The Alert table contains legacy information that is only logged in older versions of log search alerts. The official method to query all alerts, regardless of version or alert type, is by using Azure Resource Graph (ARG) to query Alerts metadata.
Schema
Name
Description
Type
_BilledSize
Double
_IsBillable
String
_ResourceId
A unique identifier for the resource that the record is associated with
String
_SubscriptionId
A unique identifier for the subscription that the record is associated with
String
AlertContext
Details of the data item that caused the alert to be generated in XML format.
String
AlertDescription
Detailed description of the alert.
String
AlertError
String
AlertId
GUID of the alert.
String
AlertName
Name of the alert.
String
AlertPriority
Priority level of the alert.
String
AlertRuleId
String
AlertRuleInstanceId
String
AlertSeverity
Severity level of the alert.
String
AlertState
Latest resolution state of the alert.
String
AlertStatus
Int32
AlertTypeDescription
String
AlertTypeNumber
Int32
AlertValue
Int32
Comments
String
Computer
String
Custom1
String
Custom10
String
Custom2
String
Custom3
String
Custom4
String
Custom5
String
Custom6
String
Custom7
String
Custom8
String
Custom9
String
Expression
String
Flags
Int32
FlagsDescription
String
HostName
String
LastModifiedBy
Name of the user who last modified the alert.
String
LinkToSearchResults
String
ManagementGroupName
Name of the management group for System Center Operations Manager agents.
String
ObjectDisplayName
String
PriorityNumber
Int32
Query
String used to run the query
String
QueryExecutionEndTime
DateTime
QueryExecutionStartTime
DateTime
RemediationJobId
String
RemediationRunbookName
String
RepeatCount
Number of times the same alert was generated for the same monitored object since being resolved.
Int32
ResolvedBy
Name of the user who resolved the alert. Empty if the alert has not yet been resolved.
String
ResourceId
Unique identifier of the resource accessed
String
ResourceType
Type of cloud resource
String
ResourceValue
String
RootObjectName
String
ServiceDeskConnectionName
String
ServiceDeskId
String
ServiceDeskWorkItemLink
String
ServiceDeskWorkItemType
String
SourceDisplayName
Display name of the monitoring object that generated the alert.
String
SourceFullName
Full name of the monitoring object that generated the alert.
String
SourceSystem
String
StateType
String
StatusDescription
String
TemplateId
String
ThresholdOperator
String
ThresholdValue
Int32
TicketId
Ticket ID for the alert if the System Center Operations Manager environment is integrated with a process for assigning tickets for alerts. Empty of no ticket ID is assigned.
String
TimeGenerated
Date and time the record was created.
DateTime
TimeLastModified
Date and time that the alert was last changed.
DateTime
TimeRaised
Date and time that the alert was generated.
DateTime
TimeResolved
Date and time that the alert was resolved. Empty if the alert has not yet been resolved.