Azure Monitor-Log Analytics

Welcome to the "Azure Log Analytics ":https://azure.microsoft.com/en-us/services/log-analytics/ Feedback page. We appreciate your feedback and look forward to hearing from you. Use this site for new ideas and bug reports or to request help.
NOTE – Log Analytics is now a part of Operations Management Suite. Learn more at http://microsoft.com/OMS

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Allow custom logs to process UCS-2 LE BOM formatted logs

    We are trying to upload SQLERROR logs for Microsoft SQL server into the Log Analytics Custom Log feature but UCS-2 LE BOM formatted logs are not currently supported. Please add this feature as MS SQL server does not give an option to change the format for these logs.

    4 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  2. Log analytics to support multi dimensional metrics input from Event Hubs

    Sending multi-dimensional metrics via diagnostic settings is not currently supported. Metrics with dimensions are exported as flattened single dimensional metrics, aggregated across dimension values.
    For example: The 'Incoming Messages' metric on an Event Hub can be explored and charted on a per queue level. However, when exported via diagnostic settings the metric will be represented as all incoming messages across all queues in the Event Hub.

    The Diagnostics and Metrics team did confirm that the Incoming messages metric is multi-dimensional. And because of this when sending the data to Log Analytics it will only present all of the incoming messages…

    4 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)

    Thanks for the feedback . Your feedback is now open for the user community to upvote & comment on. This allows us to effectively prioritize your request against our existing feature backlog and also gives us insight into the potential impact of implementing the suggested feature.

  3. 4 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  4. operationalinsights

    Get-AzureRmOperationalInsightsSearchResults change or bug?
    There seems to have been a (undocumented?) change in the format of the output from the Get-AzureRmOperationalInsightsSearchResults cmdlet in the AzureRM.OperationalInsights PowerShell module between versions 2.3.0 and 3.1.0.
    Piping the output into ConvertFrom-json now fails.
    Details attached.

    4 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  5. Application Pool Logging

    We would love for an ability to be able to collect logs from specific application pools

    4 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  6. What is going to happen to the Standard OMS licens (S)?

    Hi!

    I´m using the Standard OMS licens plan now and i think it suites my needs very well. Will i be able to use this licens for OMS in the future?

    4 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  7. Build Trend Queries

    It would be great to make some trends. For example, query free space in Mb on specific disk on DB Server for last month, measure average decreasing per day/hour/minute and build possible trend for the next day/month/year of decreasing free space an put it on the dashboard with specific treshhold. It is just a "hot" example scenario very needed for admins and i guess it is possible to trend not only performance data.

    OMS already has "Measure" command, maybe it is good idea to expand it with some kind of "trend" operator.

    4 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  8. UI Bug in Custom Log Modal

    There is a bug within the Azure Log Analytics portal when adding a Linux Custom Log path.

    4 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  9. Message display bug

    Added in a new log collection and when I hit save, this message came up, with a truncated question.

    3 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  10. Allow Activity Log to be Scoped for a particular Resource Group

    When you collect the Azure Activity Log through Log Analytics, it collects Azure Activity for the entire subscription. We need the ability to collect it for just a specific resource group.

    3 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  11. Shorten Custom Log Pulls from 5 mins

    We are using OMS to track usb unplug events in our meeting rooms. But the wait time for an alert is 5 mins. Thats to long. We want to have self-healing scripts that would notify the user that something has been unplugged within a min of the disconnect.

    3 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  12. import data

    It would be good to have a way to automatically import azure tables into log analytics. Currently the only way is to call log analytics and after call azure tables to have a data replica. Other possibility it would be to export data from Log Analytics into azure tables. Currently log analytics is kind of a black box since the only way to pull or push data is through the API.

    3 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  13. No AzureActiveDirectory audit data in workspace after recreating ws with same name

    AAD diagnostic Settings do not update the id of the Workspace if this newly created one gets the same name again.

    3 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)

    Thanks for the feedback. Your feedback is now open for the user community to upvote & comment on. This allows us to effectively prioritize your request against our existing feature backlog and also gives us insight into the potential impact of implementing the suggested feature.

  14. Custom Field as a Primary Key and Status "Update" Discovery

    I believe that if we have the ability in custom logs to select a custom field as a Primary Key in order to correlate other events with that would be very helpful. For Example i have a log with Custom Field "ID" and another custom field "Status". If the Status has value "Open" i can create a view with "ID" and Status "OPEN" if something changes in that Primary Key in the STATUS Field to understand that this ID is now Closed. Thank you very much.
    The main function here is for OMS to understand the uniqueness of the custom…

    3 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  15. Nagios Alert does not show Service Name

    Nagios alerts are collected by LogAnalytics.
    Customers were able to implement settings to send alerts to LogAnalytics and receive notifications.

    But there is a problem.
    That is AlertName = SERVICE ALERT data.
    The Service Name detected by Nagios is not stored in this column.
    Therefore, we can not judge from what LogAnalytics logs what service alerts are.

    The same problem is raised in Github.
    https://github.com/Microsoft/OMS-Agent-for-Linux/issues/613

    When is the ETA?

    3 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Log Management and Log Collection Policy  ·  Flag idea as inappropriate…  ·  Admin →
  16. Agent for iOS/Android/Windows 10 Mobile

    I want to monitor iOS/Android/Windows 10 Mobile by Microsoft Operations Management Suite.

    3 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  17. Regex to support MM/DD/YYYY HH:MM:SS

    Need a Regex option in Custom Logs to support 24hr formatting minus the AM/PM requirement.

    3 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Log Management and Log Collection Policy  ·  Flag idea as inappropriate…  ·  Admin →
  18. Allow a push stream to be sent to the HTTP Data Collector

    It should be possible to dynamically parse data and stream it to the HTTP Data Collector API using a push stream approach.

    This is not currently possible since the Content-Length is a required component of the Signature in the Authorization header and the size of the payload is not known ahead of time when generating a push stream.

    3 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Log Management and Log Collection Policy  ·  Flag idea as inappropriate…  ·  Admin →
  19. event log filtering

    provide ability to define custom event log filtering to include / exclude events from specific hosts or groups.
    All, Common, Minimal are not effective and are causing cost overruns.

    3 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  20. Custom logs - monitoringhost.exe crashes

    When configuring Collection of a custom log, then we see monitoring host crashes with event id 4000 every 10 min on most agents. Event description contains "A monitoring host is unresponsive or has crashed. The status code for the host failure was 2164195371". This also causes the NIC to be paused and restarted.

    Event ID 1026 is logged in the Application log containing: Application: MonitoringHost.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.ArgumentOutOfRangeException at System.DateTime.op_Subtraction(System.DateTime System.TimeSpan) at Microsoft.EnterpriseManagement.HealthService.LogWatcher.LogDirectoryWatcher.ErrorRetryCallback(System.Object) at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext System.Threading.ContextCallback System.Object Boolean) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext System.Threading.ContextCallback System.Object Boolean) at System.Threading.TimerQueueTimer.CallCallback() at System.Threading.TimerQueueTimer.Fire()…

    3 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  • Don't see your idea?

Feedback and Knowledge Base