Azure Monitor Alerting: Rules, Action Groups, and Investigation
Pluralsight Hands-On Lab — Monitoring
At a Glance
| Platform | Pluralsight |
| Category | Azure Monitoring |
| Lab Type | Guided + Challenge Mode |
| Environment | Azure Portal, Azure Monitor, Activity Log, Azure Cloud Shell (Bash), Azure CLI |
| Completed | 2026 |
Overview
Azure Monitor alerting provides three complementary components for operational awareness: alert rules that define when to fire, action groups that define who to notify and how, and alert processing rules that suppress or modify alerts during known maintenance windows. These three Pluralsight labs cover the full alerting lifecycle — creating rules via both the portal and Azure CLI, configuring multi-channel action groups, triggering alerts and investigating them through the Activity Log, and suppressing alert noise during scheduled maintenance windows.
Lab 1 — Configure Logging and Alerts with Activity Log and Azure Monitor
- Created an alert rule in Azure Monitor scoped to the subscription, using "Delete Virtual Machine" as the signal condition and naming the rule "vm-delete-alert"
- Triggered the alert by deleting the lab VM and waiting approximately five minutes for propagation
- Filtered the Activity Log by Virtual Machines resource type, located the VM deletion event with Succeeded status, and reviewed event details including the affected resource, timestamp, and initiating identity
- Opened Azure Monitor Alerts, selected the fired vm-delete-alert, and reviewed alert details — demonstrating how this data supports incident investigation workflows
Lab 2 — Configure an Azure Monitor Alert Rule via CLI
- Set environment variables for resource group name and storage account resource ID in Azure Cloud Shell (Bash)
- Created an action group (my-agl) with an SMS receiver using Azure CLI:
az monitor action-group create \
--name $action_group_name \
--short-name $action_group_name \
--resource-group $resource_group_name \
--action sms <name> 1 <phone>
- Created an activity log alert rule (myalertrule3) scoped to the storage account, triggering on Administrative category write operations:
az monitor activity-log alert create \
--name "myalertrule3" \
--resource-group $resource_group_name \
--scope $rule_scope \
--condition "category=Administrative and operationName=Microsoft.Storage/storageAccounts/write" \
--action-group $action_group_name
- Confirmed alert creation with az monitor activity-log alert list and verified the rule appeared in the portal's Alert rules blade
Lab 3 — Alert Rules, Action Groups, and Alert Processing Rules
- Created an alert rule scoped to the lab storage account using Availability as the signal condition, severity 1 - Error, named "storage01Unavailable"
- Created an action group (notifyOfUnavailable) with two notification channels: an Email/SMS/Push/Voice notification with common alert schema enabled, and a Webhook action pointing to a fictitious URI
- Created an alert processing rule (updateWindow) scoped to lab-VM with Suppress notifications action type, configured as a recurring weekly schedule every Sunday from 3:00 AM to 5:00 AM to silence alerts during a known VM maintenance window
← Back to Pluralsight Labs