Azure Monitor-Log Analytics
Welcome to the "Azure Log Analytics ":https://azure.microsoft.com/en-us/services/log-analytics/ Feedback page. We appreciate your feedback and look forward to hearing from you. Use this site for new ideas and bug reports or to request help.
NOTE – Log Analytics is now a part of Operations Management Suite. Learn more at http://microsoft.com/OMS
- For general discussion/question and answers (not ideas and bug reports) use the MSDN Forum
- Onboarding issues? Read this troubleshooting guide
- How do I do XYZ? Try our documentation
- Customers with Premier support can log support cases via Premier
- Customers with Azure support agreements can log support cases in the Azure portal
-
Improve multitenancy for managed services providers
Currently we can have one subscription per MG and/or consolidate multiple MGs into one single subscription. What's missing is the ability to have groups of different systems from the same MG to report to different subscriptions. In management as a service scenario for SMB customers it's often impractical to have 1 MG per customer, rather multiple customers are consolidated into one infrastructure (MG) and then access is limited via scoping. Bring this to Advisor, please.
299 votesMSP asks have been addressed with feature updates with in Product. If there is still any request not covering the scenario please voice it out. Thank you.
Documentation Reference for existing supportability – https://docs.microsoft.com/en-us/azure/azure-monitor/platform/service-providers
-
Hard-delete option for Log Analytics workspaces
We're building immutable infrastructure for our product and would like to delete/destroy any resource on-demand. Unfortunately we noticed the Log Analytics workspaces use a "soft-delete" which gives us the ability to recover workspaces for a certain amount of time.
Although this is a nice feature, it also limits us in our ability to destroy and create workspaces at any given time. Therefore we would like to propose a "Hard-delete" option which needs to be configured explicitly when deleting a workspace.
63 votesApologies for delayed response on this. Currently the permanent workspace delete option is available. Please see if this would fit your scenario.
-
Export dashboard customizations
It would be really nice if we could export dashboards as a template. As part of the Microsoft IR team, we plan to create a standard desktop fed off of the same sources for multiple customers during compromise recovery. If there was a way to export \ import a pre-configured dashboard it would be really useful.
21 votesIt is possible with Azure Dashboards that now fully support Log Analytics queries
-
Per Server Usage
Ability to see GB usage per monitored server.
9 votesThe new usage views includes the ability to see the amount of data per computer
The included views will give you information on:
• How much data is sent to Log Analytics and by which Computers
• How much data is sent for each solution
• How much data isn’t associated with a computer
• Which computers are sending data and which computers haven’t recently sent data
• How many nodes are sending data for each of the OMS offers (Insight & Analytics, Automation & Control, and Security and Compliance)
• How long it takes for Log Analytics to make data searchable-Richard
-
Data usage per solution
Check data usage per solution
6 votesToday in the usage panel the data per solution is available over the last 30 days. We have additional work coming for solution targeting
-
'Settings' page does not load (needs Silverlight)
Settings screen remains blank. Tried in IE10 and Chrome.
5 votesWe have updated the accounts experience to html5 last week. Enjoy!
For the more broad wlimination of Silverlight, please also refer to this other thread http://feedback.azure.com/forums/267889-azure-operational-insights/suggestions/6519191-please-dump-all-use-of-silverlight-it-crashes-re
-
Dashboard Theme
Please can you add the ability to change the theme so that it's consistent with the Azure Portal (Black).
4 votes -
When adding organisational accounts as admins need a filter\find button on account browse pane
So just went to add some admins in, chose my organization then clicked to browse and had to manually search for account. It would be good to have a filter\find button at the top of this pane to let me put the first few letters of the user in.
With a large organization having to manually browse through the directory is not practical4 votesAs part of replacing the Silverlight account page with an HTML based page we have provided an auto-complete experience where typing the first several letters will then open a drop down with all matching names.
-
Add Organization button not available
The Add Organization button is greyed out
4 votesThis was fixed and we confirmed over email it is working.
-
Resource Manager VM & Operation Insight
Not sure if it is a bug. When we create an Ops Insight work space, it is possible only from Old portal (new portal redirects the connection to old portal, for Ops Insight). In this case...if we create ARM Vms which is possible via only New portal..., and if we want to see if a VM is enabled for Ops insight or not...how is possible ? If I got to Ops Inisight section in old portal ie "Ops Insight Workspace --> servers "., we never see the Resource Manager VMs. it shows only classic Vms with 'Operation Insight Enabled /…
4 votesThe Operational Insights [called Log Analytics (OMS) ] experience in the new Azure portal shows both ARM and Classic VMs.
-
Operational Insights Requirements
Hi, how are you? I would like to know what are the Operational Insights requirements for example, what port I need to have available, etc.
I'm attentive to your comments, thank you so much, regards!
4 votes -
Grant access to security group - members are always asked to create a new workspace
When granting access to the MMS workspace using a security group, members of this group always got the error "The Microsoft account you used is not associated with an Microsoft Operations Management Suite workspace. Do you want to create a new Microsoft Operations Management Suite workspace?" while obviously this user is:
* first not a MSA but a work account (Office 365/Azure AD) synched
* member of the security group granted for access3 votesThis should not be the case, if you added a WAAD group you should just get access to that workspace.
This was resolved offline over email, repeating the operation on the new ‘settings’ → account page.
-
Add organizational accounts from another directory as users or admins
We have added users from another directory into the current directory associated with the subscription where OMS has been deployed, but we cannot add those external users as admins or users in OMS.
3 votesIn the Log Analytics portal you can change the organizational account that is used for adding users.
This lets you add users from multiple Azure Active Directories to a single workspace.
-Richard
-
Operational Insights onsite agent collector
This is a question for Azure Operational Insights.
Can we an option to install a soft of agent and collector at the same time? Why this request?
- I will like to send event from many source to one device only in one segment or area of my environment, and this device will be the only one connecting with azure using my workspaced credential.
I will like to send network (router, appliances) log to this device via port setting only, without go to an public network connection and have my network logs in Azure too.Windows Event Logs "Forwarded Events"…
3 votes -
Why are we forced to change password when signing in or signing up?
When I first signed up with the preview using my AzureAD "OrgID" it forced me to change my password - claiming the reason was needing to enforce password complexity.
Now when I invite a Microsoft Account to the my preview service, that user gets the same experience.
In both cases the claimed reason is flawed:
1) The operational insights process should not KNOW what the password used to authenticate was - so can't tell if the passcode was "complex" or not
2) The changed password is was no more complex than the one before it.If there is another reason…
3 votesThere is such a requirement when authenticating to enterprise-grade applications, especially for Microsoft accounts (formerly LiveID) which represent ‘individual’ identities (as opposed to ‘organizational’ identities). As you wrote, with LiveID’s you could have people whose passwords were last set back in Passport.net.
Many users use Windows Azure Active Directory / Organizational accounts for an even higher degree of security – just extending their corporate AD, where you probably already have password complexity rules in place.
We (OpInsights) don’t enforce pwd complexity in your WAAD tenants – Active Directory team told us that you should only be seeing the request to change your user’s password when you have a temporary password that needs to be changed (=one that is created when a new user account is created), or because your password has expired. It’s a “Change on first login” or a "password is expired’ message, basically.
It has nothing to do… -
Allow non admin of AAD organization to associate organization with Advisor Account
Example:
Contoso.com administrators are the only ones who can associate Contoso.com as an organization to an advisor account. As long as some admin has previously given permission for Advisor to read Contoso.com azure active directory, Advisor should allow users of Contoso.com to configure an advisor account with Microsoft.com as the organization. In a large organization it would be too heavy handed to ask administrators of Contoso.com to do this.2 votesWe have completed our 1st-party integration with WAAD, and this has become possible, as the need to grant explicit consent has been lifted with this change.
We still don’t allow adding users from different Org ID’s to the same workspace, and we still don’t allow users to change the Org Id associated with their subscription, anyhow.
-
Adding Users under settings only lets me choose Microsoft Account
I've seen the same issue listed below but without the explanation of how someone has got to where they are so...
I've recently started the MAOI and added some on-prem servers
we have an AD Federated on Azure
I can see 'Microsoft Azure Operational Insights' in the AD Apps
Access has been granted to MAOIon the MAOI portal I go to settings and scroll down to
[ Manage Users ]if I add a user with their ORG ID it defaults to a Microsoft Account and this cant be changed/edited or selected as an option at creation.
I am…
2 votes -
invalid workspace id
When I install the agent and try to set the workspace ID I get the error "invalid workspace ID" .... The format is wrong
But I copy-paste it???2 votesOk so in one case the user was using the workspace name rather than the ID.
In the other case, the clock of the client was off about 18 minutes compared to the one in Azure and was making authentication fail.
-
Bug: Can not log in to Azure Operational Insights after update to OMS
We can not log in to our pre-existing workspaces after the update to OMS.
When I try to sign in from http://www.microsoft.com/en-us/server-cloud/operations-management-suite/overview.aspx or https://preview.opinsights.azure.com/ or SCOM integration I’m forwarded to this page https://www.mms.microsoft.com/Error.aspx?errorCode=589828 ;-(
I am using a Microsoft account that happens to match my organizational ID. We never added our organization to the Preview.
I have two workspaces one of which was created a few weeks ago. ID: 4869558c-689b-4ec5-a1af-9df9ef5c11b0
Please advice.
PS: I have a customer presentation on Tuesday and I'm beginning to panik ;-)
2 votesThis was fixed.
-
Control of data aggregation
Allow more granularity with data 30 minute aggregation after 6 hours does not meet requirements to see raw data further out in time.
1 voteInstead of storing 30 minute aggregates for performance counters we now store the raw performance counters and let you perform your own aggregations.
The following blog has more information:
https://blogs.technet.microsoft.com/msoms/2016/08/05/raw-searchable-performance-metrics-in-oms/-Richard
- Don't see your idea?