Bird
Raised Fist0
Azurecloud~7 mins

Event Grid subscriptions and filters in Azure - Commands & Configuration

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Introduction
Event Grid subscriptions let you receive notifications when something happens in your cloud resources. Filters help you choose which events you want to get, so you only get the important ones.
When you want to get notified only about new files added to a storage container, not all changes.
When you want to trigger a function only if a virtual machine changes state to running.
When you want to send alerts only for error events from your app, ignoring info messages.
When you want to connect your app to events from multiple sources but only care about specific event types.
When you want to reduce the amount of data your app processes by filtering events early.
Config File - eventgrid-subscription.json
eventgrid-subscription.json
{
  "type": "Microsoft.EventGrid/eventSubscriptions",
  "apiVersion": "2023-06-01",
  "name": "myEventSubscription",
  "properties": {
    "destination": {
      "endpointType": "WebHook",
      "properties": {
        "endpointUrl": "https://myapp.example.com/api/events"
      }
    },
    "filter": {
      "subjectBeginsWith": "/blobServices/default/containers/images/",
      "subjectEndsWith": ".jpg",
      "isSubjectCaseSensitive": false,
      "includedEventTypes": [
        "Microsoft.Storage.BlobCreated"
      ]
    }
  }
}

This JSON creates an Event Grid subscription named myEventSubscription.

The destination is a webhook URL where events will be sent.

The filter section limits events to those where the subject starts with /blobServices/default/containers/images/ and ends with .jpg, meaning only new JPEG images in the images container.

It also only includes the event type Microsoft.Storage.BlobCreated, so only new blobs trigger the subscription.

The filter is case insensitive for the subject.

Commands
This command creates an Event Grid subscription named myEventSubscription. It listens to blob created events from the storage account mystorageaccount. It filters events to only those starting with the images container path and ending with .jpg files. Events are sent to the specified webhook endpoint.
Terminal
az eventgrid event-subscription create --name myEventSubscription --source-resource-id /subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/myResourceGroup/providers/Microsoft.Storage/storageAccounts/mystorageaccount --endpoint https://myapp.example.com/api/events --included-event-types Microsoft.Storage.BlobCreated --subject-begins-with /blobServices/default/containers/images/ --subject-ends-with .jpg
Expected OutputExpected
{ "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/myResourceGroup/providers/Microsoft.Storage/storageAccounts/mystorageaccount/providers/Microsoft.EventGrid/eventSubscriptions/myEventSubscription", "name": "myEventSubscription", "type": "Microsoft.EventGrid/eventSubscriptions", "destination": { "endpointType": "WebHook", "properties": { "endpointUrl": "https://myapp.example.com/api/events" } }, "filter": { "includedEventTypes": [ "Microsoft.Storage.BlobCreated" ], "subjectBeginsWith": "/blobServices/default/containers/images/", "subjectEndsWith": ".jpg", "isSubjectCaseSensitive": false }, "provisioningState": "Succeeded" }
→
--included-event-types - Specifies which event types to receive
→
--subject-begins-with - Filters events by subject prefix
→
--subject-ends-with - Filters events by subject suffix
This command shows the details of the event subscription named myEventSubscription to verify it was created with the correct filters and destination.
Terminal
az eventgrid event-subscription show --name myEventSubscription --source-resource-id /subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/myResourceGroup/providers/Microsoft.Storage/storageAccounts/mystorageaccount
Expected OutputExpected
{ "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/myResourceGroup/providers/Microsoft.Storage/storageAccounts/mystorageaccount/providers/Microsoft.EventGrid/eventSubscriptions/myEventSubscription", "name": "myEventSubscription", "type": "Microsoft.EventGrid/eventSubscriptions", "destination": { "endpointType": "WebHook", "properties": { "endpointUrl": "https://myapp.example.com/api/events" } }, "filter": { "includedEventTypes": [ "Microsoft.Storage.BlobCreated" ], "subjectBeginsWith": "/blobServices/default/containers/images/", "subjectEndsWith": ".jpg", "isSubjectCaseSensitive": false }, "provisioningState": "Succeeded" }
This command lists all event subscriptions on the storage account to see all active subscriptions and their filters.
Terminal
az eventgrid event-subscription list --source-resource-id /subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/myResourceGroup/providers/Microsoft.Storage/storageAccounts/mystorageaccount
Expected OutputExpected
[ { "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/myResourceGroup/providers/Microsoft.Storage/storageAccounts/mystorageaccount/providers/Microsoft.EventGrid/eventSubscriptions/myEventSubscription", "name": "myEventSubscription", "destination": { "endpointType": "WebHook", "properties": { "endpointUrl": "https://myapp.example.com/api/events" } }, "filter": { "includedEventTypes": [ "Microsoft.Storage.BlobCreated" ], "subjectBeginsWith": "/blobServices/default/containers/images/", "subjectEndsWith": ".jpg", "isSubjectCaseSensitive": false }, "provisioningState": "Succeeded" } ]
This command deletes the event subscription named myEventSubscription when it is no longer needed to stop receiving events.
Terminal
az eventgrid event-subscription delete --name myEventSubscription --source-resource-id /subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/myResourceGroup/providers/Microsoft.Storage/storageAccounts/mystorageaccount
Expected OutputExpected
No output (command runs silently)
Key Concept

If you remember nothing else from this pattern, remember: filters let you receive only the events you care about, saving time and resources.

Common Mistakes
Not specifying included event types when creating the subscription
You might receive all event types, causing unnecessary processing and noise.
Always use the --included-event-types flag to limit events to only those you want.
Using incorrect subject filters that do not match event subjects
No events will be delivered because the filter excludes all events.
Check the exact event subject format and use correct prefixes and suffixes in filters.
Not verifying the subscription after creation
You might miss misconfigurations that prevent events from arriving.
Use the show or list commands to confirm the subscription settings.
Summary
Create an Event Grid subscription with filters to receive only specific event types and subjects.
Verify the subscription details to ensure filters and destination are correct.
Delete the subscription when it is no longer needed to stop event delivery.

Practice

(1/5)
1. What is the main purpose of using filters in Azure Event Grid subscriptions?
easy
A. To receive only specific events based on criteria like event type or subject
B. To increase the number of events sent to subscribers
C. To block all events from being delivered
D. To change the event data before delivery

Solution

  1. Step 1: Understand Event Grid subscriptions

    Subscriptions let you receive events from Azure services.
  2. Step 2: Role of filters in subscriptions

    Filters help select only the events you want, based on event type or subject.
  3. Final Answer:

    To receive only specific events based on criteria like event type or subject -> Option A
  4. Quick Check:

    Filters select events = B [OK]
Hint: Filters pick events you want, ignoring others [OK]
Common Mistakes:
  • Thinking filters increase event volume
  • Believing filters block all events
  • Assuming filters modify event data
2. Which of the following is the correct JSON snippet to filter events by subject prefix in an Event Grid subscription?
easy
A. "filter": { "subjectBeginsWith": "/blobServices/default/containers/images" }
B. "filter": { "subjectEndsWith": "/blobServices/default/containers/images" }
C. "filter": { "eventType": "Microsoft.Storage.BlobCreated" }
D. "filter": { "subjectContains": "images" }

Solution

  1. Step 1: Identify subject prefix filter syntax

    The correct property to filter by subject prefix is "subjectBeginsWith".
  2. Step 2: Match the correct JSON snippet

    "filter": { "subjectBeginsWith": "/blobServices/default/containers/images" } uses "subjectBeginsWith" with the correct path prefix.
  3. Final Answer:

    "filter": { "subjectBeginsWith": "/blobServices/default/containers/images" } -> Option A
  4. Quick Check:

    Prefix filter uses subjectBeginsWith = A [OK]
Hint: Prefix filters use subjectBeginsWith property [OK]
Common Mistakes:
  • Confusing subjectEndsWith with subjectBeginsWith
  • Using eventType instead of subject filter
  • Using subjectContains which is not valid
3. Given this Event Grid subscription filter configuration:
{ "subjectBeginsWith": "/devices/", "subjectEndsWith": "/temperature" }

Which event subject will be delivered to the subscriber?
medium
A. /sensors/device123/temperature
B. /devices/device123/humidity
C. /devices/device123/temperature
D. /devices/temperature/device123

Solution

  1. Step 1: Understand filter conditions

    The event subject must start with "/devices/" and end with "/temperature".
  2. Step 2: Check each option

    /devices/device123/temperature matches both start and end. Others fail one condition.
  3. Final Answer:

    /devices/device123/temperature -> Option C
  4. Quick Check:

    Subject starts with /devices/ and ends with /temperature = A [OK]
Hint: Match both start and end strings exactly [OK]
Common Mistakes:
  • Ignoring subjectEndsWith condition
  • Confusing similar paths
  • Assuming partial matches are enough
4. You wrote this filter in your Event Grid subscription:
{ "subjectBeginsWith": "/orders/", "subjectEndsWith": "/completed" }

But no events are received even though events exist. What is the likely issue?
medium
A. The subscription is disabled
B. The filter syntax is invalid JSON
C. Event Grid does not support subject filters
D. The subject filter is case-sensitive and event subjects differ in case

Solution

  1. Step 1: Check filter syntax and support

    The JSON syntax is valid and Event Grid supports subject filters.
  2. Step 2: Consider case sensitivity and subscription status

    Subject filters are case-sensitive; if event subjects differ in case, no match occurs. Subscription being disabled would stop all events, but question implies filter issue.
  3. Final Answer:

    The subject filter is case-sensitive and event subjects differ in case -> Option D
  4. Quick Check:

    Subject filters are case-sensitive = D [OK]
Hint: Remember filters are case-sensitive in Event Grid [OK]
Common Mistakes:
  • Assuming filters ignore case
  • Blaming JSON syntax without checking
  • Ignoring subscription status
5. You want to create an Event Grid subscription that only receives events of type Microsoft.Storage.BlobCreated where the blob is in the container named images. Which filter configuration achieves this?
hard
A. { "eventType": "Microsoft.Storage.BlobDeleted", "subjectBeginsWith": "/blobServices/default/containers/images/" }
B. { "eventType": "Microsoft.Storage.BlobCreated", "subjectBeginsWith": "/blobServices/default/containers/images/" }
C. { "eventType": "Microsoft.Storage.BlobCreated", "subjectEndsWith": "/images" }
D. { "eventType": "Microsoft.Storage.BlobCreated" }

Solution

  1. Step 1: Filter by event type

    The event type must be exactly "Microsoft.Storage.BlobCreated" to get blob creation events.
  2. Step 2: Filter by subject prefix for container

    The subject prefix for blobs in the "images" container is "/blobServices/default/containers/images/".
  3. Step 3: Combine filters correctly

    { "eventType": "Microsoft.Storage.BlobCreated", "subjectBeginsWith": "/blobServices/default/containers/images/" } combines both eventType and subjectBeginsWith correctly.
  4. Final Answer:

    { "eventType": "Microsoft.Storage.BlobCreated", "subjectBeginsWith": "/blobServices/default/containers/images/" } -> Option B
  5. Quick Check:

    Event type and subject prefix filter combined = C [OK]
Hint: Combine eventType and subjectBeginsWith for precise filtering [OK]
Common Mistakes:
  • Using wrong event type
  • Using subjectEndsWith instead of subjectBeginsWith
  • Omitting container path in subject filter