search
Get Started
search
AZ

Azure Log Analytics

language

description Azure Log Analytics Overview

Azure Log Analytics is a cloud-based analytics service within Microsoft Azure. It processes logs and performance data from various sources including virtual machines, applications, and network devices. The system utilizes the Kusto Query Language for powerful data exploration and analysis. It’s primarily used by IT professionals, security analysts, and developers seeking to monitor, troubleshoot, and gain insights into their systems and applications.

help Azure Log Analytics FAQ

What query language does Azure Log Analytics use?

Azure Log Analytics uses Kusto Query Language (KQL), a powerful, read-only query language designed specifically for high-performance data exploration. It allows users to easily parse, filter, and aggregate massive volumes of telemetry and log data.

Can I send Active Directory logs to Azure Log Analytics?

Yes, you can connect Azure Active Directory (now known as Microsoft Entra ID) diagnostic settings to send sign-in logs and audit logs directly to a Log Analytics workspace. This allows security teams to actively query user behavior and build alerting rules within Azure Monitor.

How long does Azure Log Analytics retain data by default?

By default, Azure Log Analytics retains interactive data for 31 days for most subscription tiers. You can configure the retention period up to 730 days (or up to 12 years using Archive and Basic logs) depending on your specific compliance requirements.

Reviews & Comments

Write a Review

rate_review

Be the first to review

Share your thoughts with the community and help others make better decisions.

Save to your list

Save your favorites and follow how their scores change over time.

Save favorites
Track changes
Compare scores

Already have an account? Sign in

Compare Items

See how they stack up against each other

Comparing
VS
Select 1 more item to compare