Azure Monitor-Log Analytics

Welcome to the "Azure Log Analytics ":https://azure.microsoft.com/en-us/services/log-analytics/ Feedback page. We appreciate your feedback and look forward to hearing from you. Use this site for new ideas and bug reports or to request help.
NOTE – Log Analytics is now a part of Operations Management Suite. Learn more at http://microsoft.com/OMS

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Raise the maximum alert rules from the limit of 250.

    We are running into the maximum limit of 250 rules, which is requiring our organization to change our alerting workflow to work around this limit and makes the OMS solution not feel scalable as an alerting tool.

    48 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    2 comments  ·  Alert Management Solution  ·  Flag idea as inappropriate…  ·  Admin →

    While OMS puts a restriction of up to 250 Alerts via OMS Portal – the solution is scalable to beyond these limits. The limit is only put in place to prevent abuse.

    If your organization requires more than 250 Log Analytics based Alerts – be it in OMS or Azure; please reach out to Microsoft Support / Account representatives or Azure Partner. They’ll guide you through the process of increasing alerts, as required for your organizational needs.

  2. Can't create alerts based on cross-resource queries

    It used to be possible through the OMS portal to link an Application Insights instance to Log Analytics. Since the portal is being depreciated, along with the App Insights connector, we are forced to use cross-resource queries to query an App Insights instance from a separate Log Analytics instance. This works fine for general queries, but we cannot create alerts based on cross-resource queries. The alert will not create because of a "syntax error", when the same query works in Log Analytics.

    There should be a way to ingest App Insights data into a Log Analytics instance. Or else we…

    44 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    completed  ·  3 comments  ·  Alert Management Solution  ·  Flag idea as inappropriate…  ·  Admin →
  3. ACTIVATED/RESOLVED states for alerts with auto-resolution

    It often happens an alert being fired and keeping sending me notifications every X minutes until I resolve the problem. It may happen the problem can only be resolved the day after or, worse, many days after (for example, a low disk space condition). Meanwhile, I keep receiving all these notifications, filling up my mailbox and... you know!

    It would be great to have a single ACTIVATED notification when the alert fires and later a RESOLVED notification when the alert condition is not met anymore. I believe there may be a way of achieving this through a pair of complex…

    30 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    5 comments  ·  Alert Management Solution  ·  Flag idea as inappropriate…  ·  Admin →
  4. 29 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    5 comments  ·  Alert Management Solution  ·  Flag idea as inappropriate…  ·  Admin →
  5. Alert

    In most cases when you are looking at the Alert Management Solution you do not care about the instances of an alert - especially if you have been notified by runbook/webhook/email.

    I'd wager that most people care about the data in the search query that caused that alert and the data it returned. Having to copy and paste the LinkToSearchResults is quite time consuming. The UX on this should be improved to allow jumping directly to the search results that caused the alert, would save time on training too!

    18 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    3 comments  ·  Alert Management Solution  ·  Flag idea as inappropriate…  ·  Admin →
  6. Computer Heartbeat

    We want to get an alert if a Server don´t post any data in the Workspace since 5 minutes. Like a heartbeat from each Agent.

    18 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    5 comments  ·  Alert Management Solution  ·  Flag idea as inappropriate…  ·  Admin →
  7. Alert threshold

    Alerts based on Metrics, e.g. if the processor time goes over 95% for 5 Minutes etc.

    16 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    2 comments  ·  Alert Management Solution  ·  Flag idea as inappropriate…  ·  Admin →
  8. Please add the ability to modify/update/enable/disable existing Alerts

    Please provide an interface to allow us to update/modify and enable/disable existing alerts.

    10 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    1 comment  ·  Alert Management Solution  ·  Flag idea as inappropriate…  ·  Admin →
  9. Allow any number of alerts to be defined (currently limited to 10)

    Currently we are limited to 10 alerts, please provide the ability to define as many as are needed by a customer.

    9 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    2 comments  ·  Alert Management Solution  ·  Flag idea as inappropriate…  ·  Admin →
  10. Provide Alert management in the Azure Portal

    Add support for Alert management in the Azure Portal. We really need this option.

    9 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Alert Management Solution  ·  Flag idea as inappropriate…  ·  Admin →
  11. Integration to 3rd party incident management tools like pagerduty

    Getting the alerts out to the on-call teams will require some more logic than sending an email.

    Direct integration to systems like pagerduty or slack would be great.

    8 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    2 comments  ·  Alert Management Solution  ·  Flag idea as inappropriate…  ·  Admin →
  12. Alert Management Intelligence Pack not sending alerts EventID 4501

    in SCOM I see this event EventID 4501

    A module of type "System.PublishDataToEndPoint" reported an error 87L which was running as part of rule "Microsoft.SystemCenter.CollectAlertChangeDataToCloud" running for instance "Operations Manager Management Group" with id:"{6B1D1BE8-EBB4-B425-08DC-2385C5930B04}" in management group "SCOMTEST".

    7 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    6 comments  ·  Alert Management Solution  ·  Flag idea as inappropriate…  ·  Admin →

    This has been fixed – you should see those alerts now!

    (This was ONLY applicable if you see the exact error described in this post in your event log.)

    If you don’t see OTHER types of data, refer to these other ideas and posts
    IIS logs on Windows Server 2008 / IIS7
    SQL Server Assessment data
    are tracked here http://feedback.azure.com/forums/267889-azure-operational-insights/suggestions/6626222-no-data-after-more-than-60-minutes-sql-assessment

    Capacity/Performance only works with VMM, tracked here http://feedback.azure.com/forums/267889-azure-operational-insights/suggestions/6662146-open-up-the-capacity-management-pack-for-other-sys

    Other general info on troubleshooting connectivity issues (written for SCOM but the errors in the event log would be identical for Direct Agent) here http://blogs.technet.com/b/momteam/archive/2014/05/29/advisor-error-3000-unable-to-register-to-the-advisor-service-amp-onboarding-troubleshooting-steps.aspx

  13. Please add the ability to Acknowledge/Resolve Alerts

    As noted in the subject I would like to be able to acknowledge/resolve an alert and have that reflected in the dashboard tile.
    Active alerts: XX
    Resolved Alerts: XX

    7 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Alert Management Solution  ·  Flag idea as inappropriate…  ·  Admin →
  14. Alerting via SMS

    we want to use sms for alerting instead of emails.

    7 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    2 comments  ·  Alert Management Solution  ·  Flag idea as inappropriate…  ·  Admin →
  15. Azure AD Group alert targeting in OMS

    It would be great with an option to limit alerts to specific groups of people in Azure Active Directory. Basically the same functionality that is possible with email notification, where we can enter the "Recipients" of the email alert notification.

    Alerts on a group level should happen both at the OMS API level and also in the Mobile App. I get a lot of alerts that is intended for other group or people.

    5 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Alert Management Solution  ·  Flag idea as inappropriate…  ·  Admin →
  16. scoping

    Allow for scoping by Computer Group(s)

    4 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    1 comment  ·  Alert Management Solution  ·  Flag idea as inappropriate…  ·  Admin →
  17. Alert Management (solution) is missing from Azure Marketplace (June 7, 2018)

    (updating with screenshot)

    The Log Analytics solution, Alert Management, does not come up in search results across the Azure Marketplace.

    See documentation here https://docs.microsoft.com/en-us/azure/log-analytics/log-analytics-solution-alert-management

    3 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Alert Management Solution  ·  Flag idea as inappropriate…  ·  Admin →
  18. Choose Option for Alert Remediation

    Hello,

    Alert Remediation Runbooks are running only on Azure. We need a choose option for hybrid as well.

    2 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    2 comments  ·  Alert Management Solution  ·  Flag idea as inappropriate…  ·  Admin →
  19. No data received on Alert IP

    Can see alert when using Configuration assessment but can't when using Alert IP

    1 vote
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Alert Management Solution  ·  Flag idea as inappropriate…  ·  Admin →

    Alert IP will show new/modified alerts generated in Operations Manager (SCOM) and will exclusively use the new Search backend and experience, NOT the old Advisor ‘Configuration Assessment’ alerts nor those old Silverlight pages.

    Do you have Operations Manager? How long ago have you enabled the Alert IP ? what troubleshooting steps have you already done?

    Let us know if this helps, if not – what do you expect to see here and are not seeing, could you elaborate some more?

    Thx,

  20. alerts does not cleanup webhooks in azure automation when alert rule is deleted

    alerts does not cleanup webhooks in azure automation when alert rule is deleted

    additionally it created 4 webhooks per alert rule (the runbook in picture has have had 3 alerts attached to it. now 2 is deleted, but there is a lot of webhooks)

    1 vote
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Alert Management Solution  ·  Flag idea as inappropriate…  ·  Admin →
← Previous 1
  • Don't see your idea?

Feedback and Knowledge Base