Azure Monitor-Log Analytics

Welcome to the "Azure Log Analytics ":https://azure.microsoft.com/en-us/services/log-analytics/ Feedback page. We appreciate your feedback and look forward to hearing from you. Use this site for new ideas and bug reports or to request help.
NOTE – Log Analytics is now a part of Operations Management Suite. Learn more at http://microsoft.com/OMS

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Date facet and TimeGenerated in query are inconsistent - can we override or disable Date facet

    The Date facet in the log query screen seems to apply inconsistently - if I specificy the timeframe I want to query it may or may not override my query and use it's set default range
    e.g. I use TimeGenerated>NOW-30DAYS in my query, but as I have NOT adjusted the Date facet it restricts my results to the "Data based on the last 1 day" - which is what the Date facet is set to by default for each new query
    It would be good if Date filter could be turned off for queries

    6 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Search UI and Language  ·  Flag idea as inappropriate…  ·  Admin →
  2. Log Search is slow

    Some searches seem very slow. For example, try
    Type=SecurityEvent (EventID="4624") for the last 7 days and it never completes. I do see an 'Internal Server Error' in the UI, but it give no details.

    5 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    1 comment  ·  Search UI and Language  ·  Flag idea as inappropriate…  ·  Admin →
  3. Allow me to choose the 'width' of each time bar in 'results over time' facet / time control

    Now it automatically adjusts - i.e. when looking at 7 days, each bar becomes 6 hours. It would be nice to decide what interval to choose.
    6 hours is an odd interval. If I am looking at 7 days I would rather see how many of those results are there each day/24 hrs intervals/buckets.
    If I am querying 1 or 2 days, I probably want to see a hourly breakdown.

    The idea is to offer a drop down to allow selecting specific aggregation intervals.

    5 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Search UI and Language  ·  Flag idea as inappropriate…  ·  Admin →

    Hi,

    Thanks for offering this feature. Currently the plan is to upgrade the portal with many new features, the timeline is being re-designed as part of it.
    Until that, I can only recommend you to use the query to generate charts that describe this in the manner that fits your data best.

    We’ve recently upgraded the query language. Here’s an example of the new syntax, using 3-hour bins over the last two days of events:
    Event
    | where TimeGenerated > now(-2d)
    | summarize count() by bin(TimeGenerated, 3h)
    | render timechart

    Regards,
    Noa

  4. Line Number for Syntax

    Whenever I make an error in a Log Search syntax, it tells me a line number, but I have no easy way of finding that line number or position in the editor. Is there a sytax checker that would provide that information?

    5 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Search UI and Language  ·  Flag idea as inappropriate…  ·  Admin →
  5. Filters in OMS

    It would be great if you could provide a set of entities without case sensitive names, or at least provide a set of entities that do not have the same name. I have found clientIp_s and clientIP_s ..... they are different!

    A bit difficult to filter !

    4 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Search UI and Language  ·  Flag idea as inappropriate…  ·  Admin →
  6. Search Result Column Re-Sizing is Broken

    When query results are returned the columns need to be fully re-sizable. The far right column restricts how wide you can make the other columns which makes other columns un-viewable if the content is to long. Example attached.

    4 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Search UI and Language  ·  Flag idea as inappropriate…  ·  Admin →
  7. Operationional Insights reference in OMS

    I've noticed a reference to Operational Insights (old name) reference in the portal.

    4 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Search UI and Language  ·  Flag idea as inappropriate…  ·  Admin →
  8. Log Analytics -> Logs (Preview) blade needs Saved Searches-like feature

    The current "Logs" blade is pre-populated with "A few more queries to try" and heavily pre-populated "Saved Searches" for common queries. This UI feature was critical to my understanding of log queries. If the new "Logs (Preview)" blade is to supersede the current "Logs" blade: please bring over a similar each to find and use feature.

    3 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Search UI and Language  ·  Flag idea as inappropriate…  ·  Admin →
  9. Ability to turn off Filter (preview)

    When using the Log Analytics query portal, every time we execute a query, the portal automatically switches to the Filter (preview) pane. When working with complex data (such as AzureDiagnostics or Syslog), this hangs the browser--sometimes for several minutes.

    Can we please have the option to turn this feature OFF? I personally find it useless for my day-to-day work anyway (and I live in Log Analytics).

    3 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Search UI and Language  ·  Flag idea as inappropriate…  ·  Admin →
  10. "measure x interval" graph should go to zero when there are no data

    I want to get a graphical overview of the occurence of some event and I want to do so in a 5 minute interval. That search could fx be
    Type=Error_CL | measure count() interval 5minute
    The event occurs much less often than on a 5 minute interval, so I expect the graph to go to 0 most of the time but it doesn't.
    To be explicit, I expect:
    No graph until first event.
    No graph beyond last event.
    Graph in between first and last event is 0 when there are no events - not interpolated.
    See attachment.

    3 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Search UI and Language  ·  Flag idea as inappropriate…  ·  Admin →
  11. Issue when using special charecters in query

    Issue with special characters in query:
    when a query contains a special character the query reports an error "the remote server returned an error:(400) Bad Request"

    query example: Type=ConfigurationChange ConfigChangeType="Software" SoftwareType="Application" and SoftwareName=µTorrent

    3 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Search UI and Language  ·  Flag idea as inappropriate…  ·  Admin →
  12. Right Click Paste

    The right click menu is missing paste in the new Log Analytics blade and the Log Analytics advanced portal. Copy and Cut are there, no paste.

    3 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Search UI and Language  ·  Flag idea as inappropriate…  ·  Admin →
  13. Choose Width of Filter Slicer

    You should be able to change the width of the filter slicer on the Search page or it should be expandable between 3 sizes (collapse, mini, full screen width) , similar to the experience in the Azure portal for blades.

    3 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Search UI and Language  ·  Flag idea as inappropriate…  ·  Admin →
  14. Ignore the mouse (until click) when suggesting searches

    Ignore the mouse over suggestions in the search field, unless an option is clicked. When typing in a search query, I hit enter to execute the search and OMS selects one of it's suggested options because the mouse happened to be left in the middle of the screen.

    3 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Search UI and Language  ·  Flag idea as inappropriate…  ·  Admin →
  15. Ability to disable automatic search history dropdown

    As my searches get more complex and I am using the search function to investigate the automatic history drop down is frustrating as it covers the results, requiring me to click in another part of the window to get it to go away.

    3 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Search UI and Language  ·  Flag idea as inappropriate…  ·  Admin →
  16. Ability to use back button to navigate back to previous query in Azure Log Analytics

    Currently the back button can't be used to navigate back to the last query in the new Azure Portal log analytics interface.
    There is no way of navigating back to a previous query which would be very useful if drilling down into a query and then wanting to revert.

    3 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Search UI and Language  ·  Flag idea as inappropriate…  ·  Admin →
  17. Editor for Favorites

    Need an editor for changing a favorite without the need having to delete it and recreate it.

    3 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Search UI and Language  ·  Flag idea as inappropriate…  ·  Admin →
  18. "internal server error" for search Type=SecurityEvent TimeGenerated>NOW-24Hours

    Similar search work for other Types. This one generates and internal sever error.

    3 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    under review  ·  1 comment  ·  Search UI and Language  ·  Flag idea as inappropriate…  ·  Admin →
  19. Bug with saved queries containing a plus sign

    When I open in Log Search a saved query that contains a '+' sign, it does not load correctly, ommiting the '+' and thus generating a syntax error (please see attached file)

    2 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Search UI and Language  ·  Flag idea as inappropriate…  ·  Admin →
  20. Table view of a Measure should include all groups

    Table view only displays the first column of multiple groupings. Example:
    Type:W3CIISLog | measure sum(TimeTaken) as TotalTime by sSiteName, csUriStem
    Click Table view.
    The column sSiteName shows up in Table view but csUriStem does not.

    2 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Search UI and Language  ·  Flag idea as inappropriate…  ·  Admin →
  • Don't see your idea?

Feedback and Knowledge Base