Microsoft Certified: DevOps Engineer ExpertImplement an instrumentation strategyMedium
A company is implementing a new alerting strategy for their critical business applications hosted on Azure. They want to ensure that alerts are not only triggered but also routed to the correct teams based on the severity and affected service. Additionally, they need to integrate with an existing IT Service Management (ITSM) system to automatically create incident tickets. Which Azure Monitor component is responsible for defining the actions to be taken when an alert fires, including routing and ITSM integration?
- ALog Analytics workspaces
- BMetric alert rules
- CAlert processing rules
- DAction groups
Show answer & explanationAnswer & explanation
Correct answer: D. Action groups
Action groups in Azure Monitor define the collection of notifications and actions to be triggered when an alert fires. They support various actions including email, SMS, webhooks, ITSM integration, and more, making them central to an alerting strategy that includes routing and incident creation.
Why the other options are wrong
- A. Log Analytics workspaces store and analyze log data; they are a source for log alerts but not responsible for defining alert actions.
- B. Metric alert rules define *when* an alert should fire based on metric thresholds, not *what* actions should be taken.
- C. Alert processing rules are used to apply actions or suppress alerts at scale, but the *definition* of what action to take (e.g., send email, create ITSM ticket) resides in action groups.
Azure Monitor Action Groups
A collection of notification preferences and actions that can be triggered by an Azure alert, enabling automated responses and integrations.
- Reusable across multiple alert rules.
- Supports various actions: email, SMS, push notifications, webhooks, ITSM, runbooks, functions.
- Centralized management of alert responses.
Memory trick: Action Groups: The 'what to do' when an alert screams.