Log Analytics workspace overview - Azure Monitor (2024)

  • Article

A Log Analytics workspace is a data store into which you can collect any type of log data from all of your Azure and non-Azure resources and applications. Workspace configuration options let you manage all of your log data in one workspace to meet the operations, analysis, and auditing needs of different personas in your organization through:

  • Azure Monitor features, such as built-in insights experiences, alerts, and automatic actions
  • Other Azure services, such as Microsoft Sentinel, Microsoft Defender for Cloud, and Logic Apps
  • Microsoft tools, such as Power BI and Excel
  • Integration with custom and third-party applications

This article provides an overview of concepts related to Log Analytics workspaces.

Important

Microsoft Sentinel documentation uses the term Microsoft Sentinel workspace. This workspace is the same Log Analytics workspace described in this article, but it's enabled for Microsoft Sentinel. All data in the workspace is subject to Microsoft Sentinel pricing.

Log tables

Each Log Analytics workspace contains multiple tables in which Azure Monitor Logs stores data you collect.

Azure Monitor Logs automatically creates tables required to store monitoring data you collect from your Azure environment. You create custom tables to store data you collect from non-Azure resources and applications, based on the data model of the log data you collect and how you want to store and use the data.

Table management settings let you control access to specific tables, and manage the data model, retention, and cost of data in each table. For more information, see Manage tables in a Log Analytics workspace.

Data retention

A Log Analytics workspace retains data in two states - interactive retention and long-term retention.

During the interactive retention period, you retrieve the data from the table through queries, and the data is available for visualizations, alerts, and other features and services, based on the table plan.

Each table in your Log Analytics workspace lets you retain data up to 12 years in low-cost, long-term retention. Retrieve specific data you need from long-term retention to interactive retention using a search job. This means that you manage your log data in one place, without moving data to external storage, and you get the full analytics capabilities of Azure Monitor on older data, when you need it.

For more information, see Manage data retention in a Log Analytics workspace.

Data access

Permission to access data in a Log Analytics workspace is defined by the access control mode setting on each workspace. You can give users explicit access to the workspace by using a built-in or custom role. Or, you can allow access to data collected for Azure resources to users with access to those resources.

For more information, see Manage access to log data and workspaces in Azure Monitor.

View Log Analytics workspace insights

Log Analytics Workspace Insights helps you manage and optimize your Log Analytics workspaces with a comprehensive view of your workspace usage, performance, health, ingestion, queries, and change log.

Transform data you ingest into your Log Analytics workspace

Data collection rules (DCRs) that define data coming into Azure Monitor can include transformations that allow you to filter and transform data before it's ingested into the workspace. Since all data sources don't yet support DCRs, each workspace can have a workspace transformation DCR.

Transformations in the workspace transformation DCR are defined for each table in a workspace and apply to all data sent to that table, even if sent from multiple sources. These transformations only apply to workflows that don't already use a DCR. For example, Azure Monitor agent uses a DCR to define data collected from virtual machines. This data won't be subject to any ingestion-time transformations defined in the workspace.

For example, you might have diagnostic settings that send resource logs for different Azure resources to your workspace. You can create a transformation for the table that collects the resource logs that filters this data for only records that you want. This method saves you the ingestion cost for records you don't need. You might also want to extract important data from certain columns and store it in other columns in the workspace to support simpler queries.

Cost

There's no direct cost for creating or maintaining a workspace. You're charged for the data you ingest into the workspace and for data retention, based on each table's table plan.

For information on pricing, see Azure Monitor pricing. For guidance on how to reduce your costs, see Azure Monitor best practices - Cost management. If you're using your Log Analytics workspace with services other than Azure Monitor, see the documentation for those services for pricing information.

Design a Log Analytics workspace architecture to address specific business needs

You can use a single workspace for all your data collection. However, you can also create multiple workspaces based on specific business requirements such as regulatory or compliance requirements to store data in specific locations, split billing, and resilience.

For considerations related to creating multiple workspaces, see Design a Log Analytics workspace configuration.

Next steps

  • Create a new Log Analytics workspace.
  • See Design a Log Analytics workspace configuration for considerations on creating multiple workspaces.
  • Learn about log queries to retrieve and analyze data from a Log Analytics workspace.
Log Analytics workspace overview - Azure Monitor (2024)

FAQs

Does Azure Monitor use Log Analytics Workspace? ›

Each Log Analytics workspace contains multiple tables in which Azure Monitor Logs stores data you collect.

How do I view logs in Azure Log Analytics workspace? ›

Go to the Log Analytics dashboard by clicking on the Dashboard button in the top menu. On the dashboard page, click on the Logs tab in the left menu. In the search box at the top of the page, enter your query using the Log Analytics query language. Press the Enter key or click the Run button to execute the query.

What is the difference between Azure monitor metrics and Azure monitor logs? ›

Metrics are numerical values that are collected at regular intervals and describe some aspect of a system at a particular time. Azure Monitor Metrics is one half of the data platform that supports Azure Monitor. The other half is Azure Monitor Logs, which collects and organizes log and performance data.

How do I monitor Azure function logs? ›

To view a near real time stream of application log files generated by your function running in Azure, you can connect to Application Insights and use Live Metrics Stream. Or, you can use the App Service platform built-in log streaming to view a stream of application log files.

What is the difference between log monitoring and Log Analytics? ›

Log monitoring and log analytics are related — but different — concepts that work in conjunction. Together, they ensure the health and optimal operation of applications and core services. Whereas log monitoring is the process of tracking logs, log analytics evaluates logs in context to understand their significance.

What is the difference between log Analytics and application insights and Azure monitor? ›

A: Microsoft Azure Application Insights is a service that provides application performance monitoring and diagnostics, while Log Analytics is a service that collects and analyzes log data from various sources.

What are the two main kinds of data Azure Monitor works with? ›

All data collected by Azure Monitor fits into one of two fundamental types: metrics and logs. Metrics are numerical values that describe some aspect of a system at a particular point in time. They are lightweight and capable of supporting near real-time scenarios.

What is the difference between Azure diagnostics and log Analytics? ›

The key differences to consider are: Azure Diagnostics Extension can be used only with Azure virtual machines. The Log Analytics agent can be used with virtual machines in Azure, other clouds, and on-premises.

Where are Azure Monitor logs stored? ›

Activity log data in a Log Analytics workspace is stored in a table called AzureActivity that you can retrieve with a log query in Log Analytics. The structure of this table varies depending on the category of the log entry. For a description of the table properties, see the Azure Monitor data reference.

How does Azure Monitor organize log data? ›

Azure Monitor organizes log data into tables. Azure Monitor organizes log data in tables, each composed of multiple columns. Every query contains data that's organized into a hierarchy similar to SQL (databases, tables, and columns).

How long are Azure Monitor activity logs kept? ›

Activity log events are retained in Azure for 90 days and then deleted. There's no charge for entries during this time regardless of volume. For more functionality, such as longer retention, create a diagnostic setting and route the entries to another location based on your needs.

What is the difference between Log Analytics and application insights and Azure Monitor? ›

A: Microsoft Azure Application Insights is a service that provides application performance monitoring and diagnostics, while Log Analytics is a service that collects and analyzes log data from various sources.

What is the difference between monitoring contributor and Log Analytics contributor? ›

The Log Analytics Reader role allows you to view and search all monitoring data as well as view monitoring settings. This includes viewing the configuration of Azure diagnostics on all Azure resources. The Monitoring Contributor role allows you to read all monitoring data and update monitoring settings.

What is the difference between Azure Monitor and Grafana? ›

Ease of Use and Setup: Azure Monitor requires minimal setup and configuration, especially for Azure resources, as it is integrated natively. It provides a user-friendly interface for monitoring and alert management. Grafana, on the other hand, might require more setup and configuration efforts initially.

Top Articles
Is your investment in Tata Power at risk? What Goldman Sachs thinks - CNBC TV18
Active vs. Passive Voice
Play FETCH GAMES for Free!
Ghosted Imdb Parents Guide
Prosper TX Visitors Guide - Dallas Fort Worth Guide
Do you need a masters to work in private equity?
Samsung 9C8
Costco in Hawthorne (14501 Hindry Ave)
Fire Rescue 1 Login
Ktbs Payroll Login
Daniela Antury Telegram
Nashville Predators Wiki
Nier Automata Chapter Select Unlock
Immediate Action Pathfinder
Jc Post News
104 Whiley Road Lancaster Ohio
Mills and Main Street Tour
Interactive Maps: States where guns are sold online most
Nutrislice Menus
Wicked Local Plymouth Police Log 2022
Craigslist In Flagstaff
Dumb Money, la recensione: Paul Dano e quel film biografico sul caso GameStop
Everything you need to know about Costco Travel (and why I love it) - The Points Guy
Like Some Annoyed Drivers Wsj Crossword
Plaza Bonita Sycuan Bus Schedule
Which Sentence is Punctuated Correctly?
Sadie Sink Reveals She Struggles With Imposter Syndrome
Hannaford Weekly Flyer Manchester Nh
fft - Fast Fourier transform
Top 20 scariest Roblox games
Rainfall Map Oklahoma
Gridwords Factoring 1 Answers Pdf
Wake County Court Records | NorthCarolinaCourtRecords.us
Where Can I Cash A Huntington National Bank Check
Metro 72 Hour Extension 2022
4083519708
Etowah County Sheriff Dept
PA lawmakers push to restore Medicaid dental benefits for adults
Hellgirl000
Craigslist Mexicali Cars And Trucks - By Owner
Nsav Investorshub
Fwpd Activity Log
Simnet Jwu
Craigslist Farm And Garden Reading Pa
Coroner Photos Timothy Treadwell
N33.Ultipro
The Complete Uber Eats Delivery Driver Guide:
Turok: Dinosaur Hunter
Theater X Orange Heights Florida
Uno Grade Scale
Les BABAS EXOTIQUES façon Amaury Guichon
Latest Posts
Article information

Author: Kelle Weber

Last Updated:

Views: 6627

Rating: 4.2 / 5 (53 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Kelle Weber

Birthday: 2000-08-05

Address: 6796 Juan Square, Markfort, MN 58988

Phone: +8215934114615

Job: Hospitality Director

Hobby: tabletop games, Foreign language learning, Leather crafting, Horseback riding, Swimming, Knapping, Handball

Introduction: My name is Kelle Weber, I am a magnificent, enchanting, fair, joyous, light, determined, joyous person who loves writing and wants to share my knowledge and understanding with you.