{"_id":"@alerthq/provider-azure-monitor","_rev":"2-5dd1ca3c23a5dbe3719b8d143e065505","name":"@alerthq/provider-azure-monitor","dist-tags":{"latest":"0.0.1"},"versions":{"0.0.1":{"name":"@alerthq/provider-azure-monitor","version":"0.0.1","keywords":["alerthq","provider","azure","monitor","alerts","monitoring"],"license":"MIT","_id":"@alerthq/provider-azure-monitor@0.0.1","maintainers":[{"name":"rsafaya","email":"rsafaya@edrv.io"}],"homepage":"https://github.com/ai-software-agency/alerthq#readme","bugs":{"url":"https://github.com/ai-software-agency/alerthq/issues"},"dist":{"shasum":"f16ae9297e69bf39db53e9b305eb6ba2070bb0d0","tarball":"https://registry.npmjs.org/@alerthq/provider-azure-monitor/-/provider-azure-monitor-0.0.1.tgz","fileCount":5,"integrity":"sha512-SxFg95sC2RO0b6n7YwdH+wLlX6Pc0H2gHwrqmYIPXuTUpuV/HTANmxjBIwJbDn8RlDmXzIv+tPywb8SBd7UcLA==","signatures":[{"sig":"MEQCICVY0XNHXDgD3rThDIqgXuwq14y8afQ5H29EgXRp0TS8AiALnq4G1jbxGkQ3AAZOmyzBDZd6td37IqVjdACwndFWbw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":16448},"main":"./dist/index.js","type":"module","_from":"file:alerthq-provider-azure-monitor-0.0.1.tgz","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"scripts":{"lint":"eslint src/","test":"vitest run --passWithNoTests","build":"tsup src/index.ts --format esm --dts","typecheck":"tsc --noEmit"},"_npmUser":{"name":"rsafaya","email":"rsafaya@edrv.io"},"_resolved":"/private/var/folders/y_/sbbsfnm54k310t77b7c43cdm0000gn/T/c7d5dd1473d6a29b3162e9c3f43fc85d/alerthq-provider-azure-monitor-0.0.1.tgz","_integrity":"sha512-SxFg95sC2RO0b6n7YwdH+wLlX6Pc0H2gHwrqmYIPXuTUpuV/HTANmxjBIwJbDn8RlDmXzIv+tPywb8SBd7UcLA==","repository":{"url":"git+https://github.com/ai-software-agency/alerthq.git","type":"git","directory":"packages/provider-azure-monitor"},"_npmVersion":"11.7.0","description":"Azure Monitor alert provider for alerthq","directories":{},"_nodeVersion":"25.4.0","dependencies":{"zod":"^3.24.0","@azure/identity":"^4.5.0","@azure/arm-monitor":"^7.0.0"},"_hasShrinkwrap":false,"peerDependencies":{"@alerthq/core":"0.0.1"},"_npmOperationalInternal":{"tmp":"tmp/provider-azure-monitor_0.0.1_1775722588419_0.5488753555876336","host":"s3://npm-registry-packages-npm-production"}}},"time":{"created":"2026-04-09T08:16:28.296Z","modified":"2026-04-09T09:10:23.642Z","0.0.1":"2026-04-09T08:16:28.563Z"},"bugs":{"url":"https://github.com/ai-software-agency/alerthq/issues"},"license":"MIT","homepage":"https://github.com/ai-software-agency/alerthq#readme","keywords":["alerthq","provider","azure","monitor","alerts","monitoring"],"repository":{"url":"git+https://github.com/ai-software-agency/alerthq.git","type":"git","directory":"packages/provider-azure-monitor"},"description":"Azure Monitor alert provider for alerthq","maintainers":[{"email":"dpipalia@edrv.io","name":"dhruvin-edrv"},{"email":"rsafaya@edrv.io","name":"rsafaya"}],"readme":"# @alerthq/provider-azure-monitor\n\nAzure Monitor alert provider for [alerthq](https://github.com/edrv/alerthq).\n\n## Supported Alert Types\n\n| Alert Type | API Source | Notes |\n|------------|-----------|-------|\n| Metric Alerts | `metricAlerts.listBySubscription()` via `@azure/arm-monitor` | Standard and dynamic threshold metric alerts |\n| Activity Log Alerts | `activityLogAlerts.listBySubscriptionId()` via `@azure/arm-monitor` | Service health, resource health, administrative alerts |\n| Scheduled Query Rules | `scheduledQueryRules.listBySubscription()` via `@azure/arm-monitor` | Log search alerts (KQL-based) |\n\n## Authentication\n\nUses Azure `DefaultAzureCredential` from `@azure/identity`, which tries credentials in this order:\n\n1. Environment variables (`AZURE_CLIENT_ID`, `AZURE_TENANT_ID`, `AZURE_CLIENT_SECRET`)\n2. Managed Identity (on Azure VMs, App Service, Functions, etc.)\n3. Azure CLI (`az login`)\n4. Azure PowerShell\n5. Visual Studio Code Azure Account extension\n\nSee: [DefaultAzureCredential documentation](https://learn.microsoft.com/en-us/javascript/api/@azure/identity/defaultazurecredential)\n\n## Configuration\n\nAdd to your `alerthq.yaml`:\n\n```yaml\nproviders:\n  azure-monitor:\n    enabled: true\n    subscriptionIds:\n      - 12345678-1234-1234-1234-123456789abc\n      - 87654321-4321-4321-4321-cba987654321\n```\n\n| Field | Type | Required | Default | Description |\n|-------|------|----------|---------|-------------|\n| `subscriptionIds` | `string[]` | Yes | — | Azure subscription IDs to scan for alerts |\n\n## Required Permissions\n\nThe authenticated identity needs the **Reader** role (or equivalent) on each subscription. Specifically:\n\n- `Microsoft.Insights/metricAlerts/read`\n- `Microsoft.Insights/activityLogAlerts/read`\n- `Microsoft.Insights/scheduledQueryRules/read`\n\nThe built-in **Monitoring Reader** role covers all three.\n\n## Field Mapping\n\n### Metric Alerts\n\n| AlertDefinition Field | Source |\n|-----------------------|--------|\n| `id` | `generateAlertId('azure-metric-alert', resource.id)` |\n| `source` | `'azure-metric-alert'` |\n| `sourceId` | `resource.id` (full Azure resource ID) |\n| `name` | `resource.name` |\n| `description` | `properties.description` |\n| `enabled` | `properties.enabled` |\n| `severity` | `properties.severity` mapped: 0-1 = critical, 2 = warning, 3-4 = info |\n| `conditionSummary` | Built from `criteria.allOf` (metricNamespace, metricName, timeAggregation, operator, threshold) |\n| `notificationTargets` | Action group IDs extracted as `actionGroup:<name>` |\n| `tags` | Azure resource tags |\n| `lastModifiedAt` | `systemData.lastModifiedAt` |\n\n### Activity Log Alerts\n\n| AlertDefinition Field | Source |\n|-----------------------|--------|\n| `id` | `generateAlertId('azure-activity-log-alert', resource.id)` |\n| `source` | `'azure-activity-log-alert'` |\n| `severity` | `'unknown'` (activity log alerts have no severity) |\n| `conditionSummary` | Built from `condition.allOf` (field == value, field in [...]) |\n| `notificationTargets` | Action group IDs from `actions.actionGroups` |\n\n### Scheduled Query Rules\n\n| AlertDefinition Field | Source |\n|-----------------------|--------|\n| `id` | `generateAlertId('azure-scheduled-query-rule', resource.id)` |\n| `source` | `'azure-scheduled-query-rule'` |\n| `name` | `properties.displayName` (falls back to `resource.name`) |\n| `severity` | `properties.severity` mapped same as metric alerts |\n| `conditionSummary` | Built from `criteria.allOf` (query, timeAggregation, operator, threshold, failingPeriods) |\n| `notificationTargets` | Action group IDs from `actions.actionGroups` |\n\n## Limitations\n\n- Each alert type uses a different `source` prefix (`azure-metric-alert`, `azure-activity-log-alert`, `azure-scheduled-query-rule`), not a single `azure-monitor` source.\n- Activity log alerts have no native severity — always mapped to `'unknown'`.\n- Owner is always empty — Azure resource `systemData.createdBy` is not mapped to `owner`.\n- If listing a particular alert type fails for a subscription (insufficient permissions), that type is skipped and the others still proceed.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}