
Summary
The Azure Storage Blob Uploaded detection rule is designed to monitor and track successful uploads of blobs to Azure Storage accounts. This rule falls under the Azure Monitor Activity log category, with a focus on operations involving the creation or writing of blobs within a storage account. The rule captures important contextual information such as the caller's IP address, the resource ID of the storage account, and the operation details, including the operation status, object key, and the TLS version used. It supports checking for different variations of the upload operation, including case-insensitive requests, ensuring it can accurately detect successful blob uploads while ignoring non-upload operations like deletions. The rule is currently enabled, but it does not create alerts upon triggering, as it is categorized under 'Info' severity to inform administrators without alarming them.
Categories
- Cloud
- Azure
- Infrastructure
- Database
Data Sources
- Cloud Service
- Logon Session
- Application Log
Created: 2026-01-14