Use this reference
Use this file when you need a fast path through Azure SRE Agent audit telemetry in Application Insights customEvents.
Event types verified from Microsoft Learn on 2026-06-05:
AgentToolExecutionModelGenerationApprovalDecisionIncidentActivitySnapshot
Also use shared correlation fields such as TraceId, SpanId, ParentSpanId, ThreadId, and CorrelationId.
Start here at 2am
- Open the agent's Application Insights resource from Monitor > Logs.
- Switch the default query from
tracestocustomEvents. - Start with the thread timeline query below.
- Pivot to tool usage, approval history, incident outcomes, or token usage as needed.
Thread timeline
customEvents
| where timestamp > ago(7d)
| where tostring(customDimensions.ThreadId) == "<THREAD_ID>"
| project timestamp,
Event = name,
EventType = tostring(customDimensions.EventType),
Tool = tostring(customDimensions.ToolName),
Agent = tostring(customDimensions.SubAgentName),
TraceId = tostring(customDimensions.TraceId)
| sort by timestamp ascTool execution history
customEvents
| where name == "AgentToolExecution"
| where timestamp > ago(24h)
| project timestamp,
Tool = tostring(customDimensions.ToolName),
EventType = tostring(customDimensions.EventType),
Input = tostring(customDimensions.ToolInput),
Output = tostring(customDimensions.ToolOutput),
CallId = tostring(customDimensions.CallId),
Agent = tostring(customDimensions.SubAgentName)
| sort by timestamp descApproval decisions
customEvents
| where name == "ApprovalDecision"
| where timestamp > ago(30d)
| project timestamp, customDimensions
| sort by timestamp descIncident outcomes
customEvents
| where name == "IncidentActivitySnapshot"
| where timestamp > ago(30d)
| project timestamp,
IncidentId = tostring(customDimensions.IncidentId),
Title = tostring(customDimensions.IncidentTitle),
Platform = tostring(customDimensions.IncidentPlatform),
MitigatedByAgent = tostring(customDimensions.IncidentMitigatedByAgent),
AssistedByAgent = tostring(customDimensions.IncidentAssistedByAgent),
Autonomy = tostring(customDimensions.AgentAutonomyLevel),
ResponsePlan = tostring(customDimensions.ResponsePlanId)
| sort by timestamp descToken and AAU proxy trend
Use ModelGeneration events as the local signal for token cost. Azure billing remains the source of truth for actual AAU charges.
customEvents
| where name == "ModelGeneration"
| where customDimensions.EventType == "ModelGenerationEnd"
| where timestamp > ago(30d)
| extend Agent = tostring(customDimensions.AgentName),
Model = tostring(customDimensions.ModelId),
InputTokens = toint(customDimensions.InputTokens),
OutputTokens = toint(customDimensions.OutputTokens)
| summarize TotalInput = sum(InputTokens), TotalOutput = sum(OutputTokens), Calls = count() by Agent, Model
| sort by TotalInput descWhat to check before autonomy promotion
- repeated approval decisions for the same action pattern
- tool failures or repeated retries in
AgentToolExecution - high token use with low incident mitigation value
- false positives or noisy response plans in
IncidentActivitySnapshot
Source
Primary source: references/source-map.md → Microsoft Learn audit-agent-actions