Getting data from Endpoint analytics e.g., Startup performance into a Log Analytics Workspace

G Cole 1 Reputation point
2022-11-18T01:19:11.01+00:00

Hi,

I'm trying to setup alerts from an Azure monitor "Log Analytics Workspace", based on ingesting "Endpoint" analytics metrics: "Startup Performance" and "Application Reliability".

I have been unsuccessful in finding any relevant links, tutorials, guides or video's describing how to set this up. Hoping someone can describe the process? We basically just want an alert fired if a normal user workstation crashes 5 times in 1 week for example, or if outlook is crashing 10 times in 1 week.

An alert should be triggered/fired to send the help desk an email which will raise a ticket (ITSM). I cannot see any tables with relevant data in the "Log Analytics Workspace" or find a schema diagrams to show me what tables to query via GQL. Any advice would be really appreciated.

From:

261661-img1.png

To:

261637-img2.png

Cheers.

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
3,013 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Maxim Sergeev 6,566 Reputation points Microsoft Employee
    2022-11-18T02:19:44.72+00:00

    Hi there,

    AFAIK, this data isn't available as a part of Diagnostics Setting telemetry for Intune.
    This is a guide how to enable the integration https://learn.microsoft.com/en-us/mem/intune/fundamentals/review-logs-using-azure-monitor

    But it collects the following data only:

    Microsoft Intune includes built-in logs that provide information about your environment:

    Audit Logs shows a record of activities that generate a change in Intune, including create, update (edit), delete, assign, and remote actions.
    Operational Logs show details on users and devices that successfully (or failed) to enroll, and details on non-compliant devices.
    Device Compliance Organizational Logs show an organizational report for device compliance in Intune, and details on non-compliant devices.
    IntuneDevices show device inventory and status information for Intune enrolled and managed devices.

    Btw, you can try to request a feature via a support case.

    0 comments No comments