Monitoring Azure Unified Alerts

Download this manual as a PDF file

This section describes the Azure unified alert Event Policies that are included in the "Microsoft: Azure" PowerPack and information about configuring Azure and Skylar One to generate events based on Azure unified alerts.

Prerequisites for Configuring Azure Unified Alerts

In addition to Skylar One collecting metrics for Azure resources, you can configure Azure to send alert information to Skylar One via API. Skylar One can then generate an event for each alert.

To monitor Azure unified alerts, you must first configure Azure to proactively send alerts when important conditions are found in your Azure monitoring data. Azure bases these alerts on metrics and activity logs, and raises them when the alert's monitor condition is set to "fired".

You must also create alert rules in Azure that determine the following:

  • The resource that the alert is targeting
  • The signal from the target resource that could trigger the alert
  • The logic that determines whether the signal from the target resource actually triggers the alert

For details about how to create and manage alert rules, see https://docs.microsoft.com/en-us/azure/azure-monitor/platform/alerts-overview.

Azure Unified Alert Event Policies

The "Microsoft: Azure" PowerPack includes several pre-defined event policies for unified alerts, based on their severity:

Event Policy Name Event Source Severity
Microsoft: Azure Alert Severity 0 API Critical
Microsoft: Azure Alert Severity 1 API Major
Microsoft: Azure Alert Severity 2 API Minor
Microsoft: Azure Alert Severity 3 API Notice
Microsoft: Azure Alert Severity 4 API Notice

Microsoft: Azure Alert Severity 0 Resolved

Microsoft: Azure Alert Severity 1 Resolved

Microsoft: Azure Alert Severity 2 Resolved

Microsoft: Azure Alert Severity 3 Resolved

Microsoft: Azure Alert Severity 4 Resolved

API Healthy

The Healthy events trigger when the alert's monitor condition is "resolved" or the alert state is "acknowledged" or "closed".

These events are aligned to Azure component devices in the following way:

  • If Skylar One can determine the specific Azure resource that generated the alert, it checks whether that resource is discovered as a component device. If so, Skylar One aligns the event with that resource's component device.
  • If Skylar One cannot determine the specific resource, it checks whether it can determine the Azure service that generated the alert instead. If that service is discovered as a component device, Skylar One aligns the event with that service's component device.
  • In version 122 and later of the "Microsoft: Azure" PowerPack, if Skylar One cannot determine an appropriate resource or service component device, it aligns the event with the Azure subscription component device. If you do not want alerts aligned with the Azure subscription component device, then you can disable that feature.

Enabling the "Microsoft: Azure Unified Alerts Performance" Dynamic Application

The "Microsoft: Azure" PowerPack also includes a "Microsoft: Azure Unified Alerts Performance" Dynamic Application. This Dynamic Application collects alerts from the Azure API for all available resources and associates the alerts with the appropriate Azure component devices in Skylar One, if applicable. If an appropriate component device does not exist in Skylar One or cannot be determined, Skylar One instead associates the alert with the component device for the Azure subscription.

You must enable this Dynamic Application if you want Skylar One to generate unified alert events.

To enable the "Microsoft: Azure Unified Alerts Performance" Dynamic Application:

  1. Go to the Dynamic Applications Manager page (System > Manage > Dynamic Applications).
  2. Locate the "Microsoft: Azure Unified Alerts Performance" Dynamic Application and then click its wrench icon (wrench icon). The Dynamic Applications Properties Editor page appears.
  3. In the Operational State field, select Enabled.
  4. Click Save.

Starting in version 122 of the "Microsoft: Azure" PowerPack, you can opt to disable unified alert collection for an entire Azure subscription using the "Enable Unified Alert Collection" threshold object in the "Microsoft: Azure Unified Alerts Performance" Dynamic Application.

To configure this threshold:

  1. Go to the Dynamic Applications Manager page (System > Manage > Dynamic Applications).
  2. Locate the "Microsoft: Azure Unified Alerts Performance" Dynamic Application and then click its wrench icon (wrench icon). The Dynamic Applications Properties Editor page appears.
  3. Click the Thresholds tab.
  4. Locate the "Enable Unified Alert Collection" threshold object and click its wrench icon (wrench icon).
  5. In the Threshold Value field, type "0".
  6. Click Save.

Viewing Azure Unified Alert Counts

After you have enabled the "Microsoft: Azure Unified Alerts Performance" Dynamic Application and it has begun collecting alerts from the Azure API, you can view a count of the total number of alerts generated for each severity level for a given component device.

By default, the "Microsoft: Azure Unified Alerts Performance" Dynamic Application collects alerts over a one-day period.

To view Azure unified alert counts:

  1. Go to the Device Components page (Devices > Device Components).
  2. Click the plus-sign icon (+) for your Azure service until you locate the Azure component device for which you want to see an alert count. Click its graph icon (). The Device Summary page appears.
  3. Click the Performance tab. The Device Performance page appears.
  4. Click the Microsoft: Azure Unified Alerts Performance link to expand the options listed, and then select the alert severity for which you want to see metrics. The performance graph displays a graph detailing the count for your selected alert severity over the selected timespan.