Azure Monitor: Unable to Create Alerts for JIT Access Events with Security Category
I am trying to create an alert to be generated when a VM JIT access request is made. While creating the alert, when I choose the signal "Initiate JIT Network Access Policy (Just-In-Time Network Access Policies)" where the signal source is of…
Problem with DRC transformation KQL when column name starts with special character
I'm trying to send custom JSON logs from VM to Log Analytics workspace using Azure Monitor Agent. Custom JSON log has couple of fields with name starting with @ character (@t, @mt). Those fields are generated by Serilog library the application is using…
Log Analytics WindowsFirewall - table transformation not working
Hello, I am collecting Windows Firewall logs via AMA from servers - that is working fine, I have ingested logs. But what I am trying to set up is transformation with DCR to collect only DROP records. Transformation KQL source | where FirewallAction !=…
How do you ignore exceptions that occur at the window level outside of the application?
not sure what to tag this post as, but we're having a problem on our web page with app insights logging an exception in production for our web application that is occurring at the window level for a user that has a chrome extension enabled. we use the…
Application Insights missing telemetry information from D365 FO
We have enabled Application Insights in D365 FO. We have enabled User sessions (Custom Events) to YES, on the Configure tab, copied the Environment Id from LCS into the Environment ID field on the Environnement tab and selected Production as the…
AMA installed by creating DCR, but did not send heartbeat to Log Analytics
I have created a DCR which will automatically install AMA to VM. In VM, validated all required exe, include MonAgentCore.exe are running. But when query heartbeat, it did not update the heartbeat. Connection to endpoint checked, no issue.
How to monitor incoming Kubernetes pod load on Azure instances?
Dear Team, We have Prometheus pods running on Azure instances and pods are getting restarted quite frequently due to some invisible load or requests. We tried troubleshooting this problem, but we are unable to see any spike in Memory/CPU/Networking on…
Is it possible to turn Application Insights off from an external source?
Is it possible to to turn off application insights remotely? I am trying to find a way (if there is any) to toggle TelemetryConfiguration.Active.DisableTelemetry = false via remote, I've been told that having an endpoint is futile because we won't…
Alert action should shut down VM, it doesn't
We have an alert rule that monitors the CPU usage of a VM and when it drops below a certain usage, shuts down the VM. – This worked well for a while, but then started working only sometimes. Although the rule was triggered, it didn't shut down the VM.…
Data diagnostic from Azure Storage Account doesn't capture RequesterID
We have enabled diagnostic on our storage account for blob data. But in the log analytics we don't see information regarding user or system that performed operation on blob. Those fields are empty. One thing to mention that we are using private endpoints…
Azure Log Analytics Query Cost Calculation
While reviewing the Azure Log Analytics Basic Table plan query costs, it states: "The charge for a query on Basic and Auxiliary tables is based on the amount of data the query scans, which depends on the size of the table and the query's time…
Migrate OMS agent to AMA agent (in terraform)
Hi, I have Azure resources managed in terraform. I'm not really a "good friend" with terraform, but I was chosen to migrate OMS agents to the new AMA agent. I know a migration guides exists, I went through it, but I either do not understand it…
Apps on AKS don't send anything to Application Insights
We are developing ASP.NET Core applications and have integrated Application Insights. When the developer in running the App locally on his mchine, AppInsigehts receives data from the app. So the integration of the package is working as expected,…
Need Help with Aggregated Metrics for Azure Container Apps
Hi, I'm trying to retrieve aggregated metrics for a group of Azure Container Apps based on a tag. Specifically, I need the total number of requests and billed duration, but I'm not using a Log Analytics workspace for metrics ingestion. I've tried using…
Why does the Azure portal tell me to "Turn on Application Insights" while I have it installed via SDK NuGet package and configured correctly?
My app has the Application Insights SDK for ASP.NET Core installed at build time via NuGet as as described in https://learn.microsoft.com/en-us/azure/azure-monitor/app/asp-net-core#enable-application-insights-server-side-telemetry-visual-studio My…
Azure REST API Create Metric Alert - Dynamic Threshold Not Working
I am using the Azure REST API to create metric alerts for Azure Monitor using dynamic thresholds. I have been successful at creating alerts with static thresholds, but not with dynamic thresholds. The docs clearly show many examples of how to create with…
Availability Sets are not supported in Azure Policy for deploying Azure Monitor Agent.
I have created a Initiative for deploying the Azure Monitor agent on a subscription. The agent is deployed on all the Windows vm's except on the machines in a availability set. The policy I'm using is "Configure Windows virtual machines to run Azure…
Migrate to Azure monitor agent from legacy agent
When I click on the Log Analytics workspace and click Settings | Agents I see my Windows computer connected via Azure Monitor Windows Agent and connected via Log Analytics Windows agent (legacy). How do I remove the Log Analytics Windows agent…
Error when running the required MigrationPrerequisites.ps1
I have installed the latest Az CLI package so I know that's not the issue. But when I run the script locally in Powershell, I can't get past this error: Write-Telemetry : Unhandled exception The term 'Invoke-AzRestMethod' is not recognized as the name…
Hey Community i am trying to create disk available alert for the Azure
hey i am trying to create alert using since the recent update on log analytics agent i am unable t create alert can someone please guide mw