Types of Health Log Analytics alerts

  • Rversion finale: Australia
  • Mis à jour 12 mars 2026
  • 1 minute de lecture
  • Health Log Analytics generates several types of alerts.

    In the list of alerts, all alerts that are generated by Health Log Analytics have the value Log Analytics in the Source column.

    The value in the Group column identifies the type of alert as one of the following:

    Component-based alert
    Component-based alerts involve more than one configuration item (CI). A component is a logical component of a service instance that caused the alert. A component can be multiple CIs that perform the same function, such as multiple redundant hosts.
    Important :
    Each Component-based alert is the parent of a number of read-only alerts. You do not work directly on read-only alerts. You work only on the parent Component-based alert.
    In this example service instance, the identical Java apps X, Y, and Z make up a single component: Component B. Tomcat servers Q, R, and S and their hosts make up a different single component: Component C.
    Figure 1. Example service instance
    Service instance with four components.
    Log Analytics alert
    A Log Analytics alert identifies an anomaly that involves a single CI. A Log Analytics alert has the value None in the Group column. The anomaly that leads to the alert can be an unexpected number of log entries or an unexpected value of a metric.
    Log Analytics group
    When the system identifies multiple Log Analytics alerts that are related in important ways, it groups them into a Log Analytics group. A Log Analytics group can group up to four alerts. The system generates a Log Analytics group when the Log Analytics alerts share one or more of the following relationships:
    • Time: The events all occurred within a configured time interval.
    • Metadata: The alerts have matching values in log-line metadata. For example, all alerts involve the same host.
    • Message text: The message text in the log data is similar or identical between alerts.
    • Trend: The alerts show a similar tendency in values or rates. For example, a particular metric value is increasing in all alerts.
    Remarque :
    You can mark an alert as significant. A significant alert is more likely to be included in a Log Analytics group when the associated metric behaves anomalously. For more information, see Mark an alert as significant in Health Log Analytics.