Skip to main content

Change Monitoring: Azure Activity Review

Overview

Change Monitoring in Spotto is an Azure activity review page for answering "what changed, who changed it, and did it line up with the incident?" It combines material changes, sensitive actions, failed events, and resource health signals across selected subscriptions so you can troubleshoot environment issues without starting from raw activity logs.

Use it when something broke, slowed down, became exposed, stopped updating, or started behaving strangely. The fastest first question is usually not "what is the root cause?" It is "what changed recently?"

Feature overview

Change Monitoring summarizes Azure activity logs into a focused investigation view:

  • Material Changes: important configuration, resource, or operation changes.
  • Sensitive Actions: credential, RBAC, networking, firewall, policy, and similar security-sensitive events.
  • Health Events: Azure resource health changes that help correlate outages or degraded service.
  • Failed Events: failed operations that may explain incomplete work or instability.
  • Actor context: users, service principals, managed identities, Azure platform events, and unknown actors.
  • Resource context: affected resource, resource group, resource type, subscription, operation, status, and event count.

Questions Change Monitoring answers

Use Change Monitoring when you need quick answers to operational and security investigation questions:

  • What changed in this Azure environment recently?
  • Who made the change: a user, service principal, managed identity, Azure platform event, or unknown actor?
  • Which sensitive actions occurred, such as credential, RBAC, networking, firewall, or policy activity?
  • Which operations failed and may explain incomplete updates or unstable services?
  • Which resources, resource groups, and subscriptions were affected?
  • Did a resource health event happen near the same time as the issue?
  • Were noisy activity log events suppressed so the review stays focused?

This makes the page useful for Azure change monitoring, cloud troubleshooting, incident correlation, audit review, and "please tell me this was not a mystery change" conversations.

Why use this? (Jobs, pains, gains)

Jobs to be done

  • When an incident starts, I want to see recent material changes, so I can quickly confirm whether a deployment, configuration change, or platform event lines up with the issue.
  • When access or exposure looks wrong, I want to find sensitive actions, so I can review credential, RBAC, firewall, networking, and policy changes first.
  • When a patch or update did not run cleanly, I want to find failed operations, so I can separate "planned work completed" from "planned work tried and failed".
  • When I need accountability, I want to see the actor and actor type, so follow-up goes to the right user, automation owner, or platform team.

Common pains

  • Azure activity logs are comprehensive, which is another way of saying "there is a lot of noise."
  • The useful question is rarely "show me every event." It is "show me the events that matter for this problem."
  • Security-sensitive changes are often mixed in with routine operations.
  • Failed updates, health events, and user changes are easy to review separately and harder to correlate quickly.

What you gain

  • A focused activity feed across selected subscriptions.
  • Clear separation between Change, Security, and Health event types.
  • Importance labels (High, Medium, Low) with text labels, not just color.
  • Actor filters for Users, Automation, Azure Platform, and Unknown.
  • Breakdowns by actor, operation, and resource group for fast pattern recognition.
  • CSV export for incident notes, change review, and audit follow-up.

Turn the evidence into a decision

Select the labelled briefcase Business Value button beside Notes. The brief combines live material, security-sensitive, failed-change, and actor facts with an owned response decision.

Live activity evidence is not replaced by AI and caller identity is not inferred when Azure did not provide it. Generate tailors only the narrative and saves it for the exact scope. Clear removes that saved narrative and immediately restores the standard Business Value content without deleting Customer Context or changing live facts. Regenerate when evidence changes. Above 100 subscriptions, the curated live brief remains available without tailoring.

Current position and priority work

Investigate failed, security-sensitive, or disruptive changes affecting important services first. Group recurring patterns into rollback, automation, approval-control, or accepted-risk actions with clear owners.

Business outcomes

Change monitoring creates operational accountability by connecting material activity to actors, resources, and timing. It can reduce investigation time while showing where controls or automation need improvement without slowing normal delivery.

Cost of delay

Unauthorized or unintended changes may persist longer and become harder to reconstruct during an incident. Recurring failed or disruptive changes can continue when intent, root cause, and ownership remain unclear.

Decision required

Agree which changes require immediate response, which control improvement will prevent recurrence, and who owns the follow-up.

Validate with stakeholders

When you can manage Company Notes, select any question in the portal to retain the answer in the relevant Customer Context note.

  • Was the change authorized, expected, and linked to a change record?
  • Did it affect a critical service, security boundary, or compliance control?
  • Should the response be rollback, investigation, control improvement, or acceptance?

Key capabilities

Where to find it

In the Spotto Portal sidebar, open Investigate -> Review -> Change Monitoring.

Use the company and subscription selector at the top of the page to choose the Azure subscriptions you want to investigate. Change Monitoring combines the selected subscriptions into one activity feed.

Review the summary cards

The summary cards show:

  • Material Changes: activity rows Spotto classified as material changes.
  • Sensitive Actions: security-sensitive events and how many failed events are present.
  • Health Events: Azure resource health events, including the latest event age.
  • Human Actors: distinct user actors, plus noisy events suppressed from the focused feed.

These cards help you decide whether the review is mostly about a change, a security-sensitive action, a health event, or actor follow-up.

Use insight cards for investigation leads

Change Monitoring generates insight cards from the selected activity:

  • Failed change activity found: failed events may explain recent instability or incomplete work.
  • Sensitive actions need review: credential, RBAC, networking, firewall, policy, or similar sensitive events were surfaced.
  • User-driven activity is visible: human actors appear in the selected feed.
  • Resource health changed: health events are available for incident correlation.
  • No notable change activity: no material change, security, or health events were found in the selected feed.

Understand event types and importance

FieldValuesWhat it means
TypeChange, Security, Health, OperationThe activity feed the event belongs to. The main filters expose Change, Security, and Health.
ImportanceHigh, Medium, LowA triage label for which rows deserve attention first. The UI shows text labels in addition to color.
Actor typeUser, Service Principal, Managed Identity, Azure Platform, UnknownWho or what initiated the activity, based on the best actor information available.
StatusExamples include Succeeded, Failed, ResolvedWhether the operation completed, failed, or represents a resolved health event.
note

Change Monitoring is evidence for investigation, not a final incident verdict. A sensitive action can be expected, and a quiet feed does not prove nothing happened outside the available data.

Inspect the activity feed

The Activity Feed table includes:

  • When: relative event time. Grouped rows show the grouped event count.
  • Type: event type plus importance.
  • Change: operation name and operation subtype.
  • Actor: actor display name and actor type.
  • Resource: affected resource, resource group, and resource type.
  • Status: operation status and subscription.

Use this table to answer practical troubleshooting questions:

  • Did a user or automation change the resource before the issue started?
  • Did a failed patch, update, deployment, or action line up with the incident?
  • Did a resource health event occur during the same window?
  • Did a sensitive action affect credentials, access control, network paths, firewall rules, or policy?
  • Is the activity concentrated in one actor, operation, or resource group?

Use filters to narrow the feed:

  • Search by actor, operation, resource, resource group, resource type, subscription, status, category, kind, or importance.
  • Filter by feed: All Feeds, Change, Security, or Health.
  • Filter by importance: All Importance, High, Medium, or Low.
  • Filter by actor type: All Actors, Users, Automation, Azure Platform, or Unknown.

The filtered row count updates above the table, so you can see whether the investigation scope is narrowing as expected.

Review breakdowns

Breakdown cards show the top activity groups:

  • By Actor: which users, identities, or platform actors appear most often.
  • By Operation: which operations are driving the feed.
  • By Resource Group: where activity is concentrated.

These are useful when you need a quick lead before reading every row.

Export the current activity feed

Use Export CSV to download the currently filtered rows. The export includes timestamp, kind, importance, operation, actor, status, subscription, resource, resource group, resource type, and event count.

The export filename uses change_monitoring_YYYY-MM-DD.csv.

1. Scope the affected subscriptions

Select the subscriptions tied to the incident or service you are investigating. Keep the scope tight at first; broad searches are useful later, but incident triage starts with the smallest plausible blast radius.

2. Check High importance activity

Filter importance to High. Review failed operations and sensitive actions first, especially if the issue involves access, networking, firewall behavior, credentials, policy, or system updates.

3. Compare activity timing with the incident

Use the When column to compare event timing with alert timestamps, deployment windows, customer reports, or monitoring signals. Close timing is not proof, but it is a good reason to keep looking.

4. Review actor patterns

Use By Actor and the actor type filter to distinguish user activity from automation and Azure platform events. A failed service principal action points to a different follow-up path than a user-driven portal change.

5. Check Health events

Filter feed to Health when the issue looks like platform instability, VM availability, service degradation, or a resource health transition.

6. Export evidence for follow-up

Export the filtered feed once you have a useful view. Attach it to incident notes, change records, security review, or remediation tickets.

Technical reference

ComponentDetails
InputsAzure activity log reports for each selected subscription, including material changes, security-sensitive events, resource health events, suppressed noisy event summaries, actor details, resource context, operation names, status, and event counts.
OutputsSummary cards, insight cards, actor/operation/resource-group breakdowns, a searchable and filterable activity feed, and CSV export.
DefaultsData is fetched per selected subscription. The table page size is 25 rows. Filters default to All Feeds, All Importance, and All Actors.

How it differs from Azure-native activity logs

Azure activity logs are the source of truth, but they are designed as a broad event stream. Change Monitoring is designed for the operational question: "what should I look at first while troubleshooting?"

Spotto focuses the activity review by:

  • Grouping activity into Change, Security, and Health feeds.
  • Surfacing material and security-sensitive events ahead of routine noise.
  • Showing actor, operation, resource, and status context in one table.
  • Suppressing noisy events while still showing how much noise was suppressed.
  • Letting you filter and export the incident-relevant slice.

How it works (high level)

  • You select one or more Azure subscriptions.
  • Spotto loads activity log reports for each selected subscription.
  • The Portal combines changes, security events, and health events into one sorted feed.
  • Rows may represent single events or grouped events, with grouped event(s) shown in the When column.
  • The model calculates summary counts, top breakdowns, insights, and filterable rows from the selected data.

Coverage and limitations

  • Not a full SIEM: Change Monitoring helps with troubleshooting and review, but it is not a replacement for a dedicated SIEM, EDR, or forensic logging platform.
  • Not real-time: The page updates after Spotto receives activity log data. It should be treated as investigation support, not live alerting.
  • Sensitive action does not always mean breach: Sensitive actions need review because they can affect security posture, not because they automatically indicate compromise.
  • Unknown actors can happen: Some events may not resolve cleanly to a user, service principal, or managed identity.
  • Suppressed events are intentionally hidden from the main feed: Suppression reduces noise, but the summary still shows how many noisy events were suppressed.
  • Azure only today: Change Monitoring currently covers Azure activity log data.
  • Use Perimeter Insights to check whether recent network or public IP changes affected internet exposure.
  • Use Security to review secure score and security recommendations after sensitive actions.
  • Use Cloud Resources to inspect affected resources and related recommendations.
  • Use Relationship Graph to understand resource relationships and blast radius after a change.
  • Use Tickets to track follow-up work created from investigation findings.

Troubleshooting

No change monitoring data found

What you're seeing: The page shows No change monitoring data found. Likely causes:

  • No subscriptions are selected.
  • The selected subscriptions do not currently have activity log data available.
  • The subscriptions have not completed their first sync.

How to fix:

  1. Select at least one subscription.
  2. Confirm the subscriptions are connected and syncing in Spotto.
  3. Refresh after the next ingestion cycle.

No activity matches these filters

What you're seeing: The table shows No activity matches these filters. Likely causes:

  • The search term is too specific.
  • The feed, importance, or actor filter excludes the rows you expected.

How to fix:

  1. Clear the search box.
  2. Reset feed to All Feeds.
  3. Reset importance to All Importance.
  4. Reset actor to All Actors.

Activity log data could not be loaded

What you're seeing: The page shows Activity log data could not be loaded. Likely causes:

  • Temporary API or network issue.
  • The selected company or subscriptions are not available in your current session.

How to fix:

  1. Refresh the page.
  2. Re-select the subscriptions.
  3. If it continues, capture the time, company, and subscription IDs and contact support.

Some subscriptions unavailable

What you're seeing: A notification says Some subscriptions unavailable and lists subscription names. Likely causes:

  • Spotto loaded activity data for some selected subscriptions but failed to load others.
  • One or more subscriptions are temporarily unavailable or still syncing.

How to fix:

  1. Review the rows that did load.
  2. Retry after the unavailable subscriptions finish syncing.
  3. If the same subscriptions fail repeatedly, contact support with the listed subscription names.

I expected to see every Azure activity log event

What you're seeing: The summary mentions suppressed noisy events, but those rows do not appear in the main feed. Likely cause: Change Monitoring suppresses routine or noisy events so the main feed stays useful for troubleshooting. How to fix: Use the suppressed event count as a noise indicator, then use Azure-native activity logs if you need every raw event for audit or forensic review.

Optimize Your Azure Environment

Looking to enhance your cloud setup for cost efficiency, performance, reliability, or security?

Talk to a cloud specialist. Email us or schedule a 30-minute consultation and let's optimize your cloud environment together.

Book a Free Consultation