How to track Public IP attach/detach events across all Azure resources in last 24 hours?

RaajaSree Andar Pillai 20 Reputation points
2026-05-26T08:03:43.5933333+00:00

Hello,

I’m trying to track public (external) IP address changes in Azure—specifically whether a public IP was attached or detached from any resource within the last 24 hours.

Currently, I’m using activity log operations like:

  • Microsoft.Network/networkInterfaces/write → for VM NIC-level IP changes
  • Microsoft.Network/loadBalancers/write → for load balancer-related IP updates

However, this approach requires checking multiple resource-specific operations (NIC, Load Balancer, etc.), and it only gives partial insights depending on the resource type.

Challenge: There doesn’t seem to be a single, unified operation or API that provides a consolidated view of all public IP attach/detach events across all resource types.

What I’m looking for:

Is there any way to:

  • Fetch all public IP-related operations (attach/detach) across all Azure resources
  • Retrieve this data in a single query/API call
  • Filter results for the last 24 hours

Goal:

To centrally track all public IP association/disassociation events without needing to query each resource provider individually.

Any guidance or recommended approach would be appreciated!

Azure Virtual Network
Azure Virtual Network

An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.

0 comments No comments

Answer accepted by question author
Sina Salam 31,456 Reputation points Volunteer Moderator
2026-05-26T14:51:05.1833333+00:00

Hello RaajaSree Andar Pillai,

Welcome to the Microsoft Q&A and thank you for posting your questions here.

I understand that you would like to know how you can track Public IP attach/detach events across all Azure resources in last 24 hours.

My best practice advice to you:

  • Do not query NIC/LB/other resource-provider writes individually.
  • Do not rely on Public IP diagnostics.
  • Query resourcechanges for microsoft.network/publicipaddresses and evaluate property diffs on properties.ipConfiguration.id and properties.natGateway.id for the last 24 hours.

For cross-resource resources for Public IP attach/detach detection in Azure use the link below to read more and get some steps: https://learn.microsoft.com/en-us/azure/governance/resource-graph/changes/get-resource-changes, https://learn.microsoft.com/en-us/azure/virtual-network/ip-services/public-ip-addresses, https://github.com/Azure/Azure-Network-Security/blob/master/Cross%20Product/NetworkSecurity%20-%20%20Queries/Mapping%20Public%20IPs%20to%20Azure%20Assets/README.md

I hope this is helpful! Do not hesitate to let me know if you have any other questions, steps or clarifications.


Please don't forget to close up the thread here by upvoting and accept it as an answer if it is helpful.

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments

2 additional answers

Sort by: Oldest
  1. Thanmayi Godithi 11,905 Reputation points Microsoft External Staff Moderator
    2026-05-26T09:14:32.87+00:00

    Hi RaajaSree Andar Pillai ,

    You’re on the right track, and your observation about needing to query multiple operations is expected behavior in Azure.

    While there isn’t a single native event for public IP attach/detach, you can approximate a centralized view by routing Activity Logs to Log Analytics and querying them in one place.

    1. Enable Activity Log collection
    • Go to Monitor → Activity Log → Export Activity Logs (Diagnostic settings)
    • Create a diagnostic setting and send logs to a Log Analytics workspace
    1. Run a KQL query in Log Analytics

    Once logs are available in the AzureActivity table, you can query network-related write operations and look for indicators of public IP changes. For example:

    AzureActivity
    | where TimeGenerated >= ago(24h)
    | where ResourceProvider == "MICROSOFT.NETWORK"
    | where Category == "Administrative"
    | where OperationNameValue endswith "/write"
    | where tostring(Properties) contains "publicIPAddress"
    | project TimeGenerated, OperationNameValue, ResourceId, Caller, Properties
    | sort by TimeGenerated desc
    
    • This query filters the last 24 hours of network-related update operations.
    • The Properties filter helps narrow down events that may involve public IP associations.
    • Since association is part of resource updates (NIC, Load Balancer, etc.), this is a best-effort approach, not an exact event match.

    Refer: https://learn.microsoft.com/en-in/azure/virtual-network/ip-services/monitor-public-ip
    Azure Activity Logs record resource-level changes, not explicit “attach/detach” actions. So:

    • There is no single operation or API that directly returns all public IP association events
    • Any solution (including the above) relies on correlating multiple write operations

    Kindly let us know if the above helps or you need further assistance on this issue.

    If the answer is helpful, please "Accept the answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Was this answer helpful?

    1 person found this answer helpful.

  2. Salamat Shah 750 Reputation points MVP
    2026-05-26T13:23:04.68+00:00

    You can’t avoid multi-resource operations, but by centralizing Activity Logs + using a single KQL query, you get a near unified view of all public IP attach/detach events in one place.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.