Forum Discussion

Rodrigo_Pereira's avatar
Rodrigo_Pereira
Copper Contributor
Aug 13, 2022

Problem collecting log files in VM's using Azure Monitor Agent - missing columns

Hi,

I'm trying to use the Azure Monitor Agent (AMA) to collect Linux log files via DCR's, into a LAW custom table. I followed the instructions in https://docs.microsoft.com/en-us/azure/azure-monitor/agents/data-collection-text-log because this is still in preview and configuring collection of log files with a DCR can't yet be done via the portal.

 

I can see data arriving into the workspace. But when I check the entries in the custom table, there is no column for "Computer", which I absolutely require to match the log with the originating VM name.

When collecting with the Log Analytics Agent (OMS), this column is populated automatically.

 

I've tried to add the Computer column explicitly when creating the custom table, and also in the DCR template definition, to no avail. With this limitation, I cannot use the AM agent.

 

Of course, I may be doing something wrong.

Any suggestion?

 

Thanks in advance 

    • Rodrigo_Pereira's avatar
      Rodrigo_Pereira
      Copper Contributor
      Hi. Thanks for the pointer. I reviewed the page, and could not find anything that matched my issue. It also does not contain any specific section regarding log file collection. The agent is running, the DCR rule was downloaded, the table in LAW is getting data that the agent tails from the log file. It's just the "Computer" column is missing.
      • Clive_Watson's avatar
        Clive_Watson
        Bronze Contributor
        It was worth a look, some of the error logs from the agent can be useful to delve into and the article is good at identifying them on the host. You may also need it to file a support ticket.

        It could be a re-install is needed (as I'd expect the Computer column to be there), I assume you have a supported Linux distro?

Resources