Kaganapan
Mar 17, 9 PM - Mar 21, 10 AM
Sumali sa serye ng meetup upang bumuo ng mga scalable AI solusyon batay sa mga kaso ng paggamit ng tunay na mundo sa mga kapwa developer at eksperto.
Magparehistro naHindi na suportado ang browser na ito.
Mag-upgrade sa Microsoft Edge para samantalahin ang mga pinakabagong tampok, update sa seguridad, at teknikal na suporta.
Log Analytics Workspace Insights provides comprehensive monitoring of your workspaces through a unified view of your workspace usage, performance, health, agent, queries, and change log. This article helps you understand how to onboard and use Log Analytics Workspace Insights.
Microsoft.OperationalInsights/workspaces/read
permissions to the Log Analytics workspace whose insights you want to see, as provided by the Log Analytics Reader built-in role, for example..*/read
permissions, as provided by the Log Analytics Reader built-in role, for example.When you access Log Analytics Workspace Insights through Azure Monitor Insights, the At scale perspective is shown. Here you can:
To start Log Analytics Workspace Insights at scale:
Sign in to the Azure portal.
Select Monitor from the left pane in the Azure portal. Under the Insights Hub section, select Log Analytics Workspace Insights.
You can use insights in the context of a specific workspace to display rich data and analytics of the workspace performance, usage, health, agents, queries, and changes.
To access Log Analytics Workspace Insights:
Open Log Analytics Workspace Insights from Azure Monitor (as previously explained).
Select a workspace to drill into.
Or use these steps:
In the Azure portal, select Log Analytics Workspaces.
Choose a Log Analytics workspace.
Under Monitoring, select Insights on the workspace menu.
The data is organized in tabs. The time range on top defaults to 24 hours and applies to all tabs. Some charts and tables use a different time range, as indicated in their titles.
On the Overview tab, you can see:
Main statistics and settings:
Top five tables: Charts that analyze the five most-ingested tables over the past month:
This tab provides a dashboard display.
This tab provides information on the workspace's usage. The dashboard subtab shows ingestion data displayed in tables. It defaults to the five most-ingested tables in the selected time range. These same tables are displayed on the Overview page. Use the Workspace Tables dropdown to choose which tables to display.
Main grid: Tables are grouped by solutions with information about each table:
AzureDiagnostics
and ContainerLog
alone stand for more than two-thirds (64%) of the data ingested to this workspace.Table-specific details: At the bottom of the page, you can see detailed information on the table selected in the main grid:
Ingestion volume: How much data was ingested to the table from each resource and how it spreads over time. Resources ingesting more than 30% of the total volume sent to this table are marked with a warning sign.
Ingestion latency: How much time ingestion took, analyzed for the 50th, 90th, or 95th percentiles of requests sent to this table. The top chart in this area depicts the total ingestion time of the requests for the selected percentile from end to end. It spans from the time the event occurred until it was ingested to the workspace.
The chart below it shows separately the latency of the agent, which is the time it took the agent to send the log to the workspace. The chart also shows the latency of the pipeline, which is the time it took the service to process the data and push it to the workspace.
The Additional Queries subtab exposes queries that run across all workspace tables (instead of relying on the usage metadata, which is refreshed hourly). Because the queries are much more extensive and less efficient, they don't run automatically. They can reveal interesting information about which resources send the most logs to the workspace and perhaps affect billing.
One such query is What Azure resources send most logs to this workspace (showing the top 50). In the demo workspace, you can clearly see that three Kubernetes clusters send far more data than all other resources combined. One cluster loads the workspace the most.
This tab shows the workspace health state, when it was last reported, and operational errors and warnings retrieved from the _LogOperation
table. For more information on the listed issues and mitigation steps, see Monitor health of a Log Analytics workspace in Azure Monitor.
This tab provides information on the agents that send logs to this workspace.
_LogOperation
table through the Logs experience to see the raw data and analyze it further.Query auditing creates logs about the execution of queries on the workspace. If enabled, this data is beneficial to understanding and improving the performance, efficiency, and load for queries. To enable query auditing on your workspace or learn more about it, see Audit queries in Azure Monitor Logs.
This tab shows:
The Slow & Inefficient Queries subtab shows two grids to help you identify slow and inefficient queries you might want to rethink. These queries shouldn't be used in dashboards or alerts because they'll create unneeded chronic load on your workspace.
The Users subtab shows user activity against this workspace:
This tab shows configuration changes made on the workspace during the last 90 days regardless of the time range selected. It also shows who made the changes. It's intended to help you monitor who changes important workspace settings, such as data capping or workspace license.
To learn the scenarios that workbooks are designed to support and how to author new and customize existing reports, see Create interactive reports with Azure Monitor workbooks.
Kaganapan
Mar 17, 9 PM - Mar 21, 10 AM
Sumali sa serye ng meetup upang bumuo ng mga scalable AI solusyon batay sa mga kaso ng paggamit ng tunay na mundo sa mga kapwa developer at eksperto.
Magparehistro naPagsasanay
Module
Create and configure a Log Analytics workspace - Training
In this module, you learn how to create and configure access to a Log Analytics workspace. You also learn how to configure data retention and to enable health status alerts for a Log Analytics workspace.
Sertipikasyon
Microsoft Certified: Information Protection and Compliance Administrator Associate - Certifications
Demonstrate the fundamentals of data security, lifecycle management, information security, and compliance to protect a Microsoft 365 deployment.
Dokumentasyon
Monitor operational issues logged in your Azure Monitor Log Analytics workspace - Azure Monitor
The article describes how to monitor the health of your Log Analytics workspace by using data in the Operation table.
Monitor Log Analytics workspace health - Azure Monitor
This article how to monitor the health of a Log Analytics workspace and set up alerts about latency issues specific to the Log Analytics workspace or related to known Azure service issues.
Log Analytics workspace overview - Azure Monitor
Overview of Log Analytics workspace, which stores data for Azure Monitor Logs.