Share via

DCR Transformation Not Affecting Data Ingested via Azure Monitor Agent

Nimmala Anveshreddy 3,560 Reputation points Moderator
2024-10-03T09:23:23.27+00:00

Why is my DCR transformation at the table level in Log Analytics workspace not affecting the data ingested via the Azure Monitor Agent into the Common Security Log table?

PS - Based on common issues that we have seen from customers and other sources, we are posting these questions to help the Azure community.

Azure Monitor
Azure Monitor

An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.

0 comments No comments

1 answer

Sort by: Most helpful
  1. Nimmala Anveshreddy 3,560 Reputation points Moderator
    2024-10-03T09:27:08.71+00:00

    When you apply a Data Collection Rule (DCR) transformation at the table level within your Log Analytics workspace, this method does not impact logs collected via the Azure Monitor Agent (AMA). This table-level transformation method supports logs collected through other methods such as Diagnostic Settings or the legacy Microsoft Monitoring Agent (MMA) or OMS agent. To correctly apply transformations to data being ingested via the Azure Monitor Agent, you need to modify the DCR at the DCR level.

    Here are the steps to resolve this issue: 1. Go to the Data Collection Rule (DCR) that is configured to ingest the security logs. 2. Modify the DCR to apply the required transformation directly within the DCR.

    Here is a video tutorial to guide through this process: YouTube Video Tutorial.

    For further details, refer to the following resources: - Azure Monitor Logs Ingestion Time Transformations

    Please do not forget to "Accept the answer" and "up-vote" wherever the information provided helps you, as this can be beneficial to other community members.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.