Azure PowerShell中New-AzActivityLogAlert的Action参数存在Bug
Azure PowerShell New-AzActivityLogAlert -Action参数无法关联动作组的问题与解决方法
在使用Azure PowerShell的New-AzActivityLogAlert cmdlet创建活动日志警报时,发现-Action参数存在Bug,无法将指定的动作组关联到警报规则。以下是相关实现代码:
# Variables $task3storageAccountName = "testRG" $actionGroupName = "Storage Admins" $actionGroupShortName = "SA Admins" $notificationName = "Email storage admins" $emailAddress = "test@gmail.com" # Replace with your actual email # Get the Storage Account and its resource ID (this will be used in the alert rule) $storageAccount = Get-AzStorageAccount -Name $task3storageAccountName -ResourceGroupName $resourceGroupName Write-Host "For task 3 the storage account '$task3storageAccountName' will be used.`nResource ID: $($storageAccount.Id)" $storageAccount | Format-List # Create receiver object $email1 = New-AzActionGroupEmailReceiverObject -EmailAddress $emailAddress -Name "Name" $sms1 = New-AzActionGroupSmsReceiverObject -CountryCode '61' -Name user2 -PhoneNumber '00000000' # Create action group $actionGroup=New-AzActionGroup ` -Name $actionGroupName ` -ResourceGroupName $resourceGroupName ` -Location "global" ` -GroupShortName $actionGroupShortName ` -EmailReceiver $email1 ` -SmsReceiver $sms1 $alertRuleName = "Storage account key generation failed" $location = "global" $categoryCondition = New-AzActivityLogAlertAlertRuleAnyOfOrLeafConditionObject ` -Field "category" ` -Equal "Administrative" # Operation name filter $operationCondition = New-AzActivityLogAlertAlertRuleAnyOfOrLeafConditionObject ` -Field "operationName" ` -Equal "Microsoft.Storage/storageAccounts/regenerateKey/action" # Status filter $statusCondition = New-AzActivityLogAlertAlertRuleAnyOfOrLeafConditionObject ` -Field "status" ` -Equal "Failed" # Create the alert # There's a bug in the Az module that prevents the use of the -Action parameter. $alert=New-AzActivityLogAlert ` -Name $alertRuleName ` -ResourceGroupName $resourceGroupName ` -Action $actionGroup ` -Condition @($categoryCondition, $operationCondition, $statusCondition) ` -Location $location ` -Scope $storageAccount.Id ` -Enabled:$true
临时解决方法(依赖Azure CLI)
目前可通过Azure CLI命令补加动作组,但需同时登录Azure CLI和PowerShell,操作繁琐:
az monitor activity-log alert action-group add -n test2 -g $resourceGroupName --action $actionGroup.Id
纯PowerShell替代解决方法
方法1:创建警报时使用动作组引用对象
避免直接传入动作组对象,先构造动作组引用对象再传入-Action参数:
# 创建动作组引用对象 $actionRef = New-AzActivityLogAlertActionGroupObject -Id $actionGroup.Id # 创建警报并关联动作组 $alert = New-AzActivityLogAlert ` -Name $alertRuleName ` -ResourceGroupName $resourceGroupName ` -Action $actionRef ` -Condition @($categoryCondition, $operationCondition, $statusCondition) ` -Location $location ` -Scope $storageAccount.Id ` -Enabled:$true
方法2:先创建警报再追加动作组
若方法1仍无效,可先创建不含动作组的警报,再通过Set-AzActivityLogAlert添加动作组:
# 先创建基础警报 $alert = New-AzActivityLogAlert ` -Name $alertRuleName ` -ResourceGroupName $resourceGroupName ` -Condition @($categoryCondition, $operationCondition, $statusCondition) ` -Location $location ` -Scope $storageAccount.Id ` -Enabled:$true # 追加动作组到警报 $alert.Action.ActionGroup += New-AzActivityLogAlertActionGroupObject -Id $actionGroup.Id Set-AzActivityLogAlert -InputObject $alert
内容的提问来源于stack exchange,提问作者Álvaro
相关产品推荐
相关产品推荐

