Log Analytics

Welcome to the "Azure Log Analytics ":https://azure.microsoft.com/en-us/services/log-analytics/ Feedback page. We appreciate your feedback and look forward to hearing from you. Use this site for new ideas and bug reports or to request help.
NOTE – Log Analytics is now a part of Operations Management Suite. Learn more at http://microsoft.com/OMS

How can we improve Azure Log Analytics ?

You've used all your votes and won't be able to post a new idea, but you can still search and comment on existing ideas.

There are two ways to get more votes:

  • When an admin closes an idea you've voted on, you'll get your votes back from that idea.
  • You can remove your votes from an open idea you support.
  • To see ideas you have already voted on, select the "My feedback" filter and select "My open ideas".
(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can support and comment on it.

If it doesn't exist, you can post your idea so others can support it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Iot solution for IotHub/ServiceBus

    One of my customers build Iot Solution based on multiple Azure Services (web Apps, service fabric, sql, iot hub, service bus, application insights).
    We started using OMS as a single point of monitoring. OMS covering almost all services from our set, except of IoT... it's a gap in a our solution, because we must use big azure portal to initial investigation.

    Please, add native support for IoT Hub and Service Bus as a solution to OMS.

    If we need more details, please contact with me

    3 votes
    Vote
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      I agree to the terms of service
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      0 comments  ·  Extensibility  ·  Flag idea as inappropriate…  ·  Admin →
    • Ability to configure user permissions on solutions

      It would be welcomed to see a possibility to configure user permissions on a solution level. Currently if we allow users to an OMS workspace they will see every solution and every data and every log, which is not preferred.

      3 votes
      Vote
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • facebook
      • google
        Password icon
        I agree to the terms of service
        Signed in as (Sign out)
        You have left! (?) (thinking…)
        0 comments  ·  Workspace Settings / Administration  ·  Flag idea as inappropriate…  ·  Admin →
      • Do we really need ArcSight while Azure Security Center is in use?

        Hi,

        I am working on deployment of a new site. We are planning for Azure Security Center(ASC) implementation. But we do have SIEM(ArcSight) solution already in place for an older site. Now my question is do I really need to send those Azure Security Center (New Site) logs to already existing (Old Site) SIEM ArcSight? Or Azure Security Center alone capable as a primary SIEM solution?

        P.S.: The reason I am asking this because integrating Azure Security Center logs with ArcSight will add extra cost such us (Connector, Extra GB license, Increasing EPS etc. etc.).

        6 votes
        Vote
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • facebook
        • google
          Password icon
          I agree to the terms of service
          Signed in as (Sign out)
          You have left! (?) (thinking…)
          0 comments  ·  Flag idea as inappropriate…  ·  Admin →
        • Breadcrumb navigation in solutions

          Breadcrumb style navigation is not fully implemented. It would be great to be able to go back from log search to the solution from where I got there. For example I select DNS analytics solution, click on any of the section, and if I choose to see the exact entry it takes me to the log search window from where I cannot go back, unless I use browser navigation.

          3 votes
          Vote
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • facebook
          • google
            Password icon
            I agree to the terms of service
            Signed in as (Sign out)
            You have left! (?) (thinking…)
          • Expose OMS REST API to post ticket information by custom ITSM implementations who don't support PULL model

            Expose OMS REST API to post ticket information by custom ITSM implementations who don't support or provide REST APIs to pull ticket information through querying at regular intervals (example: every 15 minutes).

            3 votes
            Vote
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • facebook
            • google
              Password icon
              I agree to the terms of service
              Signed in as (Sign out)
              You have left! (?) (thinking…)
              0 comments  ·  OMS Gateway  ·  Flag idea as inappropriate…  ·  Admin →
            • Ability to change the logging time

              We already log in UTC timezone on our machines, but the monitoring agent thinks it is in local time so it converts it.
              It would be great to have an option to switch between local and utc time when we are setting the delimiters for the logs

              1 vote
              Vote
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • facebook
              • google
                Password icon
                I agree to the terms of service
                Signed in as (Sign out)
                You have left! (?) (thinking…)
              • Allow deep links to computers in Service Map

                When accessing Service Map data in the portal, it doesnt allow to directly jump to a computer or machine group.

                When calling Service Maps from external tools, it would be great to directly jump to a particular machine for diagnosis.

                Those links could be pinned to the azure dashboard or simply saved as a favourite on the webbrowser.

                1 vote
                Vote
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • facebook
                • google
                  Password icon
                  I agree to the terms of service
                  Signed in as (Sign out)
                  You have left! (?) (thinking…)
                  0 comments  ·  Service Map  ·  Flag idea as inappropriate…  ·  Admin →
                • Windows Defender AV Assessment

                  Make the values for signature-ou-of-date etc. customizable. The default 14 days is way to far in the past.

                  Signature out of date devices are devices with signature older than 14 days.

                  3 votes
                  Vote
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • facebook
                  • google
                    Password icon
                    I agree to the terms of service
                    Signed in as (Sign out)
                    You have left! (?) (thinking…)
                    0 comments  ·  Flag idea as inappropriate…  ·  Admin →
                  • Import Application specific logs from Blob Storage or Table entries into Log Analytics for Azure Functions

                    Import Application specific logs from Blob Storage or Table entries into Log Analytics for Azure Functions

                    1 vote
                    Vote
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • facebook
                    • google
                      Password icon
                      I agree to the terms of service
                      Signed in as (Sign out)
                      You have left! (?) (thinking…)
                    • Table view of a Measure should include all groups

                      Table view only displays the first column of multiple groupings. Example:
                      Type:W3CIISLog | measure sum(TimeTaken) as TotalTime by sSiteName, csUriStem
                      Click Table view.
                      The column sSiteName shows up in Table view but csUriStem does not.

                      2 votes
                      Vote
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • facebook
                      • google
                        Password icon
                        I agree to the terms of service
                        Signed in as (Sign out)
                        You have left! (?) (thinking…)
                        0 comments  ·  Search UI and Language  ·  Flag idea as inappropriate…  ·  Admin →
                      • MessageTrace

                        It would be nice to receive MessageTrace Logs from O365 into OMS so that we could be more proactive in seeing compromised accounts. This would allow us to be alerted say on a user that is sending 100 messages of the same subject out.

                        3 votes
                        Vote
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • facebook
                        • google
                          Password icon
                          I agree to the terms of service
                          Signed in as (Sign out)
                          You have left! (?) (thinking…)
                          0 comments  ·  Security and Audit Solution  ·  Flag idea as inappropriate…  ·  Admin →
                        • Date facet and TimeGenerated in query are inconsistent - can we override or disable Date facet

                          The Date facet in the log query screen seems to apply inconsistently - if I specificy the timeframe I want to query it may or may not override my query and use it's set default range
                          e.g. I use TimeGenerated>NOW-30DAYS in my query, but as I have NOT adjusted the Date facet it restricts my results to the "Data based on the last 1 day" - which is what the Date facet is set to by default for each new query
                          It would be good if Date filter could be turned off for queries

                          3 votes
                          Vote
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • facebook
                          • google
                            Password icon
                            I agree to the terms of service
                            Signed in as (Sign out)
                            You have left! (?) (thinking…)
                            0 comments  ·  Search UI and Language  ·  Flag idea as inappropriate…  ·  Admin →
                          • Update Management

                            I'm not sure if this is the place to put a question on the Update Management solution, but I didn't see a category for 'Automation and Control' or 'Update Management'.

                            I've been experimenting with the OMS offerings using Windows 10 1703 computers for testing. In all cases, the Windows 10 machines are pointing to Microsoft Update, and not to a internal WSUS server.

                            I've noticed that Update Manager is reporting ~20 missing drivers for my computer that Windows Update that the Windows Update Agent is not picking up. Some of those drivers are categorized as Windows 8.1 drivers.

                            One that…

                            1 vote
                            Vote
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                            • facebook
                            • google
                              Password icon
                              I agree to the terms of service
                              Signed in as (Sign out)
                              You have left! (?) (thinking…)
                              0 comments  ·  Extensibility  ·  Flag idea as inappropriate…  ·  Admin →
                            • Ingestion and analysis of netflow logs

                              In order to add to the Network Monitoring piece it would be useful to also allow collection of Netflow logs for analysis and visualization

                              1 vote
                              Vote
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                              • facebook
                              • google
                                Password icon
                                I agree to the terms of service
                                Signed in as (Sign out)
                                You have left! (?) (thinking…)
                              • "measure x interval" graph should go to zero when there are no data

                                I want to get a graphical overview of the occurence of some event and I want to do so in a 5 minute interval. That search could fx be
                                Type=Error_CL | measure count() interval 5minute
                                The event occurs much less often than on a 5 minute interval, so I expect the graph to go to 0 most of the time but it doesn't.
                                To be explicit, I expect:
                                No graph until first event.
                                No graph beyond last event.
                                Graph in between first and last event is 0 when there are no events - not interpolated.
                                See attachment.

                                3 votes
                                Vote
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                • facebook
                                • google
                                  Password icon
                                  I agree to the terms of service
                                  Signed in as (Sign out)
                                  You have left! (?) (thinking…)
                                  0 comments  ·  Search UI and Language  ·  Flag idea as inappropriate…  ·  Admin →
                                • Ability to have different time duration on tiles on main dashboard

                                  For the main OMS dashboard, we need the ability for each individual tile to have its own "time duration" for graphs & charts. We have some tiles that need to show the last 24 hours, and some that need to show the last 7 days

                                  4 votes
                                  Vote
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                  • facebook
                                  • google
                                    Password icon
                                    I agree to the terms of service
                                    Signed in as (Sign out)
                                    You have left! (?) (thinking…)
                                    0 comments  ·  My Dashboard  ·  Flag idea as inappropriate…  ·  Admin →
                                  • Office 365 Analytics - populate UserSharedWith parameter

                                    The O365 pack gets logs of file sharing operations, and the user who shared, but the UserSharedWith is always blank. This is accessible in O365 audit logs

                                    26 votes
                                    Vote
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                    • facebook
                                    • google
                                      Password icon
                                      I agree to the terms of service
                                      Signed in as (Sign out)
                                      You have left! (?) (thinking…)
                                    • Extend Keyword

                                      Extend the OMS Extend keyword to permit mapping of a field value such as Windows EventID to a business friendly term. Example:

                                      Type=SecurityEvent EventID IN {4728,4729} | Extend if(EventID=4728,"ADD","REMOVE")

                                      1 vote
                                      Vote
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                      • facebook
                                      • google
                                        Password icon
                                        I agree to the terms of service
                                        Signed in as (Sign out)
                                        You have left! (?) (thinking…)
                                      • Custom Fields to more CL

                                        Please, enable capability to apply a single custom field to more CL. Or, capability to create a Sub-CL

                                        27 votes
                                        Vote
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                        • facebook
                                        • google
                                          Password icon
                                          I agree to the terms of service
                                          Signed in as (Sign out)
                                          You have left! (?) (thinking…)
                                          0 comments  ·  Flag idea as inappropriate…  ·  Admin →
                                        • Custom fileds with delimiters

                                          Need to create custom fields by standard delimiters (i.e. | , ;)

                                          62 votes
                                          Vote
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                          • facebook
                                          • google
                                            Password icon
                                            I agree to the terms of service
                                            Signed in as (Sign out)
                                            You have left! (?) (thinking…)
                                            1 comment  ·  Flag idea as inappropriate…  ·  Admin →
                                          ← Previous 1 3 4 5 36 37
                                          • Don't see your idea?

                                          Feedback and Knowledge Base