Exploring Log Analytics
Monitor and Troubleshoot Azure Solutions
Ebadur Osib
Senior Cloud Consulting Engineer
Logs everywhere
Log analytics workspace
What is log analytics workspace
Central data store for logs.
Azure data explore engine.
Workspace supports KQL.
Works across subscriptions and resource groups.
Foundation of Azure monitor.
Why it matters
Without a workspace:
Logs stored in separate places.
Hard to correlate issues.
Slow incident response.
With a workspace:
Provides a unified view.
End-to-end tracing.
Faster root cause analysis.
What data can you send?
Activity logs
Resource metrics
Application insights traces
Container logs
Network logs
Exploring logs in the workspace
Query tables to explore and investigate.
Filter by time, resource, or type.
Uncover patterns and anomalies across environments.
1
https://learn.microsoft.com/en-us/azure/azure-monitor/logs/log-excel
The login mystery
The login mystery
Introduction to KQL
Language for interacting with logs.
Fast and read-only.
Helps you:
Filter
Correlate
Summarize
Visualize
Summary
Let's practice!
Monitor and Troubleshoot Azure Solutions
Preparing Video For Download...