SOLVED
Home

Single vs. multiple instances of Log Analytics

%3CLINGO-SUB%20id%3D%22lingo-sub-116960%22%20slang%3D%22en-US%22%3ESingle%20vs.%20multiple%20instances%20of%20Log%20Analytics%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-116960%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20multiple%20client%20environments%20streaming%20data%20to%20Log%20Analytics.%26nbsp%3B%20What%20are%20the%20pros%20and%20cons%20to%20use%20a%20single%20instance%20versus%20individual%20instnaces%20of%20Log%20Analytics.%20Please%20point%20me%20to%20the%20business%20benefits%20.%20Thank%20you.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-116960%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20Log%20Analytics%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-352795%22%20slang%3D%22en-US%22%3ERe%3A%20Single%20vs.%20multiple%20instances%20of%20Log%20Analytics%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-352795%22%20slang%3D%22en-US%22%3E%3CP%3EOther%20reason%20for%20multiple%20workspaces%20are%20the%20data%20retention%20and%20cost%20impact.%20Some%20data%20you%20need%202%20years%2C%20other%20only%20form%20the%20last%2030%20days%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-119435%22%20slang%3D%22en-US%22%3ERe%3A%20Single%20vs.%20multiple%20instances%20of%20Log%20Analytics%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-119435%22%20slang%3D%22en-US%22%3EHi%2C%20There%20isn't%20reference%20architecture%20or%20model%20when%20you%20have%20multiple%20workspaces.%20It%20depends%20on%20your%20scenario%20and%20requirements%20why%20would%20you%20have%20multiple%20workspaces%20and%20how%20you%20will%20use%20them.%20The%20agent%20even%20supports%20connecting%20to%20multiple%20workspaces%20so%20you%20could%20even%20have%20different%20solutions%20enabled%20on%20different%20workspaces%20for%20the%20same%20server.%20It%20really%20depends%20on%20your%20scenarios%20and%20your%20requirements.%20The%20steps%20below%20are%20not%20something%20that%20applies%20to%20Log%20Analytics.%20Log%20Analytics%20is%20an%20Azure%20service.%20As%20an%20Azure%20service%20you%20will%20need%20to%20have%20Azure%20Subscription.%20Inside%20your%20Azure%20subscription%20you%20choose%20to%20deploy%20Log%20Analytics%20with%20name%20and%20region.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-119234%22%20slang%3D%22en-US%22%3ERe%3A%20Single%20vs.%20multiple%20instances%20of%20Log%20Analytics%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-119234%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%20Thanks%20for%20sharing%20the%20pros%20and%20cons%20of%20having%20a%20shared%20Log%20Analytics%20instance%20versus%20multiple%20workspaces%20for%20unique%2Findividual%20client%20needs.%20In%20the%20case%20with%20multiple%20Log%20Analytics%20workspaces%2C%20can%20you%20please%20share%20the%20reference%20model%2Farchitecture%20that%20meet%20these%20needs%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFrom%20my%20perspective%2C%20I%20think%20we%20need%20to%20consider%20the%20following%20steps%20for%20the%20first%20client%20setup%20and%20repeat%20step%202%20through%20step%204%20for%20the%20next%20cleint%20%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3COL%3E%3CLI%3EHave%20an%20Azure%20subscription.%3C%2FLI%3E%3CLI%3EChoose%20a%20workspace%20name.%3C%2FLI%3E%3CLI%3EAssociate%20the%20workspace%20with%20the%20subscription.%3C%2FLI%3E%3CLI%3EChoose%20a%20geographical%20location.%3C%2FLI%3E%3C%2FOL%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F9172%22%20target%3D%22_blank%22%3E%40Stanislav%20Zhelyazkov%3C%2FA%3E%26nbsp%3Bcan%20you%20please%20validate%20the%20architecture%20and%20process%3F%20Thank%20you.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-117192%22%20slang%3D%22en-US%22%3ERe%3A%20Single%20vs.%20multiple%20instances%20of%20Log%20Analytics%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-117192%22%20slang%3D%22en-US%22%3EHi%20I%20see%20your%20pain.%20To%20customize%20pages%20currently%20you%20will%20have%20to%20do%20some%20work.%20Obviously%20currently%20to%20segregate%20data%20you%20can%20use%20functions%20(previously%20compute%20groups).%20Based%20on%20functions%20you%20can%20show%20data%20for%20different%20apps%2C%20servers%2C%20etc.%20To%20visualize%20that%20data%20you%20can%20use%20Azure%20Dashboards%20or%20View%20Designer.%20Of%20course%20you%20will%20have%20to%20create%20separate%20dashboards%20for%20each%20group%20which%20is%20not%20an%20easy%20work%20if%20there%20many%20of%20them%20and%20of%20course%20it%20does%20not%20work%20with%20built-in%20views.%20View%20designer%20recently%20introduced%20some%20filtering%20capabilities%20so%20hopefully%20at%20some%20point%20they%20will%20enable%20the%20possibility%20to%20choose%20particular%20function%20and%20visualize%20the%20data%20based%20on%20its%20scope.%20Also%20hopefully%20they%20will%20do%20that%20for%20the%20built-in%20views.%20I've%20been%20giving%20that%20feedback%20for%20quite%20some%20time%20so%20I%20hope%20they%20will%20implement%20it.%20On%20segregating%20data%20based%20on%20RBAC%20I%20not%20so%20fond%20in%20such%20solution.%20I%20think%20if%20there%20is%20no%20some%20regulatory%20compliance%20to%20hide%20data%20between%20different%20teams%20I%20think%20all%20teams%20should%20see%20the%20data.%20Problems%20are%20resolved%20between%20teams%20and%20working%20in%20collaboration%20rather%20silos.%20If%20there%20is%20problem%20with%20SQL%20it%20may%20happen%20that%20the%20problem%20starts%20within%20the%20OS%20rather%20SQL%20itself.%20This%20is%20just%20one%20example.%20So%20in%20that%20case%20if%20you%20cannot%20cope%20with%20the%20above%20two%20currently%20you%20would%20go%20with%20more%20than%20one%20workspace%20but%20you%20will%20loose%20overall%20visibility%20of%20our%20envrionment.%20You%20can%20do%20cross%20worksapce%20queries%20but%20that%20is%20only%20in%20the%20Analytics%20portal%20and%20up%20to%2010%20workspaces.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-117179%22%20slang%3D%22en-US%22%3ERe%3A%20Single%20vs.%20multiple%20instances%20of%20Log%20Analytics%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-117179%22%20slang%3D%22en-US%22%3E%3CP%3EInteresting%20question%20which%20I%20also%20gave%20quite%20some%20thought.%20There%20is%20no%20doubt%20a%20single%20instance%20is%20easier.%20However%2C%20there%20are%20two%20issues%20I%20have%20in%20an%20(large)%20enterprise%20environment.%3CBR%20%2F%3EI%20need%20to%20separate%20the%20different%20operate%20groups%20such%20as%20DBA%2C%20Server%20Ops%2C%20Security.%20They%20all%26nbsp%3Bneed%20their%20own%2C%20customized%20home%20page%20in%20OMS.%20I%20don't%20see%20how%20I%20can%20manage%20that%20in%20the%20same%20workspace%2C%20the%20RBAC%20is%20not%20that%20sophisticated.%3CBR%20%2F%3EThe%20other%20issues%20is%20the%20amount%20of%20data%20in%20the%20individual%20instances%20and%20the%20complexity%20of%20the%20workspaces.%20DBAs%20only%20want%20data%20and%20solutions%20related%20to%20certain%20Azure%20Resource%20Types%2C%20they%20have%20no%20interest%20in%20e.g.%20Windows%20event%20logs%20and%20VM%20related%20solutions.%26nbsp%3BSecurity%20might%20also%20require%20a%20much%20longer%20retention%20time%20then%20operations.%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20smaller%20environments%20I%20tend%20to%20use%20a%20single%20workspace%2C%20but%20in%20larger%20ones%20I'm%20leaning%20towards%20multiple%20workspaces.%20Any%20thoughts%20on%20that%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-117093%22%20slang%3D%22en-US%22%3ERe%3A%20Single%20vs.%20multiple%20instances%20of%20Log%20Analytics%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-117093%22%20slang%3D%22en-US%22%3EWith%20single%20instance%20you%20will%20have%20to%20manage%20RBAC%20only%20on%20that%20instance%20with%20multiple%20you%20will%20have%20the%20burden%20to%20manage%20it%20on%20all%20of%20them.%20If%20you%20need%20to%20create%20a%20query%20that%20goes%20across%20multiple%20workspaces%20you%20will%20have%20to%20explicitly%20write%20in%20the%20query%20the%20workspaces%20you%20want%20to%20query.%20If%20you%20do%20not%20have%20any%20regulatory%20reasons%20to%20keep%20data%20in%20multiple%20workspaces%20I%20would%20suggest%20to%20move%20to%20a%20single%20one.%20The%20more%20data%20you%20have%20the%20better%20analysis%20you%20can%20do%20on%20your%20data.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-116991%22%20slang%3D%22en-US%22%3ERE%3A%20Single%20vs.%20multiple%20instances%20of%20Log%20Analytics%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-116991%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Avijeet%2C%20I'm%20started%20to%20use%20multiples%20instances%20for%20my%20clients.%20But%20latest%20the%20resource%20%22Computer%20Groups%22%20is%20launched%20I%20have%20trying%20to%20use%20my%20costumers%20on%20single%20instance.%20After%20that%20I%20am%20keeping%20my%20alerts%20so%20identified.%20Recently%20I%20think%20we%20will%20can%20associate%20a%20selected%20type%20of%20license%20to%20a%20determined%20costumer.%20It%60s%20will%20be%20great%20to%20use%20one%20environment%20to%20me%20on%20terms%20of%20administration.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Avijeet Ghose
New Contributor

I have multiple client environments streaming data to Log Analytics.  What are the pros and cons to use a single instance versus individual instnaces of Log Analytics. Please point me to the business benefits . Thank you.

7 Replies

Hi Avijeet, I'm started to use multiples instances for my clients. But latest the resource "Computer Groups" is launched I have trying to use my costumers on single instance. After that I am keeping my alerts so identified. Recently I think we will can associate a selected type of license to a determined costumer. It`s will be great to use one environment to me on terms of administration.

Solution
With single instance you will have to manage RBAC only on that instance with multiple you will have the burden to manage it on all of them. If you need to create a query that goes across multiple workspaces you will have to explicitly write in the query the workspaces you want to query. If you do not have any regulatory reasons to keep data in multiple workspaces I would suggest to move to a single one. The more data you have the better analysis you can do on your data.

Interesting question which I also gave quite some thought. There is no doubt a single instance is easier. However, there are two issues I have in an (large) enterprise environment.
I need to separate the different operate groups such as DBA, Server Ops, Security. They all need their own, customized home page in OMS. I don't see how I can manage that in the same workspace, the RBAC is not that sophisticated.
The other issues is the amount of data in the individual instances and the complexity of the workspaces. DBAs only want data and solutions related to certain Azure Resource Types, they have no interest in e.g. Windows event logs and VM related solutions. Security might also require a much longer retention time then operations. 

In smaller environments I tend to use a single workspace, but in larger ones I'm leaning towards multiple workspaces. Any thoughts on that?

Hi I see your pain. To customize pages currently you will have to do some work. Obviously currently to segregate data you can use functions (previously compute groups). Based on functions you can show data for different apps, servers, etc. To visualize that data you can use Azure Dashboards or View Designer. Of course you will have to create separate dashboards for each group which is not an easy work if there many of them and of course it does not work with built-in views. View designer recently introduced some filtering capabilities so hopefully at some point they will enable the possibility to choose particular function and visualize the data based on its scope. Also hopefully they will do that for the built-in views. I've been giving that feedback for quite some time so I hope they will implement it. On segregating data based on RBAC I not so fond in such solution. I think if there is no some regulatory compliance to hide data between different teams I think all teams should see the data. Problems are resolved between teams and working in collaboration rather silos. If there is problem with SQL it may happen that the problem starts within the OS rather SQL itself. This is just one example. So in that case if you cannot cope with the above two currently you would go with more than one workspace but you will loose overall visibility of our envrionment. You can do cross worksapce queries but that is only in the Analytics portal and up to 10 workspaces.

Hi, Thanks for sharing the pros and cons of having a shared Log Analytics instance versus multiple workspaces for unique/individual client needs. In the case with multiple Log Analytics workspaces, can you please share the reference model/architecture that meet these needs?

 

From my perspective, I think we need to consider the following steps for the first client setup and repeat step 2 through step 4 for the next cleint :

 

  1. Have an Azure subscription.
  2. Choose a workspace name.
  3. Associate the workspace with the subscription.
  4. Choose a geographical location.

@Stanislav Zhelyazkov can you please validate the architecture and process? Thank you.

Hi, There isn't reference architecture or model when you have multiple workspaces. It depends on your scenario and requirements why would you have multiple workspaces and how you will use them. The agent even supports connecting to multiple workspaces so you could even have different solutions enabled on different workspaces for the same server. It really depends on your scenarios and your requirements. The steps below are not something that applies to Log Analytics. Log Analytics is an Azure service. As an Azure service you will need to have Azure Subscription. Inside your Azure subscription you choose to deploy Log Analytics with name and region.

Other reason for multiple workspaces are the data retention and cost impact. Some data you need 2 years, other only form the last 30 days