Log Analytics

Welcome to the "Azure Log Analytics ":https://azure.microsoft.com/en-us/services/log-analytics/ Feedback page. We appreciate your feedback and look forward to hearing from you. Use this site for new ideas and bug reports or to request help.
NOTE – Log Analytics is now a part of Operations Management Suite. Learn more at http://microsoft.com/OMS

How can we improve Azure Log Analytics ?

You've used all your votes and won't be able to post a new idea, but you can still search and comment on existing ideas.

There are two ways to get more votes:

  • When an admin closes an idea you've voted on, you'll get your votes back from that idea.
  • You can remove your votes from an open idea you support.
  • To see ideas you have already voted on, select the "My feedback" filter and select "My open ideas".
(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can support and comment on it.

If it doesn't exist, you can post your idea so others can support it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. OMS agent for macOS

    I'd like to be able to push syslog and other data data from macOS to Log Analytics, however there is not OMS agent for macOS.

    76 votes
    Vote
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
      Password icon
      Signed in as (Sign out)
      You have left! (?) (thinking…)
    • Multihome agents

      It would be fantastic if we could multihome agents to various workspaces.
      Right now we use the SCOM agent to connect to OMS, which means one OMS workspace. But we would like to have multiple workspaces depending on type of server (eg Production servers, Dev servers, application servers etc).
      I understand we can multihome OMS to different workspaces by multihoming the SCOM agent to different SCOM management groups, but having an entire management group set up just so agents can talk to different OMS workspaces is like swatting a fly with a sledgehammer.
      Even if we can manually configure each…

      60 votes
      Vote
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
        Password icon
        Signed in as (Sign out)
        You have left! (?) (thinking…)
      • Allow me to remove managed systems (Management Groups and Directly Connected Servers/Agents) from Usage page

        Implements a feature to remove managed ( Management Groups and to Directly Connected Servers ) Overview Usage from want? I think even if servers Connected Directly, the agent is uninstalled, cannot be removed from Operational Insights Usage. Cannot disconnect in the SCOM Management Groups are for the Operational Insights on want to remove.

        41 votes
        Vote
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
          Password icon
          Signed in as (Sign out)
          You have left! (?) (thinking…)

          In the current implementation, Management groups CAN already be removed, but only once they are ‘stale’ == have not reported ANY data for >14days, the link to remove will appear.

          The number of Directly reporting agents in ‘settings’ page is the actual number of servers registered, but the drill down will take you to search (where servers presence is inferred from the data).

          We will be working on options to de-register directly connected servers, similarly to we offer for SCOM management groups.

        • Fix Bug in Agent

          We started seeing this error after installing the OMS agent on our servers.

          An unmarshaling policy check was performed when unmarshaling a custom marshaled object and the class {45FB4600-E6E8-4928-B25E-50476FF79425} was rejected.

          A quick search on the internet shows other people have the same error after installing the OMS agent also.

          38 votes
          Vote
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
            Password icon
            Signed in as (Sign out)
            You have left! (?) (thinking…)

            We’re aware of an issue that can cause this error to be logged when the Update Assessment solution is installed.
            You can check if this is what you’re seeing my temporarily removing the Update Assessment solution and confirming the errors stop.

            The Update Assessment solution functionality is not affected and you can safely ignore this error.

          • Disable Agent Data Collection from OMS Portal

            Allow to enable/disable/schedule data collection of specific agents. This allows keeping data volume down during tests (e.g. pen or security testing) that might generate lots of events that could you go over the licensed data collection threshold. Maybe combinable with OMS Alert supression.

            31 votes
            Vote
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
              Password icon
              Signed in as (Sign out)
              You have left! (?) (thinking…)
            • Surface hub cannot connect to OMS using a proxy

              we documented at https://technet.microsoft.com/en-us/itpro/surface-hub/monitor-surface-hub?f=255&MSPPError=-2147217396:

              Note
              Surface Hub does not currently support the use of a proxy server to communicate with the OMS service.

              However, in most customer environment a proxy cannot be bypassed. This limitiation must be changed to allow the SurfaceHub OMS Agent to communicate with the OMS Workspace over a Proxy.

              17 votes
              Vote
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
                Password icon
                Signed in as (Sign out)
                You have left! (?) (thinking…)
              • Push\Install of Microsoft Monitoring Agent from OMS

                If you really want this to be used for stand alone clients, which I think is a great idea for the hybrid cloud, there needs to be an easier way to get the agent installed on those devices.

                12 votes
                Vote
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                  Password icon
                  Signed in as (Sign out)
                  You have left! (?) (thinking…)
                • Control when Advisor MPs are downloaded

                  We need to control when Advisor MPs are introduced to our environment to prevent possible outages during production business hours. It would be nice to set a maintenance windows to control when changes are introduces. It would also be beneficial to be able to introduce the MPs to pre-Prod prior to Prod environments.

                  10 votes
                  Vote
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                    Password icon
                    Signed in as (Sign out)
                    You have left! (?) (thinking…)

                    Hi, we are discussing this internally.

                    Today you have a way to do this, by overriding the rules that perform MP/IP download and import – there is an override MP here http://blogs.technet.com/b/momteam/archive/2015/02/06/notice-upcoming-url-change-for-opsmgr-reporting-to-opinsights.aspx
                    - you could keep them turned off in PROD and leave them enabled in QA/TEST – once you see a new MP has been updated in the test environment, you can remove the override in prod/let the update run/then block it again.

                    We are determining how to make this more polished.
                    Also see the similar idea http://feedback.azure.com/forums/267889-azure-operational-insights/suggestions/7161777-intelligence-pack-updates

                  • SCOM-OMS prerequisites checker tool

                    Tool which can be used to do prerequisite check for connection between Agent/MS and OMS.
                    Based on firewall requirements:
                    https://technet.microsoft.com/en-us/library/mt484101.aspx
                    including option for Proxy server and Proxy user account.
                    It would be a great help for deployment and troubleshooting scenarios.

                    10 votes
                    Vote
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                      Password icon
                      Signed in as (Sign out)
                      You have left! (?) (thinking…)
                    • The health service HTTP module exceeded number of attempts to post data

                      Trying to configure the OMS/SCOM integration.. but the above error comes into the eventlog.. in the PerfMon i see continuous spikes of the system trying to send data..
                      not sure if the URL is correct.. but unknown where to configure it:
                      The health service HTTP module exceeded number of attempts to post data URL: https://.ods.opinsights.azure.com/ProtectionStatusDataService.svc/PostDataItems. Dropping data batch.

                      System

                      - Provider

                      [ Name] HealthService

                      - EventID 2136

                      [ Qualifiers] 32768

                      Level 2

                      Task 0

                      Keywords 0x80000000000000

                      10 votes
                      Vote
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                        Password icon
                        Signed in as (Sign out)
                        You have left! (?) (thinking…)
                      • Update required for Amazon Linux to current version  

                        Using OMS with Amazon Linux, last supported version is 2012.09 --> 2015.09 (x86/x64). Newer version of Amazon Linux required for reporting into OMS

                        9 votes
                        Vote
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                          Password icon
                          Signed in as (Sign out)
                          You have left! (?) (thinking…)
                        • MSI-based Windows agent for Intune compatibility

                          OMS Windows agent as MSI installer rather than a .exe setup. This enables the agent to be directly deployable wo Windows 10 devices through Intune and OMA-DM.

                          8 votes
                          Vote
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                            Password icon
                            Signed in as (Sign out)
                            You have left! (?) (thinking…)
                          • Microsoft.IntelligencePacks.Advisor.Monitoring not importing.

                            I've just onboarded our SCOM 2012 R2 environment onto OMS and I'm continually receiving the following error. The Management group is UR7.

                            Failed to import the latest Advisor Management Packs to the Management Server. Reason: System.ArgumentException: The requested management pack is not valid. See inner exception for details.
                            Parameter name: managementPack ---> Microsoft.EnterpriseManagement.Common.ManagementPackException: Verification failed with 1 errors:
                            -------------------------------------------------------
                            Error 1:
                            Found error in 2|Microsoft.IntelligencePacks.Advisor.Monitoring/31bf3856ad364e35|7.0.10038.0|Microsoft.IntelligencePacks.Advisor.Monitoring|| with message:
                            Could not load management pack [ID=Microsoft.IntelligencePacks.Monitoring, KeyToken=31bf3856ad364e35, Version=7.0.10038.0]. The management pack was not found in the store.
                            : An error occurred while loading management pack 3478205f-b521-8bc4-b69b-67ac2759516d from the database

                            -------------------------------------------------------
                            ---> Microsoft.EnterpriseManagement.Common.ManagementPackException: Could…

                            7 votes
                            Vote
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                              Password icon
                              Signed in as (Sign out)
                              You have left! (?) (thinking…)
                            • Support for OpenSSL 1.1.*

                              Please add support for the latest major version of OpenSSL 1.1.* for Linux. Now I am not able to install the agent for Linux because I don't have supported version of OpenSSL (requires 0.9.8*, 1.0.*, I have 1.1.0h).

                              6 votes
                              Vote
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                                Password icon
                                Signed in as (Sign out)
                                You have left! (?) (thinking…)
                              • Ability to define a "friendly"name for machines reporting into Azure Opperational Insights

                                In our scenario as a ISV we have many machines at different customer sites that have the same machine name. It would be extremely helpful if we were able to provide a friendly name or a description for machines reporting into the Azure Operational Insights Console.

                                5 votes
                                Vote
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                  Password icon
                                  Signed in as (Sign out)
                                  You have left! (?) (thinking…)
                                • Upgrade the version of the ruby bundled with the Linux oms agent

                                  A lot of FluentD plugins depend on the activesupport gem, which in turn depends on a Ruby version >= 2.2.2. This Ruby version in particular solves a nasty security bug related to SSL.

                                  The OMS agent bundles a Ruby interpreter version prior to 2.2.2, which prevents us from using a lot of useful fluentd plugins.

                                  5 votes
                                  Vote
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                    Password icon
                                    Signed in as (Sign out)
                                    You have left! (?) (thinking…)
                                  • ports

                                    Hi, integrating on prem SCOM suggests that it is trying to establish connection to https://seau.data.opinsights.azure.com/Data/DataProviderService.svc which is not specified in the proxy and firewall list o sites. Is this a recent change?

                                    4 votes
                                    Vote
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                      Password icon
                                      Signed in as (Sign out)
                                      You have left! (?) (thinking…)
                                    • Allow to deploy agent using GPO

                                      I know there is way to deploy agent with workspace details but this requires to use the setup.exe file
                                      Can you please provide a way to deploy with GPO?
                                      thanks

                                      4 votes
                                      Vote
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                        Password icon
                                        Signed in as (Sign out)
                                        You have left! (?) (thinking…)

                                        You have a few options today:

                                        - startup scripts from GPO’s would be the most generic way to install and configure the agent. Command line to silent install as well as script snippets on how to enable/disable/configure thru COM API are documented here https://azure.microsoft.com/en-us/documentation/articles/operational-insights-direct-agent/

                                        - Powershell magazine came up with a DSC module that allows you to install the agent that way http://www.powershellmagazine.com/2014/11/26/dsc-resource-module-for-microsoft-monitoring-agent-install-and-configuration-for-azure-operational-insights/

                                        - if the machines are in Azure, there is a VM extension http://azure.microsoft.com/en-us/updates/easily-enable-operational-insights-for-azure-virtual-machines/

                                      • Service Connector fails with http error 12044L

                                        As described in the forums (https://social.msdn.microsoft.com/Forums/azure/en-US/196833f0-bc21-4301-b982-3146a1615877/connecting-agent-gives-http-error-12044l?forum=opinsights), on some machines the agent fails with an error HTTP error 12044L on domain joined machines. Error log attached, I scraped the workplace ID but feel free to take contact for details.

                                        3 votes
                                        Vote
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                          Password icon
                                          Signed in as (Sign out)
                                          You have left! (?) (thinking…)

                                          Thanks, from the trace it appears that creating the key for the self-signed certificate is failing.

                                          We reached out to you in email to better understand how your machine’s configuration looks like, and what’s causing this odd error.

                                        • Log Analytics not supported SCOM 2012R2 UR7 servers

                                          Giving me error MMA agent can not be installed on SCOM servers, as I am trying to install MMA latest version which is downloaded from OMS since there is no option to add workspace ID in MMA agent. Please add this features so that OMS can connect to SCOM servers as well.

                                          3 votes
                                          Vote
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                            Password icon
                                            Signed in as (Sign out)
                                            You have left! (?) (thinking…)
                                          ← Previous 1
                                          • Don't see your idea?

                                          Feedback and Knowledge Base