policy_events
Creates, updates, deletes, gets or lists a policy_events resource.
Overview
| Name | policy_events |
| Type | Resource |
| Id | azure.policy_insights.policy_events |
Fields
The following fields are returned by SELECT queries:
- list_query_results_for_resource_group_level_policy_assignment
- list_query_results_for_resource_group
- list_query_results_for_policy_set_definition
- list_query_results_for_policy_definition
- list_query_results_for_subscription_level_policy_assignment
- list_query_results_for_management_group
- list_query_results_for_subscription
- list_query_results_for_resource
| Name | Datatype | Description |
|---|---|---|
@odata | object | |
complianceState | string | Compliance state of the resource. |
components | array | Components events records populated only when URL contains $expand=components clause. |
effectiveParameters | string | Effective parameters for the policy assignment. |
isCompliant | boolean | Flag which states whether the resource is compliant against the policy assignment it was evaluated against. |
managementGroupIds | string | Comma separated list of management group IDs, which represent the hierarchy of the management groups the resource is under. |
policyAssignmentId | string | Policy assignment ID. |
policyAssignmentName | string | Policy assignment name. |
policyAssignmentOwner | string | Policy assignment owner. |
policyAssignmentParameters | string | Policy assignment parameters. |
policyAssignmentScope | string | Policy assignment scope. |
policyDefinitionAction | string | Policy definition action, i.e. effect. |
policyDefinitionCategory | string | Policy definition category. |
policyDefinitionId | string | Policy definition ID. |
policyDefinitionName | string | Policy definition name. |
policyDefinitionReferenceId | string | Reference ID for the policy definition inside the policy set, if the policy assignment is for a policy set. |
policySetDefinitionCategory | string | Policy set definition category, if the policy assignment is for a policy set. |
policySetDefinitionId | string | Policy set definition ID, if the policy assignment is for a policy set. |
policySetDefinitionName | string | Policy set definition name, if the policy assignment is for a policy set. |
policySetDefinitionOwner | string | Policy set definition owner, if the policy assignment is for a policy set. |
policySetDefinitionParameters | string | Policy set definition parameters, if the policy assignment is for a policy set. |
principalOid | string | Principal object ID for the user who initiated the resource operation that triggered the policy event. |
resourceGroup | string | Resource group name. |
resourceId | string | Resource ID. |
resourceLocation | string | Resource location. |
resourceTags | string | List of resource tags. |
resourceType | string | Resource type. |
subscriptionId | string | Subscription ID. |
tenantId | string | Tenant ID for the policy event record. |
timestamp | string (date-time) | Timestamp for the policy event record. |
| Name | Datatype | Description |
|---|---|---|
@odata | object | |
complianceState | string | Compliance state of the resource. |
components | array | Components events records populated only when URL contains $expand=components clause. |
effectiveParameters | string | Effective parameters for the policy assignment. |
isCompliant | boolean | Flag which states whether the resource is compliant against the policy assignment it was evaluated against. |
managementGroupIds | string | Comma separated list of management group IDs, which represent the hierarchy of the management groups the resource is under. |
policyAssignmentId | string | Policy assignment ID. |
policyAssignmentName | string | Policy assignment name. |
policyAssignmentOwner | string | Policy assignment owner. |
policyAssignmentParameters | string | Policy assignment parameters. |
policyAssignmentScope | string | Policy assignment scope. |
policyDefinitionAction | string | Policy definition action, i.e. effect. |
policyDefinitionCategory | string | Policy definition category. |
policyDefinitionId | string | Policy definition ID. |
policyDefinitionName | string | Policy definition name. |
policyDefinitionReferenceId | string | Reference ID for the policy definition inside the policy set, if the policy assignment is for a policy set. |
policySetDefinitionCategory | string | Policy set definition category, if the policy assignment is for a policy set. |
policySetDefinitionId | string | Policy set definition ID, if the policy assignment is for a policy set. |
policySetDefinitionName | string | Policy set definition name, if the policy assignment is for a policy set. |
policySetDefinitionOwner | string | Policy set definition owner, if the policy assignment is for a policy set. |
policySetDefinitionParameters | string | Policy set definition parameters, if the policy assignment is for a policy set. |
principalOid | string | Principal object ID for the user who initiated the resource operation that triggered the policy event. |
resourceGroup | string | Resource group name. |
resourceId | string | Resource ID. |
resourceLocation | string | Resource location. |
resourceTags | string | List of resource tags. |
resourceType | string | Resource type. |
subscriptionId | string | Subscription ID. |
tenantId | string | Tenant ID for the policy event record. |
timestamp | string (date-time) | Timestamp for the policy event record. |
| Name | Datatype | Description |
|---|---|---|
@odata | object | |
complianceState | string | Compliance state of the resource. |
components | array | Components events records populated only when URL contains $expand=components clause. |
effectiveParameters | string | Effective parameters for the policy assignment. |
isCompliant | boolean | Flag which states whether the resource is compliant against the policy assignment it was evaluated against. |
managementGroupIds | string | Comma separated list of management group IDs, which represent the hierarchy of the management groups the resource is under. |
policyAssignmentId | string | Policy assignment ID. |
policyAssignmentName | string | Policy assignment name. |
policyAssignmentOwner | string | Policy assignment owner. |
policyAssignmentParameters | string | Policy assignment parameters. |
policyAssignmentScope | string | Policy assignment scope. |
policyDefinitionAction | string | Policy definition action, i.e. effect. |
policyDefinitionCategory | string | Policy definition category. |
policyDefinitionId | string | Policy definition ID. |
policyDefinitionName | string | Policy definition name. |
policyDefinitionReferenceId | string | Reference ID for the policy definition inside the policy set, if the policy assignment is for a policy set. |
policySetDefinitionCategory | string | Policy set definition category, if the policy assignment is for a policy set. |
policySetDefinitionId | string | Policy set definition ID, if the policy assignment is for a policy set. |
policySetDefinitionName | string | Policy set definition name, if the policy assignment is for a policy set. |
policySetDefinitionOwner | string | Policy set definition owner, if the policy assignment is for a policy set. |
policySetDefinitionParameters | string | Policy set definition parameters, if the policy assignment is for a policy set. |
principalOid | string | Principal object ID for the user who initiated the resource operation that triggered the policy event. |
resourceGroup | string | Resource group name. |
resourceId | string | Resource ID. |
resourceLocation | string | Resource location. |
resourceTags | string | List of resource tags. |
resourceType | string | Resource type. |
subscriptionId | string | Subscription ID. |
tenantId | string | Tenant ID for the policy event record. |
timestamp | string (date-time) | Timestamp for the policy event record. |
| Name | Datatype | Description |
|---|---|---|
@odata | object | |
complianceState | string | Compliance state of the resource. |
components | array | Components events records populated only when URL contains $expand=components clause. |
effectiveParameters | string | Effective parameters for the policy assignment. |
isCompliant | boolean | Flag which states whether the resource is compliant against the policy assignment it was evaluated against. |
managementGroupIds | string | Comma separated list of management group IDs, which represent the hierarchy of the management groups the resource is under. |
policyAssignmentId | string | Policy assignment ID. |
policyAssignmentName | string | Policy assignment name. |
policyAssignmentOwner | string | Policy assignment owner. |
policyAssignmentParameters | string | Policy assignment parameters. |
policyAssignmentScope | string | Policy assignment scope. |
policyDefinitionAction | string | Policy definition action, i.e. effect. |
policyDefinitionCategory | string | Policy definition category. |
policyDefinitionId | string | Policy definition ID. |
policyDefinitionName | string | Policy definition name. |
policyDefinitionReferenceId | string | Reference ID for the policy definition inside the policy set, if the policy assignment is for a policy set. |
policySetDefinitionCategory | string | Policy set definition category, if the policy assignment is for a policy set. |
policySetDefinitionId | string | Policy set definition ID, if the policy assignment is for a policy set. |
policySetDefinitionName | string | Policy set definition name, if the policy assignment is for a policy set. |
policySetDefinitionOwner | string | Policy set definition owner, if the policy assignment is for a policy set. |
policySetDefinitionParameters | string | Policy set definition parameters, if the policy assignment is for a policy set. |
principalOid | string | Principal object ID for the user who initiated the resource operation that triggered the policy event. |
resourceGroup | string | Resource group name. |
resourceId | string | Resource ID. |
resourceLocation | string | Resource location. |
resourceTags | string | List of resource tags. |
resourceType | string | Resource type. |
subscriptionId | string | Subscription ID. |
tenantId | string | Tenant ID for the policy event record. |
timestamp | string (date-time) | Timestamp for the policy event record. |
| Name | Datatype | Description |
|---|---|---|
@odata | object | |
complianceState | string | Compliance state of the resource. |
components | array | Components events records populated only when URL contains $expand=components clause. |
effectiveParameters | string | Effective parameters for the policy assignment. |
isCompliant | boolean | Flag which states whether the resource is compliant against the policy assignment it was evaluated against. |
managementGroupIds | string | Comma separated list of management group IDs, which represent the hierarchy of the management groups the resource is under. |
policyAssignmentId | string | Policy assignment ID. |
policyAssignmentName | string | Policy assignment name. |
policyAssignmentOwner | string | Policy assignment owner. |
policyAssignmentParameters | string | Policy assignment parameters. |
policyAssignmentScope | string | Policy assignment scope. |
policyDefinitionAction | string | Policy definition action, i.e. effect. |
policyDefinitionCategory | string | Policy definition category. |
policyDefinitionId | string | Policy definition ID. |
policyDefinitionName | string | Policy definition name. |
policyDefinitionReferenceId | string | Reference ID for the policy definition inside the policy set, if the policy assignment is for a policy set. |
policySetDefinitionCategory | string | Policy set definition category, if the policy assignment is for a policy set. |
policySetDefinitionId | string | Policy set definition ID, if the policy assignment is for a policy set. |
policySetDefinitionName | string | Policy set definition name, if the policy assignment is for a policy set. |
policySetDefinitionOwner | string | Policy set definition owner, if the policy assignment is for a policy set. |
policySetDefinitionParameters | string | Policy set definition parameters, if the policy assignment is for a policy set. |
principalOid | string | Principal object ID for the user who initiated the resource operation that triggered the policy event. |
resourceGroup | string | Resource group name. |
resourceId | string | Resource ID. |
resourceLocation | string | Resource location. |
resourceTags | string | List of resource tags. |
resourceType | string | Resource type. |
subscriptionId | string | Subscription ID. |
tenantId | string | Tenant ID for the policy event record. |
timestamp | string (date-time) | Timestamp for the policy event record. |
| Name | Datatype | Description |
|---|---|---|
@odata | object | |
complianceState | string | Compliance state of the resource. |
components | array | Components events records populated only when URL contains $expand=components clause. |
effectiveParameters | string | Effective parameters for the policy assignment. |
isCompliant | boolean | Flag which states whether the resource is compliant against the policy assignment it was evaluated against. |
managementGroupIds | string | Comma separated list of management group IDs, which represent the hierarchy of the management groups the resource is under. |
policyAssignmentId | string | Policy assignment ID. |
policyAssignmentName | string | Policy assignment name. |
policyAssignmentOwner | string | Policy assignment owner. |
policyAssignmentParameters | string | Policy assignment parameters. |
policyAssignmentScope | string | Policy assignment scope. |
policyDefinitionAction | string | Policy definition action, i.e. effect. |
policyDefinitionCategory | string | Policy definition category. |
policyDefinitionId | string | Policy definition ID. |
policyDefinitionName | string | Policy definition name. |
policyDefinitionReferenceId | string | Reference ID for the policy definition inside the policy set, if the policy assignment is for a policy set. |
policySetDefinitionCategory | string | Policy set definition category, if the policy assignment is for a policy set. |
policySetDefinitionId | string | Policy set definition ID, if the policy assignment is for a policy set. |
policySetDefinitionName | string | Policy set definition name, if the policy assignment is for a policy set. |
policySetDefinitionOwner | string | Policy set definition owner, if the policy assignment is for a policy set. |
policySetDefinitionParameters | string | Policy set definition parameters, if the policy assignment is for a policy set. |
principalOid | string | Principal object ID for the user who initiated the resource operation that triggered the policy event. |
resourceGroup | string | Resource group name. |
resourceId | string | Resource ID. |
resourceLocation | string | Resource location. |
resourceTags | string | List of resource tags. |
resourceType | string | Resource type. |
subscriptionId | string | Subscription ID. |
tenantId | string | Tenant ID for the policy event record. |
timestamp | string (date-time) | Timestamp for the policy event record. |
| Name | Datatype | Description |
|---|---|---|
@odata | object | |
complianceState | string | Compliance state of the resource. |
components | array | Components events records populated only when URL contains $expand=components clause. |
effectiveParameters | string | Effective parameters for the policy assignment. |
isCompliant | boolean | Flag which states whether the resource is compliant against the policy assignment it was evaluated against. |
managementGroupIds | string | Comma separated list of management group IDs, which represent the hierarchy of the management groups the resource is under. |
policyAssignmentId | string | Policy assignment ID. |
policyAssignmentName | string | Policy assignment name. |
policyAssignmentOwner | string | Policy assignment owner. |
policyAssignmentParameters | string | Policy assignment parameters. |
policyAssignmentScope | string | Policy assignment scope. |
policyDefinitionAction | string | Policy definition action, i.e. effect. |
policyDefinitionCategory | string | Policy definition category. |
policyDefinitionId | string | Policy definition ID. |
policyDefinitionName | string | Policy definition name. |
policyDefinitionReferenceId | string | Reference ID for the policy definition inside the policy set, if the policy assignment is for a policy set. |
policySetDefinitionCategory | string | Policy set definition category, if the policy assignment is for a policy set. |
policySetDefinitionId | string | Policy set definition ID, if the policy assignment is for a policy set. |
policySetDefinitionName | string | Policy set definition name, if the policy assignment is for a policy set. |
policySetDefinitionOwner | string | Policy set definition owner, if the policy assignment is for a policy set. |
policySetDefinitionParameters | string | Policy set definition parameters, if the policy assignment is for a policy set. |
principalOid | string | Principal object ID for the user who initiated the resource operation that triggered the policy event. |
resourceGroup | string | Resource group name. |
resourceId | string | Resource ID. |
resourceLocation | string | Resource location. |
resourceTags | string | List of resource tags. |
resourceType | string | Resource type. |
subscriptionId | string | Subscription ID. |
tenantId | string | Tenant ID for the policy event record. |
timestamp | string (date-time) | Timestamp for the policy event record. |
| Name | Datatype | Description |
|---|---|---|
@odata | object | |
complianceState | string | Compliance state of the resource. |
components | array | Components events records populated only when URL contains $expand=components clause. |
effectiveParameters | string | Effective parameters for the policy assignment. |
isCompliant | boolean | Flag which states whether the resource is compliant against the policy assignment it was evaluated against. |
managementGroupIds | string | Comma separated list of management group IDs, which represent the hierarchy of the management groups the resource is under. |
policyAssignmentId | string | Policy assignment ID. |
policyAssignmentName | string | Policy assignment name. |
policyAssignmentOwner | string | Policy assignment owner. |
policyAssignmentParameters | string | Policy assignment parameters. |
policyAssignmentScope | string | Policy assignment scope. |
policyDefinitionAction | string | Policy definition action, i.e. effect. |
policyDefinitionCategory | string | Policy definition category. |
policyDefinitionId | string | Policy definition ID. |
policyDefinitionName | string | Policy definition name. |
policyDefinitionReferenceId | string | Reference ID for the policy definition inside the policy set, if the policy assignment is for a policy set. |
policySetDefinitionCategory | string | Policy set definition category, if the policy assignment is for a policy set. |
policySetDefinitionId | string | Policy set definition ID, if the policy assignment is for a policy set. |
policySetDefinitionName | string | Policy set definition name, if the policy assignment is for a policy set. |
policySetDefinitionOwner | string | Policy set definition owner, if the policy assignment is for a policy set. |
policySetDefinitionParameters | string | Policy set definition parameters, if the policy assignment is for a policy set. |
principalOid | string | Principal object ID for the user who initiated the resource operation that triggered the policy event. |
resourceGroup | string | Resource group name. |
resourceId | string | Resource ID. |
resourceLocation | string | Resource location. |
resourceTags | string | List of resource tags. |
resourceType | string | Resource type. |
subscriptionId | string | Subscription ID. |
tenantId | string | Tenant ID for the policy event record. |
timestamp | string (date-time) | Timestamp for the policy event record. |
Methods
The following methods are available for this resource:
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
management_group_name | string | Management group name. Required. |
policy_assignment_name | string | Policy assignment name. Required. |
policy_definition_name | string | Policy definition name. Required. |
policy_events_resource | string | The name of the virtual resource under PolicyEvents resource type; only "default" is allowed. "default" Required. |
policy_set_definition_name | string | Policy set definition name. Required. |
resource_group_name | string | The name of the resource group. The name is case insensitive. Required. |
resource_id | string | Resource ID. Required. |
subscription_id | string | The ID of the target subscription. The value must be an UUID. Required. |
$apply | string | OData apply expression for aggregations. Default value is None. |
$expand | string | The $expand query parameter. For example, to expand components use $expand=components. Default value is None. |
$filter | string | OData filter expression. Default value is None. |
$from | string (date-time) | ISO 8601 formatted timestamp specifying the start time of the interval to query. When not specified, the service uses ($to - 1-day). Default value is None. |
$orderby | string | Ordering expression using OData notation. One or more comma-separated column names with an optional "desc" (the default) or "asc", e.g. "$orderby=PolicyAssignmentId, ResourceId asc". Default value is None. |
$select | string | Select expression using OData notation. Limits the columns on each record to just those requested, e.g. "$select=PolicyAssignmentId, ResourceId". Default value is None. |
$skiptoken | string | Skiptoken is only provided if a previous response returned a partial result as a part of nextLink element. Default value is None. |
$to | string (date-time) | ISO 8601 formatted timestamp specifying the end time of the interval to query. When not specified, the service uses request time. Default value is None. |
$top | integer | Maximum number of records to return. Default value is None. |
SELECT examples
- list_query_results_for_resource_group_level_policy_assignment
- list_query_results_for_resource_group
- list_query_results_for_policy_set_definition
- list_query_results_for_policy_definition
- list_query_results_for_subscription_level_policy_assignment
- list_query_results_for_management_group
- list_query_results_for_subscription
- list_query_results_for_resource
Queries policy events for the resource group level policy assignment.
SELECT
@odata,
complianceState,
components,
effectiveParameters,
isCompliant,
managementGroupIds,
policyAssignmentId,
policyAssignmentName,
policyAssignmentOwner,
policyAssignmentParameters,
policyAssignmentScope,
policyDefinitionAction,
policyDefinitionCategory,
policyDefinitionId,
policyDefinitionName,
policyDefinitionReferenceId,
policySetDefinitionCategory,
policySetDefinitionId,
policySetDefinitionName,
policySetDefinitionOwner,
policySetDefinitionParameters,
principalOid,
resourceGroup,
resourceId,
resourceLocation,
resourceTags,
resourceType,
subscriptionId,
tenantId,
timestamp
FROM azure.policy_insights.policy_events
WHERE subscription_id = '{{ subscription_id }}' -- required
AND resource_group_name = '{{ resource_group_name }}' -- required
AND policy_events_resource = '{{ policy_events_resource }}' -- required
AND policy_assignment_name = '{{ policy_assignment_name }}' -- required
AND $top = '{{ $top }}'
AND $orderby = '{{ $orderby }}'
AND $select = '{{ $select }}'
AND $from = '{{ $from }}'
AND $to = '{{ $to }}'
AND $filter = '{{ $filter }}'
AND $apply = '{{ $apply }}'
AND $skiptoken = '{{ $skiptoken }}'
;
Queries policy events for the resources under the resource group.
SELECT
@odata,
complianceState,
components,
effectiveParameters,
isCompliant,
managementGroupIds,
policyAssignmentId,
policyAssignmentName,
policyAssignmentOwner,
policyAssignmentParameters,
policyAssignmentScope,
policyDefinitionAction,
policyDefinitionCategory,
policyDefinitionId,
policyDefinitionName,
policyDefinitionReferenceId,
policySetDefinitionCategory,
policySetDefinitionId,
policySetDefinitionName,
policySetDefinitionOwner,
policySetDefinitionParameters,
principalOid,
resourceGroup,
resourceId,
resourceLocation,
resourceTags,
resourceType,
subscriptionId,
tenantId,
timestamp
FROM azure.policy_insights.policy_events
WHERE subscription_id = '{{ subscription_id }}' -- required
AND resource_group_name = '{{ resource_group_name }}' -- required
AND policy_events_resource = '{{ policy_events_resource }}' -- required
AND $top = '{{ $top }}'
AND $orderby = '{{ $orderby }}'
AND $select = '{{ $select }}'
AND $from = '{{ $from }}'
AND $to = '{{ $to }}'
AND $filter = '{{ $filter }}'
AND $apply = '{{ $apply }}'
AND $skiptoken = '{{ $skiptoken }}'
;
Queries policy events for the subscription level policy set definition.
SELECT
@odata,
complianceState,
components,
effectiveParameters,
isCompliant,
managementGroupIds,
policyAssignmentId,
policyAssignmentName,
policyAssignmentOwner,
policyAssignmentParameters,
policyAssignmentScope,
policyDefinitionAction,
policyDefinitionCategory,
policyDefinitionId,
policyDefinitionName,
policyDefinitionReferenceId,
policySetDefinitionCategory,
policySetDefinitionId,
policySetDefinitionName,
policySetDefinitionOwner,
policySetDefinitionParameters,
principalOid,
resourceGroup,
resourceId,
resourceLocation,
resourceTags,
resourceType,
subscriptionId,
tenantId,
timestamp
FROM azure.policy_insights.policy_events
WHERE subscription_id = '{{ subscription_id }}' -- required
AND policy_events_resource = '{{ policy_events_resource }}' -- required
AND policy_set_definition_name = '{{ policy_set_definition_name }}' -- required
AND $top = '{{ $top }}'
AND $orderby = '{{ $orderby }}'
AND $select = '{{ $select }}'
AND $from = '{{ $from }}'
AND $to = '{{ $to }}'
AND $filter = '{{ $filter }}'
AND $apply = '{{ $apply }}'
AND $skiptoken = '{{ $skiptoken }}'
;
Queries policy events for the subscription level policy definition.
SELECT
@odata,
complianceState,
components,
effectiveParameters,
isCompliant,
managementGroupIds,
policyAssignmentId,
policyAssignmentName,
policyAssignmentOwner,
policyAssignmentParameters,
policyAssignmentScope,
policyDefinitionAction,
policyDefinitionCategory,
policyDefinitionId,
policyDefinitionName,
policyDefinitionReferenceId,
policySetDefinitionCategory,
policySetDefinitionId,
policySetDefinitionName,
policySetDefinitionOwner,
policySetDefinitionParameters,
principalOid,
resourceGroup,
resourceId,
resourceLocation,
resourceTags,
resourceType,
subscriptionId,
tenantId,
timestamp
FROM azure.policy_insights.policy_events
WHERE subscription_id = '{{ subscription_id }}' -- required
AND policy_events_resource = '{{ policy_events_resource }}' -- required
AND policy_definition_name = '{{ policy_definition_name }}' -- required
AND $top = '{{ $top }}'
AND $orderby = '{{ $orderby }}'
AND $select = '{{ $select }}'
AND $from = '{{ $from }}'
AND $to = '{{ $to }}'
AND $filter = '{{ $filter }}'
AND $apply = '{{ $apply }}'
AND $skiptoken = '{{ $skiptoken }}'
;
Queries policy events for the subscription level policy assignment.
SELECT
@odata,
complianceState,
components,
effectiveParameters,
isCompliant,
managementGroupIds,
policyAssignmentId,
policyAssignmentName,
policyAssignmentOwner,
policyAssignmentParameters,
policyAssignmentScope,
policyDefinitionAction,
policyDefinitionCategory,
policyDefinitionId,
policyDefinitionName,
policyDefinitionReferenceId,
policySetDefinitionCategory,
policySetDefinitionId,
policySetDefinitionName,
policySetDefinitionOwner,
policySetDefinitionParameters,
principalOid,
resourceGroup,
resourceId,
resourceLocation,
resourceTags,
resourceType,
subscriptionId,
tenantId,
timestamp
FROM azure.policy_insights.policy_events
WHERE subscription_id = '{{ subscription_id }}' -- required
AND policy_events_resource = '{{ policy_events_resource }}' -- required
AND policy_assignment_name = '{{ policy_assignment_name }}' -- required
AND $top = '{{ $top }}'
AND $orderby = '{{ $orderby }}'
AND $select = '{{ $select }}'
AND $from = '{{ $from }}'
AND $to = '{{ $to }}'
AND $filter = '{{ $filter }}'
AND $apply = '{{ $apply }}'
AND $skiptoken = '{{ $skiptoken }}'
;
Queries policy events for the resources under the management group.
SELECT
@odata,
complianceState,
components,
effectiveParameters,
isCompliant,
managementGroupIds,
policyAssignmentId,
policyAssignmentName,
policyAssignmentOwner,
policyAssignmentParameters,
policyAssignmentScope,
policyDefinitionAction,
policyDefinitionCategory,
policyDefinitionId,
policyDefinitionName,
policyDefinitionReferenceId,
policySetDefinitionCategory,
policySetDefinitionId,
policySetDefinitionName,
policySetDefinitionOwner,
policySetDefinitionParameters,
principalOid,
resourceGroup,
resourceId,
resourceLocation,
resourceTags,
resourceType,
subscriptionId,
tenantId,
timestamp
FROM azure.policy_insights.policy_events
WHERE policy_events_resource = '{{ policy_events_resource }}' -- required
AND management_group_name = '{{ management_group_name }}' -- required
AND $top = '{{ $top }}'
AND $orderby = '{{ $orderby }}'
AND $select = '{{ $select }}'
AND $from = '{{ $from }}'
AND $to = '{{ $to }}'
AND $filter = '{{ $filter }}'
AND $apply = '{{ $apply }}'
AND $skiptoken = '{{ $skiptoken }}'
;
Queries policy events for the resources under the subscription.
SELECT
@odata,
complianceState,
components,
effectiveParameters,
isCompliant,
managementGroupIds,
policyAssignmentId,
policyAssignmentName,
policyAssignmentOwner,
policyAssignmentParameters,
policyAssignmentScope,
policyDefinitionAction,
policyDefinitionCategory,
policyDefinitionId,
policyDefinitionName,
policyDefinitionReferenceId,
policySetDefinitionCategory,
policySetDefinitionId,
policySetDefinitionName,
policySetDefinitionOwner,
policySetDefinitionParameters,
principalOid,
resourceGroup,
resourceId,
resourceLocation,
resourceTags,
resourceType,
subscriptionId,
tenantId,
timestamp
FROM azure.policy_insights.policy_events
WHERE subscription_id = '{{ subscription_id }}' -- required
AND policy_events_resource = '{{ policy_events_resource }}' -- required
AND $top = '{{ $top }}'
AND $orderby = '{{ $orderby }}'
AND $select = '{{ $select }}'
AND $from = '{{ $from }}'
AND $to = '{{ $to }}'
AND $filter = '{{ $filter }}'
AND $apply = '{{ $apply }}'
AND $skiptoken = '{{ $skiptoken }}'
;
Queries policy events for the resource.
SELECT
@odata,
complianceState,
components,
effectiveParameters,
isCompliant,
managementGroupIds,
policyAssignmentId,
policyAssignmentName,
policyAssignmentOwner,
policyAssignmentParameters,
policyAssignmentScope,
policyDefinitionAction,
policyDefinitionCategory,
policyDefinitionId,
policyDefinitionName,
policyDefinitionReferenceId,
policySetDefinitionCategory,
policySetDefinitionId,
policySetDefinitionName,
policySetDefinitionOwner,
policySetDefinitionParameters,
principalOid,
resourceGroup,
resourceId,
resourceLocation,
resourceTags,
resourceType,
subscriptionId,
tenantId,
timestamp
FROM azure.policy_insights.policy_events
WHERE policy_events_resource = '{{ policy_events_resource }}' -- required
AND resource_id = '{{ resource_id }}' -- required
AND $top = '{{ $top }}'
AND $orderby = '{{ $orderby }}'
AND $select = '{{ $select }}'
AND $from = '{{ $from }}'
AND $to = '{{ $to }}'
AND $filter = '{{ $filter }}'
AND $apply = '{{ $apply }}'
AND $expand = '{{ $expand }}'
AND $skiptoken = '{{ $skiptoken }}'
;