Azure Monitor-Log Analytics

Welcome to the "Azure Log Analytics ":https://azure.microsoft.com/en-us/services/log-analytics/ Feedback page. We appreciate your feedback and look forward to hearing from you. Use this site for new ideas and bug reports or to request help.
NOTE – Log Analytics is now a part of Operations Management Suite. Learn more at http://microsoft.com/OMS

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Ability to create index for custom fields

    As an administrator of OMS I have created some custom fields on e.g. syslog message from a Cisco ASA device. The field values are system codes that is hard to remember for the Network Guys who are using OMS to analyse the syslog events, so they ask for a feature where they could map the values/codes to a more descriptive sentence instead of having to look at a reference document outside of OMS.

    If the OMS admin could enable the creation of a custom index for a custom field, they could map the ASA values/codes to the descriptive values. That…

    6 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  2. Full instance name for performance counters

    Exchange Server has composite Instance names. For example, latency info for databases is located in "MSExchange Database ==> Instances(*)\I/O Database Reads (Attached) Average Latency" counter . An instance name looks like 'Information Store - DB1_Total', 'Information Store - DB2_Total'. But Log Analytics leaves only last part of an instance value an I see "Total#1", "Total#2" etc. It's not possible to identify a corresponding database. It's necessary to store a full instance name in some column.

    6 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  3. Custom Field Data extract

    Hi guys,

    When i try to extract data to a new custom field this error appears and i don't had any custom field with the same name that i give to the new.

    The error is:

    This is an error of OMS?

    Congrats

    6 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  4. BUG: Log Search Filtering by TimeGenerated range produces different results than the setting date range through gui

    Problem:
    Log filtering by date range behaves inconsistently.

    Search 1
    Perform search of "Type=Event | Measure count() by EventID" with the 'Data based on last 1 day' restriction (on the left side of the screen)

    Search 2
    Now perform search of "Type=Event TimeGenerated:[NOW-24HOURS..NOW] | Measure count() by EventID" with same 'Data based on last 1 day'

    Problem 1 -
    The results are not the same - with a bigger problem coming up next

    Search 3
    Repeat search 1 "Type=Event | Measure count() by EventID"
    and NOW Search 3 matches Search 2

    WHAT THE HECK?

    To re-trigger the mis-match, simply change…

    6 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  5. Preserve original event log order even if events have the same source time at millisecond level

    When two events fire very closely together in an application, their order is correct in the windows event log. However, in OMS log search, they are in random order, since their time is the same on the millisecond level.
    There are times that the event order is important.

    6 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  6. kubelet

    it would be really nice to add the functionality to collect kubelet logs to log analytics for AKS monitoring.

    sudo journalctl -u kubelet -o cat

    https://docs.microsoft.com/en-us/azure/aks/kubelet-logs

    6 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  7. Connect to Azure Storage should not take you to documentation

    I want to add additional storage accounts but all it keeps doing wihen I click connect is take me to documentation. Clicking the Connect to Azure Storage button should take me to a location to connect, not send me to a documentation page

    5 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  8. read logs from database table

    Allow logs to be collected from a database table. this is a common place for applications to store error or audit logs (in our case an ETL is logging progress and status to 2 tables).

    5 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  9. Sort Custom Fields Ascending / Descending for each column

    After custom fields are created through the Data Collector API, they appear in alphabetical order. Nice would be, if I could click on the column header and it would sort accordingly ascending or descending.

    5 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  10. Allow custom logs to process UCS-2 LE BOM formatted logs

    We are trying to upload SQLERROR logs for Microsoft SQL server into the Log Analytics Custom Log feature but UCS-2 LE BOM formatted logs are not currently supported. Please add this feature as MS SQL server does not give an option to change the format for these logs.

    4 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  11. Ability to use storage account keys in a keyvault

    Ability to use keyvault for storage account keys instead of having to update the OMS configuration everytime the storage account key is updated.

    This storage account key process updates the keys and writes them to the keyvault.
    http://www.dushyantgill.com/blog/2015/04/26/say-goodbye-to-key-management-manage-access-to-azure-storage-data-using-azure-ad/

    4 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  12. 4 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  13. operationalinsights

    Get-AzureRmOperationalInsightsSearchResults change or bug?
    There seems to have been a (undocumented?) change in the format of the output from the Get-AzureRmOperationalInsightsSearchResults cmdlet in the AzureRM.OperationalInsights PowerShell module between versions 2.3.0 and 3.1.0.
    Piping the output into ConvertFrom-json now fails.
    Details attached.

    4 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  14. Application Pool Logging

    We would love for an ability to be able to collect logs from specific application pools

    4 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  15. What is going to happen to the Standard OMS licens (S)?

    Hi!

    I´m using the Standard OMS licens plan now and i think it suites my needs very well. Will i be able to use this licens for OMS in the future?

    4 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  16. Build Trend Queries

    It would be great to make some trends. For example, query free space in Mb on specific disk on DB Server for last month, measure average decreasing per day/hour/minute and build possible trend for the next day/month/year of decreasing free space an put it on the dashboard with specific treshhold. It is just a "hot" example scenario very needed for admins and i guess it is possible to trend not only performance data.

    OMS already has "Measure" command, maybe it is good idea to expand it with some kind of "trend" operator.

    4 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  17. Multiline log support

    It is very inconvenient when the log comes separately from the stack trace messages, the order of the lines is mixed. This needs to be fixed. Ideally, everything should come in one message in multi lines

    4 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  18. UI Bug in Custom Log Modal

    There is a bug within the Azure Log Analytics portal when adding a Linux Custom Log path.

    4 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  19. Log Analytics agent support for specific event IDs

    I'd like to be able to ingest specific Windows event log event IDs. Considering billing is done by ingestion, there are some Informational events I need to ingest while ignoring other, extremely noisy events. In my opinion, there should be more than an "all or nothing" configuration approach.

    3 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)

    Thanks for the valid suggestion. Your feedback is now open for the user community to upvote & comment on. This allows us to effectively prioritize your request against our existing feature backlog and also gives us insight into the potential impact of implementing the suggested feature.

  20. Message display bug

    Added in a new log collection and when I hit save, this message came up, with a truncated question.

    3 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  • Don't see your idea?

Feedback and Knowledge Base