How can we improve Azure Log Analytics ?

Allow us to filter deduped data set (* | dedup * | where ??)

Ok now with dedup we can almost achieve the "last data point by Computer" scenario, but we cannot use where after dedup as in: Type:Heartbeat | dedup Computer | where TimeGenerated < NOW-10MINUTE
Just add the ability to use "| where" to process the deduped data set.

10 votes
Vote
Sign in
(thinking…)
Sign in with: Microsoft
Signed in as (Sign out)
You have left! (?) (thinking…)
Daniele shared this idea  ·   ·  Flag idea as inappropriate…  ·  Admin →

3 comments

Sign in
(thinking…)
Sign in with: Microsoft
Signed in as (Sign out)
Submitting...
  • Terry C commented  ·   ·  Flag as inappropriate

    Definitely agree with Daniele. Such feature is a 'MUST HAVE' otherwise we cannot adopt Azure Log Analytics for our business.
    Terry

  • Mickaël M. commented  ·   ·  Flag as inappropriate

    I would like to use the measure command on deduplicated data.
    Example: Type:CustomData_CL | dedup Organization_s | measure count(State_s) by Organization_s

  • Stefan commented  ·   ·  Flag as inappropriate

    We are using custom fields. After getting the last data item of a specific type and field, via dedup or max(Timegenerated), we want to filter on certain value of a specific custom field. So after getting the last data samples we need to filter for a certain value in these last data samples.

Feedback and Knowledge Base