services/KeyVault/vaults/alerts.yaml (203 lines of code) (raw):
- name: Activity Log Key Vault Delete
description: Activity Log Alert for Key Vault Delete
type: ActivityLog
verified: false
visible: true
tags:
- alz
- rag
properties:
category: Administrative
operationName: Microsoft.KeyVault/vaults/delete
status:
- succeeded
references:
- name: Activity Log Service Notifications
url: https://learn.microsoft.com/azure/service-health/alerts-activity-log-service-notifications-portal
- name: Best practices for setting up service health alerts
url: https://www.microsoft.com/videoplayer/embed/RE2OtUa
deployments:
- name: Deploy Activity Log Key Vault Delete Alert
template: Deploy-ActivityLog-KeyVault-Del.json
type: Policy
tags:
- alz
properties:
scope: Subscription
policyScope: managementGroup
documented: false
alertName: ActivityKeyVaultDelete
enabled: true
guid: f68ed392-7179-419d-8ee6-3813ea10866b
- name: Availability
description: Vault requests availability
type: Metric
verified: true
visible: true
tags:
- alz
- rag
properties:
metricName: Availability
metricNamespace: Microsoft.KeyVault/vaults
severity: 1
windowSize: PT5M
evaluationFrequency: PT1M
timeAggregation: Average
operator: LessThan
threshold: 90
criterionType: StaticThresholdCriterion
autoMitigate: false
enabled: true
references:
- name: Monitoring KeyVault Reference
url: https://docs.microsoft.com/en-us/azure/key-vault/general/monitor-key-vault-reference
- name: Monitoring Microsoft.KeyVault/vaults
url: https://docs.microsoft.com/en-us/azure/key-vault/general/monitor-key-vault
- name: KeyVault Insights Overview
url: https://docs.microsoft.com/en-us/azure/azure-monitor/insights/key-vault-insights-overview
deployments:
- name: Deploy KeyVault Availability Alert
template: Deploy-KV-Availability-Alert.json
type: Policy
tags:
- alz
properties:
scope: Resource
multiResource: true
guid: a3c8bcb4-22ca-45be-92f7-605f232ecec2
- name: SaturationShoebox
description: Vault capacity used
type: Metric
verified: true
visible: true
tags:
- alz
- rag
properties:
metricName: SaturationShoebox
metricNamespace: Microsoft.KeyVault/vaults
severity: 1
windowSize: PT5M
evaluationFrequency: PT1M
timeAggregation: Average
operator: GreaterThan
threshold: 75
criterionType: StaticThresholdCriterion
autoMitigate: false
enabled: true
references:
- name: Monitoring KeyVault Reference
url: https://docs.microsoft.com/en-us/azure/key-vault/general/monitor-key-vault-reference
- name: Monitoring Microsoft.KeyVault/vaults
url: https://docs.microsoft.com/en-us/azure/key-vault/general/monitor-key-vault
- name: KeyVault Insights Overview
url: https://docs.microsoft.com/en-us/azure/azure-monitor/insights/key-vault-insights-overview
deployments:
- name: Deploy KeyVault Capacity Alert
template: Deploy-KV-Capacity-Alert.json
type: Policy
tags:
- alz
properties:
scope: Resource
multiResource: true
guid: dc852755-e5df-4fd0-83ac-cbbc516f60b3
- name: ServiceApiLatency
description: Overall latency of service api requests
type: Metric
verified: true
visible: true
tags:
- alz
- rag
properties:
metricName: ServiceApiLatency
metricNamespace: Microsoft.KeyVault/vaults
severity: 3
windowSize: PT5M
evaluationFrequency: PT5M
timeAggregation: Average
operator: GreaterThan
threshold: 1000
criterionType: StaticThresholdCriterion
autoMitigate: false
enabled: true
references:
- name: Monitoring KeyVault Reference
url: https://docs.microsoft.com/en-us/azure/key-vault/general/monitor-key-vault-reference
- name: Monitoring Microsoft.KeyVault/vaults
url: https://docs.microsoft.com/en-us/azure/key-vault/general/monitor-key-vault
- name: KeyVault Insights Overview
url: https://docs.microsoft.com/en-us/azure/azure-monitor/insights/key-vault-insights-overview
deployments:
- name: Deploy KeyVault Latency Alert
template: Deploy-KV-Latency-Alert.json
type: Policy
tags:
- alz
properties:
scope: Resource
multiResource: true
guid: 2651f57f-ac74-44f3-8511-c245488134f8
- name: ServiceApiResult
description: Number of total service api results
type: Metric
verified: true
visible: true
tags:
- alz
- rag
properties:
metricName: ServiceApiResult
metricNamespace: Microsoft.KeyVault/vaults
severity: 2
windowSize: PT5M
evaluationFrequency: PT5M
timeAggregation: Average
operator: GreaterThan
criterionType: DynamicThresholdCriterion
alertSensitivity: Medium
failingPeriods:
numberOfEvaluationPeriods: 4
minFailingPeriodsToAlert: 4
autoMitigate: false
enabled: true
references:
- name: Monitoring KeyVault Reference
url: https://docs.microsoft.com/en-us/azure/key-vault/general/monitor-key-vault-reference
- name: Monitoring Microsoft.KeyVault/vaults
url: https://docs.microsoft.com/en-us/azure/key-vault/general/monitor-key-vault
- name: KeyVault Insights Overview
url: https://docs.microsoft.com/en-us/azure/azure-monitor/insights/key-vault-insights-overview
deployments:
- name: Deploy KeyVault Requests Alert
template: Deploy-KV-Requests-Alert.json
type: Policy
tags:
- alz
properties:
scope: Resource
multiResource: true
guid: 14356b19-1264-498d-b1cd-e3fa9f0c9fc9
- name: ServiceApiHit
description: Number of total service api hits
type: Metric
verified: false
visible: true
tags:
- auto-generated
- agc-1137
- rag
properties:
metricName: ServiceApiHit
metricNamespace: Microsoft.KeyVault/vaults
severity: 3
windowSize: PT5M
evaluationFrequency: PT5M
timeAggregation: Average
operator: GreaterThanOrEqual
criterionType: StaticThresholdCriterion
threshold: 80.0
enabled: true
guid: 7b52bf07-3d86-4429-b5d4-829a6a5542df