description Azure Log Analytics Overview
Azure Log Analytics is a cloud-based analytics service within Microsoft Azure. It processes logs and performance data from various sources including virtual machines, applications, and network devices. The system utilizes the Kusto Query Language for powerful data exploration and analysis. It’s primarily used by IT professionals, security analysts, and developers seeking to monitor, troubleshoot, and gain insights into their systems and applications.
help Azure Log Analytics FAQ
What query language does Azure Log Analytics use?
Azure Log Analytics uses Kusto Query Language (KQL), a powerful, read-only query language designed specifically for high-performance data exploration. It allows users to easily parse, filter, and aggregate massive volumes of telemetry and log data.
Can I send Active Directory logs to Azure Log Analytics?
Yes, you can connect Azure Active Directory (now known as Microsoft Entra ID) diagnostic settings to send sign-in logs and audit logs directly to a Log Analytics workspace. This allows security teams to actively query user behavior and build alerting rules within Azure Monitor.
How long does Azure Log Analytics retain data by default?
By default, Azure Log Analytics retains interactive data for 31 days for most subscription tiers. You can configure the retention period up to 730 days (or up to 12 years using Archive and Basic logs) depending on your specific compliance requirements.
explore Explore More
Similar to Azure Log Analytics
See all arrow_forwardReviews & Comments
Write a Review
Be the first to review
Share your thoughts with the community and help others make better decisions.