Update: Microsoft will be moving away from UserVoice sites on a product-by-product basis throughout the 2021 calendar year. We will leverage 1st party solutions for customer feedback. Learn more here.

Azure Monitor-Log Analytics

Welcome to the "Azure Log Analytics ":https://azure.microsoft.com/en-us/services/log-analytics/ Feedback page. We appreciate your feedback and look forward to hearing from you. Use this site for new ideas and bug reports or to request help.
NOTE – Log Analytics is now a part of Operations Management Suite. Learn more at http://microsoft.com/OMS

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Collect SQL ERROR logs into Log Analytics

    This feature will enable teams to ingest SQL ERROR logs on IaaS servers into log analytics and develop better alerting and dashboards. The current file extension limitation in log analytics prevent SQL ERROR logs to be discovered by the MMA agent.

    39 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
  2. Timezone conversion to custom log ingestion for Linux OS

    As per the following docs, currently time zone conversion is not supported for time stamps in the logs for Linux OS. Then, even if you use timestamp "yyyy-MM-ddTHH:mm:ssK" as delimiter to specify TimeGenerated in loacl time, the value on TimeGenerated is recorded as UTC.

    https://docs.microsoft.com/en-us/azure/azure-monitor/platform/data-sources-custom-logs

    It would be great if timezone conversion is supported also for Linux OS.

    34 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
  3. parameterize externaldata() argument

    Parameterize this function so that we can easily integrate API calls in KQL.

    Example:

    externaldata(businessName: string, isp:string, businessWebsite: string)
    [
    h@strcat(tostring("https://getip.com/json/"),tostring(IP))
    ]
    with(format="multijson")

    The end goal would be to make a list from make_list() and then use that list in the requestURL needed in externaldata()

    15 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Security and Audit Solution  ·  Flag idea as inappropriate…  ·  Admin →
  4. Enable configuration of multiple log analytics workspaces for linux agent

    Currently the log analytics agent for Linux only supports the configuration of one log analytics workspace. It'd be of advantage to be able to send the logs to multiple log analytics workspaces.

    We have a probably quite common setup among mid to large size enterprises that consists of hub(s) and multiple subscriptions connected to them. For Update Management we are utilizing Azure Automation which should be controlled through our hub(s). Azure Automation therefore requires to be linked to one log analytics workspace in the same subscription.

    At the same time the development / operations teams that make use of the…

    74 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
  5. Sentinel Data Connectors for Windows and Syslog Events

    Sentinel comes with a lot of connectors, most of them based on existing features from Log Analytics Workspaces. Since the presence and stability of Data Connectors is a major concern for security, it is also vital that connectors can be (re)created programmatically when the get out of order. For connectors for the Security Center we found de REST API's that works well [https://docs.microsoft.com/en-us/rest/api/securityinsights/dataconnectors]. For the Azure Activity Log we finally worked out the principles behind it, as they were poorly documented as described here [https://github.com/MicrosoftDocs/azure-docs/issues/66999].

    It would be very helpful to have REST API (or CLI,…

    10 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Flag idea as inappropriate…  ·  Admin →
  6. Multiple data destinations for Linux agent

    The Windows agent can be multihomed to send data to multiple Log Analytics workspaces. The Linux agent can send to only a single destination, either a workspace or management group. It would be a great enhancement if we could configure the Linux agent to report to multiple workspaces.

    13 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
  7. ABC Com Activate ? Dial 1-855-276-3666

    Most importantly, you need to abc com activate contribution on the back or side of the TV. On the off chance that your TV doesn't have a activate port then you should purchase a connector dependent on the video inputand yield that your activate. While deciding video abc these are the accompanying sound and video ports you will discover contingent upon your model.

    Know More : https://educatorpages.com/site/abccomactivate/pages/our-classroom-website

    3 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
  8. Add an option to send logs to different workspaces for each pod when using Container Insights

    Currently, it's supported to send a log to a single workspace from the K8S cluster, and you can't send a log to different workspaces for each pod.
    It would be great if you could have a flexible option of the target workspace depending on the pod of K8S.

    12 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
  9. Pasting integers into Azure Log Analytics query editor

    When pasting certain integers into the Azure Log Analytics query editor (eg. 1594312), they are automatically formatted as todatetime('1594312').

    This is quite inconvenient as we often paste reference numbers into specific queries.

    Could we please have the option to disable this feature?

    3 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Search UI and Language  ·  Flag idea as inappropriate…  ·  Admin →
  10. Cannot display Threshold

    Cannot display Threshold

    When we execute the following query, Threshold will not be displayed.
    If we specify "Computer" on "summarize", the Y-axis will be plotted using the "avgCounterValue" values of all computers.
    At this time, the Threshold value is not avg
    CounterValue, therefore, it is not plotted on the graph.

    Perf
    | where TimeGenerated > ago(30m)
    | where CounterName == "% Processor Time" and ObjectName == "Processor" and InstanceName == "_Total"
    | summarize avg(CounterValue) by bin(TimeGenerated, 30s), Computer
    | extend Threshold = 10
    | render timechart

    If query for a single computer, the threshold will be displayed. However, it…

    32 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Search UI and Language  ·  Flag idea as inappropriate…  ·  Admin →
  11. Belgian Malinois Puppies for Sale

    Sometimes it isn't easy to sum up, our feelings of love and care towards our dog. A little furry animal with four legs acts as the best companion for humanity, especially with disabilities. Belgian dogs are the most preferred breed to train as a service dog as they are robust, intelligent and alert. Also, they possess a prime quality to react instantly with sharpness and smartness. We at Black Rock Canines mother numerous dogs from their birth with transparency and aim to maintain their health to the best. Black Rock Canines provides supreme quality Belgian dogs for sale. Our trained…

    1 vote
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Flag idea as inappropriate…  ·  Admin →
  12. Azure management group activity log ingestion in LAW

    Management group activity logging in log analytics workspace will provide single plane of view for environment with multiple management group requirements.

    1 vote
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Log Management and Log Collection Policy  ·  Flag idea as inappropriate…  ·  Admin →
  13. Add Saved query feature to resource log blade

    according to the below article the saved query is not available when the query scope is sent to a specific resource.
    it will be great if this feature going to be available in the future.

    https://docs.microsoft.com/en-us/azure/azure-monitor/faq#why-cant-i-see-query-explorer-and-save-buttons-in-log-analytics

    3 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Search UI and Language  ·  Flag idea as inappropriate…  ·  Admin →
  14. 3 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
  15. Need a way to provide query parameters for Log Analytics REST API

    I am using [Azure Log Analytics REST API](https://dev.loganalytics.io/) to query data from Azure Log Analytics workspace with kql. Kusto provides a way to prevent query injection by using query parameters as documented [here](https://docs.microsoft.com/en-us/azure/data-explorer/kusto/query/queryparametersstatement?pivots=azuredataexplorer). However I am unable to find a way to provide those query parameters for Azure Log Analytics REST API. Is there a way to achieve this with the Azure Log Analytics REST API or that support is yet to come?

    12 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Flag idea as inappropriate…  ·  Admin →
  16. Respect output order of ContainerLog

    Today, it is only possible to order ContainerLog by generated times.
    However, it can happen that several rows are printed at the same millisecond by a container. This is usually the case when a container displays the backtrace of an error.

    When it happens, it is currently not possible to query log messages from ContainerLog in the suitable order, and thus impossible to perform a log request that would return a callstack in the appropriate order.

    3 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Search UI and Language  ·  Flag idea as inappropriate…  ·  Admin →
  17. Set legend position property with render operator

    The render operator has a legend property for visible or hidden but no property for setting the position (below or right). Either add a property for position or allow setting the position via the legend property.

    1 vote
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Flag idea as inappropriate…  ·  Admin →
  18. Content Marketing Services in India

    360DigitalSpace.com is one of the leading Digital Marketing Company in India. We offer Digital Marketing services (SEO,SMO services,SEM, Content Marketing Company in India and other Web Designing Agency in India and development Services and We also provide Services like SMO Experts in India etc with the best quality.
    https://360digitalspace.com/content-marketing/

    1 vote
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Service Map  ·  Flag idea as inappropriate…  ·  Admin →
  19. Modify the Daily Cap Reset Time

    In each Log Analytics workspace the use of a Daily Cap can been effective in the management ingested data and provides for a better cost forecast.
    Currently, if the cap is triggered, the daily reset occurs at: 04:00 UTC, which is 23:00 EST. Because this reset occurs in the middle of the night, we ingest hours of data that is less critical than data during our business day.

    6 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Flag idea as inappropriate…  ·  Admin →
  20. Allow workbooks to read parameters from URL in

    I would the ability to read the URL for any parameters being passed in it and allow those to be used as parameters within the workbook. This will allow us to be able to start workbooks from other workbooks with the parameters already filled in.

    4 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  My Dashboard  ·  Flag idea as inappropriate…  ·  Admin →
← Previous 1 3 4 5 50 51
  • Don't see your idea?

Feedback and Knowledge Base