Home
%3CLINGO-SUB%20id%3D%22lingo-sub-951937%22%20slang%3D%22en-US%22%3EWorking%20with%20Azure%20Storage%20diagnostic%20logs%20in%20Analytics%20Log%20Work-space%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-951937%22%20slang%3D%22en-US%22%3E%3CP%20style%3D%22margin%3A%200in%3B%22%3E%3CSPAN%20style%3D%22font-family%3A%20Calibri%3B%20font-size%3A%2011.0pt%3B%22%3ELog%20Analytics%20is%20an%20Azure%20service%20that%20collects%20telemetry%20and%20other%20data%20from%20a%20various%20sources%20and%20provide%20a%20query%20language%20for%20advanced%20analytics.%20After%20you%20post%20logging%20data%20to%20Log%20Analytics%20workspace%20with%20%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Flog-analytics%2Flog-analytics-data-collector-api%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3E%3CSPAN%20style%3D%22font-family%3A%20%26amp%3Bquot%3B%20font-size%3A%2012.0pt%3B%22%3EHTTP%20Data%20Collector%20API%3C%2FSPAN%3E%3C%2FA%3E%3CSPAN%20style%3D%22font-family%3A%20Calibri%3B%20font-size%3A%2011.0pt%3B%22%3E%2C%20you%20are%20able%20to%20query%20logs%20for%20troubleshooting%2C%20visualize%20the%20data%20for%20monitoring%2C%20or%20even%20create%20alerts%20based%20on%20log%20search.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Calibri%3B%20font-size%3A%2011.0pt%3B%22%3E%3CSPAN%20style%3D%22font-weight%3A%20bold%3B%20text-decoration%3A%20underline%3B%22%3ESteps%201%3A%3C%2FSPAN%3ECreate%20Log%20Analytic%20Workspace%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F149546i8B231FFE6C275366%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22clipboard_image_0.png%22%20title%3D%22clipboard_image_0.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Calibri%3B%20font-size%3A%2011.0pt%3B%22%3EWork%20space%20got%20created%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F149548i2F2124C2157B8BF4%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22clipboard_image_1.png%22%20title%3D%22clipboard_image_1.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EStep%202%3A%3C%2FSTRONG%3E%26nbsp%3B%20Load%20the%20logs%20from%20Storage%20Analytic%20logs(%20from%20%24Log)%20folder%20to%20analytical%20workspace%20using%20below%20script.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Calibri%3B%20font-size%3A%2011.0pt%3B%22%3EPlease%20make%20sure%2C%20you%20change%20the%20following%20values%20in%20the%20script%20before%20executing.%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Calibri%3B%20font-size%3A%2011.0pt%3B%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%23%20-%20%24ResourceGroup%3C%2FP%3E%0A%3CP%3E%23%20-%20%24StorageAccountName%3C%2FP%3E%0A%3CP%3E%23%20-%20%24CustomerId%3C%2FP%3E%0A%3CP%3E%23%20-%20%24SharedKey%3C%2FP%3E%0A%3CP%3E%23%20-%20%24LogType%3C%2FP%3E%0A%3CP%3E%23%20-%20Please%20create%20a%26nbsp%3B%20file%20with%20the%20name%20Log.txt%20in%20your%20D%20drive%20and%20update%20the%20below%20path%20in%20the%20script.%3C%2FP%3E%0A%3CP%3E%24filename%20%3D%20%22D%3A%5CLog%5CLog.txt%22%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F149549i172759C534A226C1%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22clipboard_image_0.png%22%20title%3D%22clipboard_image_0.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Calibri%3B%20font-size%3A%2011.0pt%3B%22%3EYou%20can%20find%20more%20details%20on%20this%20script%20%3CA%20href%3D%22https%3A%2F%2Fgithub.com%2FAzure%2Fazure-docs-powershell-samples%2Fblob%2Fmaster%2Fstorage%2Fpost-storage-logs-to-log-analytics%2FPostStorageLogs2LogAnalytics.ps1%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehere%3C%2FA%3E%3C%2FP%3E%0A%3CDIV%20style%3D%22direction%3A%20ltr%3B%22%3E%0A%3CTABLE%20style%3D%22direction%3A%20ltr%3B%20border-collapse%3A%20collapse%3B%20border%3A%200pt%20solid%20%23A3A3A3%3B%22%20title%3D%22%22%20border%3D%220%22%20summary%3D%22%22%20cellspacing%3D%220%22%20cellpadding%3D%220%22%3E%0A%3CTBODY%3E%0A%3CTR%3E%0A%3CTD%20style%3D%22border-width%3A%200pt%3B%20background-color%3A%20white%3B%20vertical-align%3A%20top%3B%20width%3A%2067.6364px%3B%20padding%3A%204pt%3B%22%3E%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Calibri%3B%20font-size%3A%2011.0pt%3B%22%3E%3CSPAN%20style%3D%22font-weight%3A%20bold%3B%20text-decoration%3A%20underline%3B%22%3EStep%203%3A%3C%2FSPAN%3E%3C%2FP%3E%0A%3C%2FTD%3E%0A%3CTD%20style%3D%22border-width%3A%200pt%3B%20background-color%3A%20white%3B%20vertical-align%3A%20top%3B%20width%3A%20658.182px%3B%20padding%3A%204pt%3B%22%3E%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Calibri%3B%20font-size%3A%2011.0pt%3B%22%3EOnce%20you%20run%20the%20script%2C%20you%20will%20get%20below%20output%2C%20which%20indicates%20that%20logs%20are%20being%20posted%20to%20Log%20analytics.%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F149550i5A0075A3EF66900D%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22clipboard_image_0.png%22%20title%3D%22clipboard_image_0.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F149551iC502443CE2FF2F7A%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22clipboard_image_0.png%22%20title%3D%22clipboard_image_0.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F149552iA058267597D9AEF8%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22clipboard_image_1.png%22%20title%3D%22clipboard_image_1.png%22%20%2F%3E%3C%2FSPAN%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CDIV%20style%3D%22direction%3A%20ltr%3B%22%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Calibri%3B%20font-size%3A%2011.0pt%3B%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Calibri%3B%20font-size%3A%2011.0pt%3B%22%3E%3CU%3E%3CSTRONG%3ECommon%20Queries%3C%2FSTRONG%3E%3C%2FU%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Calibri%3B%20font-size%3A%2011.0pt%3B%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Consolas%3B%20font-size%3A%2010.5pt%3B%20color%3A%20black%3B%22%3EApsarnewlog_CL%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Consolas%3B%20font-size%3A%2010.5pt%3B%22%3E%3CSPAN%20style%3D%22color%3A%20black%3B%22%3E%7C%20%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20blue%3B%22%3Elimit%20%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20%2309885a%3B%22%3E50%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Calibri%3B%20font-size%3A%2011.0pt%3B%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Consolas%3B%20font-size%3A%2010.5pt%3B%20color%3A%20black%3B%22%3EApsarnewlog_CL%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Consolas%3B%20font-size%3A%2010.5pt%3B%22%3E%3CSPAN%20style%3D%22color%3A%20black%3B%22%3E%7C%20%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20blue%3B%22%3Esort%20by%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20black%3B%22%3Erequest_start_time_t%20asc%20%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20green%3B%22%3E%2F%2FSorting%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Calibri%3B%20font-size%3A%2011.0pt%3B%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Consolas%3B%20font-size%3A%2010.5pt%3B%20color%3A%20green%3B%22%3E%2F%2FUse%20Wild%20cards%20using%20%22*%22%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Calibri%3B%20font-size%3A%2011.0pt%3B%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Consolas%3B%20font-size%3A%2010.5pt%3B%22%3E%3CSPAN%20style%3D%22color%3A%20blue%3B%22%3Esearch%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20black%3B%22%3Ein%20(Apsarnewlog_CL%20)%20%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20%23a31515%3B%22%3E%22*Tiger*%22%20%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20green%3B%22%3E%2F%2FThe%20search%20command%20is%20typically%20used%20to%20search%20a%20specific%20term.%20In%20the%20following%20example%2C%20all%20columns%20in%20all%20tables%20are%20scanned%20for%20the%20term%20Tiger%3A%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Calibri%3B%20font-size%3A%2011.0pt%3B%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Consolas%3B%20font-size%3A%2010.5pt%3B%22%3E%3CSPAN%20style%3D%22color%3A%20blue%3B%22%3Esearch%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20black%3B%22%3Ein%20(Apsarnewlog_CL)%20request_url_s%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20%23cd3131%3B%22%3E%3A%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20%23a31515%3B%22%3E%22*Tiger*%22%20%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20green%3B%22%3E%2F%2F%20By%20default%2C%20search%20will%20evaluate%20all%20columns%20in%20the%20data%20set.%20To%20search%20only%20a%20specific%20column%20%7Brequest_url_s%7D%2C%20use%20this%20syntax%3A%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Calibri%3B%20font-size%3A%2011.0pt%3B%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Consolas%3B%20font-size%3A%2010.5pt%3B%22%3E%3CSPAN%20style%3D%22color%3A%20blue%3B%22%3Esearch%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20black%3B%22%3Ein%20(Apsarnewlog_CL)%20%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20%23a31515%3B%22%3E%22container2%22%20%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20blue%3B%22%3Eand%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20black%3B%22%3E(%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20%23a31515%3B%22%3E%22Sucess%22%20%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20blue%3B%22%3Eor%20%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20%23a31515%3B%22%3E%22200%22%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20black%3B%22%3E)%20%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20green%3B%22%3E%2F%2FIf%20you%20have%20multiple%20search%20conditions%2C%20you%20can%20combine%20them%20into%20the%20same%20query%20using%20parentheses%3A%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Consolas%3B%20font-size%3A%2010.5pt%3B%22%3E%3CSPAN%20style%3D%22color%3A%20black%3B%22%3E%7C%20%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20blue%3B%22%3Etake%20%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20%2309885a%3B%22%3E100%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Consolas%3B%20font-size%3A%2010.5pt%3B%20color%3A%20%2309885a%3B%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Consolas%3B%20font-size%3A%2010.5pt%3B%22%3E%3CSPAN%20style%3D%22color%3A%20black%3B%22%3EApsarnewlog_CL%20%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20green%3B%22%3E%2F%2F%20Use%20project%20to%20select%20specific%20columns%20to%20include%20in%20the%20results%3A%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Consolas%3B%20font-size%3A%2010.5pt%3B%22%3E%3CSPAN%20style%3D%22color%3A%20black%3B%22%3E%7C%20%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20blue%3B%22%3Etop%20%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20%2309885a%3B%22%3E10%20%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20blue%3B%22%3Eby%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20black%3B%22%3Eclient_request_id_s%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Consolas%3B%20font-size%3A%2010.5pt%3B%22%3E%3CSPAN%20style%3D%22color%3A%20black%3B%22%3E%7C%20%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20blue%3B%22%3Eproject%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20black%3B%22%3ETimeGenerated%2C%20request_url_s%20%2C%20operation_type_s%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Calibri%3B%20font-size%3A%2011.0pt%3B%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Calibri%3B%20font-size%3A%2011.0pt%3B%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Consolas%3B%20font-size%3A%2010.5pt%3B%22%3E%3CSPAN%20style%3D%22color%3A%20black%3B%22%3EApsarnewlog_CL%20%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20green%3B%22%3E%2F%2FSummarize%3A%20aggregate%20groups%20of%20rows%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Consolas%3B%20font-size%3A%2010.5pt%3B%22%3E%3CSPAN%20style%3D%22color%3A%20black%3B%22%3E%7C%20%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20blue%3B%22%3Ewhere%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20black%3B%22%3ETimeGenerated%20%26gt%3B%20ago(%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20%2309885a%3B%22%3E1%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20black%3B%22%3Eh)%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Consolas%3B%20font-size%3A%2010.5pt%3B%22%3E%3CSPAN%20style%3D%22color%3A%20black%3B%22%3E%7C%20%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20blue%3B%22%3Esummarize%20count%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20black%3B%22%3E()%20%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20blue%3B%22%3Eby%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20black%3B%22%3Eoperation_type_s%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Consolas%3B%20font-size%3A%2010.5pt%3B%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Consolas%3B%20font-size%3A%2010.5pt%3B%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F149553i49AA7A223BF69A37%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22clipboard_image_0.png%22%20title%3D%22clipboard_image_0.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Consolas%3B%20font-size%3A%2010.5pt%3B%20color%3A%20black%3B%22%3EApsarnewlog_CL%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Consolas%3B%20font-size%3A%2010.5pt%3B%22%3E%3CSPAN%20style%3D%22color%3A%20black%3B%22%3E%7C%20%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20blue%3B%22%3Ewhere%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20black%3B%22%3Erequest_start_time_t%20%26gt%3B%20ago(%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20%2309885a%3B%22%3E1%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20black%3B%22%3Ed)%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Consolas%3B%20font-size%3A%2010.5pt%3B%22%3E%3CSPAN%20style%3D%22color%3A%20black%3B%22%3E%7C%20%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20blue%3B%22%3Esummarize%20count%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20black%3B%22%3E()%20%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20blue%3B%22%3Eby%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20black%3B%22%3Etostring(%20requester_ip_address_s)%2C%20operation_type_s%2C%20bin(request_start_time_t%2C%20%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20%2309885a%3B%22%3E1%3C%2FSPAN%3E%3CSPAN%20style%3D%22color%3A%20black%3B%22%3Eh)%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin%3A%200in%3B%20font-family%3A%20Consolas%3B%20font-size%3A%2010.5pt%3B%22%3E%26nbsp%3B%3C%2FP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F149554iA2AFA08D9D6EE1D3%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22clipboard_image_0.png%22%20title%3D%22clipboard_image_0.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FTD%3E%0A%3C%2FTR%3E%0A%3C%2FTBODY%3E%0A%3C%2FTABLE%3E%0A%3C%2FDIV%3E%3C%2FLINGO-BODY%3E
Microsoft

Log Analytics is an Azure service that collects telemetry and other data from a various sources and provide a query language for advanced analytics. After you post logging data to Log Analytics workspace with HTTP Data Collector API, you are able to query logs for troubleshooting, visualize the data for monitoring, or even create alerts based on log search.

 

Steps 1: Create Log Analytic Workspace

clipboard_image_0.png

Work space got created

clipboard_image_1.png

 

Step 2:  Load the logs from Storage Analytic logs( from $Log) folder to analytical workspace using below script.

 

Please make sure, you change the following values in the script before executing.

 

# - $ResourceGroup

# - $StorageAccountName

# - $CustomerId

# - $SharedKey

# - $LogType

# - Please create a  file with the name Log.txt in your D drive and update the below path in the script.

$filename = "D:\Log\Log.txt"

 

clipboard_image_0.png

You can find more details on this script here

Step 3:

Once you run the script, you will get below output, which indicates that logs are being posted to Log analytics.

clipboard_image_0.png

 

clipboard_image_0.png

 

clipboard_image_1.png

 

 

 

Common Queries

 

Apsarnewlog_CL

| limit 50

 

Apsarnewlog_CL

| sort by request_start_time_t asc //Sorting

 

//Use Wild cards using "*"

 

search in (Apsarnewlog_CL ) "*Tiger*" //The search command is typically used to search a specific term. In the following example, all columns in all tables are scanned for the term Tiger:

 

search in (Apsarnewlog_CL) request_url_s:"*Tiger*" // By default, search will evaluate all columns in the data set. To search only a specific column {request_url_s}, use this syntax:

 

search in (Apsarnewlog_CL) "container2" and ("Sucess" or "200") //If you have multiple search conditions, you can combine them into the same query using parentheses:

| take 100

 

Apsarnewlog_CL // Use project to select specific columns to include in the results:

| top 10 by client_request_id_s

| project TimeGenerated, request_url_s , operation_type_s

 

 

Apsarnewlog_CL //Summarize: aggregate groups of rows

| where TimeGenerated > ago(1h)

| summarize count() by operation_type_s

 

 

clipboard_image_0.png

 

Apsarnewlog_CL

| where request_start_time_t > ago(1d)

| summarize count() by tostring( requester_ip_address_s), operation_type_s, bin(request_start_time_t, 1h)

 

clipboard_image_0.png