Microsoft.EventHub/namespaces/eventhubs/delete
Microsoft.EventHub/namespaces/eventhubs/delete
Event
Deletes the specified hub, not the entire namespace. Producers and consumers using that hub may lose their route or data access. Previously captured or exported data in other storage is separate, and deleting an export destination does not erase the source Activity Log.
Security Context
Malicious deletion can cause data loss (T1485) or impair a confirmed security-log route (T1685.002). A hub name alone does not prove SIEM impact. Approved retirement and migration use the same operation.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.EventHub/namespaces/eventhubs/delete. Inspect status/subStatus and related records; asynchronous acceptance is not final resource-state evidence. Request bodies are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
caller, claims, authorization | Initiating identity and recorded authorization context; corroborate effective permissions. |
resourceId, correlationId | Target and related operation records. |
status, subStatus | Outcome and asynchronous acceptance versus completion. |
properties.requestbody, httpRequest | Configuration or command and endpoint when present; these fields are not guaranteed. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Recover the hub’s producer, consumer, capture, and diagnostic-routing configuration.
- Confirm final deletion and actual producer/consumer failures, alternative destinations, and retained archives.
- Measure the affected time window and data loss before claiming that all security monitoring stopped.
Sample Event
Synthetic scenario. The sample deletes eh-occamy-activitylog. Its name suggests a purpose but no route configuration or downstream outage is included.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.EventHub/namespaces/eventhubs/delete", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.EventHub/namespaces/evhns-occamy-prod/eventhubs/eh-occamy-activitylog" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "aud": "https://management.core.windows.net/", "iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/", "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud" }, "correlationId": "90000000-0000-4000-8000-000011010000", "description": "", "eventDataId": "90000000-0000-4000-8000-000011010001", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T23:08:42.5172938Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000011010010", "operationName": { "value": "Microsoft.EventHub/namespaces/eventhubs/delete", "localizedValue": "Delete Event Hub" }, "resourceGroupName": "rg-occamy-pipeline", "resourceProviderName": { "value": "Microsoft.EventHub", "localizedValue": "Microsoft.EventHub" }, "resourceType": { "value": "Microsoft.EventHub/namespaces/eventhubs", "localizedValue": "Microsoft.EventHub/namespaces/eventhubs" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.EventHub/namespaces/evhns-occamy-prod/eventhubs/eh-occamy-activitylog", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "OK", "localizedValue": "OK (HTTP Status Code: 200)" }, "submissionTimestamp": "2026-04-15T23:08:43.0218732Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "OK", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.EventHub/namespaces/evhns-occamy-prod/eventhubs/eh-occamy-activitylog", "message": "Microsoft.EventHub/namespaces/eventhubs/delete", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001" }, "relatedEvents": [], "httpRequest": { "clientRequestId": "90000000-0000-4000-8000-000011010011", "clientIpAddress": "203.0.113.66", "method": "DELETE", "url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.EventHub/namespaces/evhns-occamy-prod/eventhubs/eh-occamy-activitylog?api-version=2024-01-01" }, "identity": null}Sources
MITRE ATT&CK Mapping
Tactics: Impact Defense Impairment
- T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
- T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...