键配置,帮你顺利部署。
首先要明确:你提到的“活动日志警报”其实属于另一种资源类型(microsoft.insights/activitylogalerts),而针对Application Insights自定义日志搜索的警报,对应的正确资源类型是microsoft.insights/scheduledqueryrules,这也是门户自动化脚本没捕获到它的原因之一。
下面是可直接复用的ARM模板,包含必要的参数和配置:
{ "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "parameters": { "alertName": { "type": "string", "metadata": { "description": "名称 of the custom log search alert rule" } }, "applicationInsightsResourceId": { "type": "string", "metadata": { "description": "Resource ID of your target Application Insights instance" } }, "actionGroupResourceId": { "type": "string", "metadata": { "description": "Resource ID of the action group to notify when alert triggers" } }, "customSearchQuery": { "type": "string", "metadata": { "description": "Your custom log search query (same as the one you used in the portal)" } }, "queryFrequencyInMinutes": { "type": "int", "defaultValue": 5, "metadata": { "description": "How often the alert runs the query (minimum 1 minute)" } }, "queryTimeWindowInMinutes": { "type": "int", "defaultValue": 15, "metadata": { "description": "Time range the query covers (must be >= frequency)" } }, "alertThreshold": { "type": "int", "defaultValue": 1, "metadata": { "description": "Number of results needed to trigger the alert" } } }, "resources": [ { "type": "microsoft.insights/scheduledqueryrules", "apiVersion": "2021-08-01", "name": "[parameters('alertName')]", "location": "[resourceGroup().location]", "properties": { "description": "Custom log search alert for Application Insights", "enabled": true, "source": { "query": "[parameters('customSearchQuery')]", "dataSourceId": "[parameters('applicationInsightsResourceId')]", "queryType": "ResultCount" }, "schedule": { "frequencyInMinutes": "[parameters('queryFrequencyInMinutes')]", "timeWindowInMinutes": "[parameters('queryTimeWindowInMinutes')]" }, "action": { "odata.type": "Microsoft.WindowsAzure.Management.Monitoring.Alerts.Models.Microsoft.AppInsights.Nexus.DataContracts.Resources.ScheduledQueryRules.AlertingAction", "severity": "1", "aznsAction": { "actionGroup": "[array(parameters('actionGroupResourceId'))]" }, "trigger": { "thresholdOperator": "GreaterThan", "threshold": "[parameters('alertThreshold')]" } } } } ] }
关键配置说明:
- 资源类型与API版本:必须使用
microsoft.insights/scheduledqueryrules,API版本推荐用2021-08-01(稳定版,兼容性好) - 数据源配置:
dataSourceId要填你的Application Insights实例的完整资源ID,query就是你在门户里用的自定义搜索语句 - 调度规则:
frequencyInMinutes是查询执行间隔,timeWindowInMinutes是查询覆盖的时间范围,注意后者必须大于等于前者 - 触发条件:
queryType设为ResultCount表示基于查询结果数量触发;如果是基于指标计算(比如平均响应时间),可以改成Metric;thresholdOperator支持GreaterThan/LessThan等,根据需求调整 - 操作组配置:
aznsAction.actionGroup需要传入数组类型,所以用array()包裹你的操作组ID,这样就能复用你已配置好的通知渠道 - 位置:建议和Application Insights实例同区域,这里用资源组位置简化配置,如果AI在其他区域,直接替换成对应区域字符串即可
部署这个模板后,你可以在Azure门户的「警报规则」列表里找到它,测试一下是否能正常触发和通知——和你手动创建的效果完全一致。
内容的提问来源于stack exchange,提问作者Jonas K
相关产品推荐
相关产品推荐

