SOLVED

AzureDiagnostics log management

%3CLINGO-SUB%20id%3D%22lingo-sub-147932%22%20slang%3D%22en-US%22%3EAzureDiagnostics%20log%20management%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-147932%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%0A%3CP%3EI%20am%20running%20the%20following%20query%26nbsp%3B%3C%2FP%3E%0A%3CDIV%3E%0A%3CDIV%3E%3CSPAN%3EAzureDiagnostics%3C%2FSPAN%3E%3C%2FDIV%3E%0A%3CDIV%3E%3CSPAN%3E%7C%20%3C%2FSPAN%3E%3CSPAN%3Esummarize%3C%2FSPAN%3E%20%3CSPAN%3Ecount%3C%2FSPAN%3E%3CSPAN%3E(CallerIPAddress)%20%3C%2FSPAN%3E%3CSPAN%3Eby%3C%2FSPAN%3E%3CSPAN%3E%20HttpMethod_s%20%2C%20bin(TimeGenerated%2C%20%3C%2FSPAN%3E%3CSPAN%3E2%3C%2FSPAN%3E%3CSPAN%3Em)%3C%2FSPAN%3E%3C%2FDIV%3E%0A%3CDIV%3E%3CSPAN%3Ethat%20gives%20me%20the%20type%20of%20request%20grouped%20by%20IP%20Address%20for%20a%20period%20of%20time%3C%2FSPAN%3E%3C%2FDIV%3E%0A%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CDIV%3E%3CSPAN%3EBut%20when%20I%20look%20at%20the%20documentation%20there%20is%20no%20%22AzureDiagnostics%22%20log%20management%20category.%20the%20query%20works%20fine%20though.%3C%2FSPAN%3E%3C%2FDIV%3E%0A%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CDIV%3E%3CSPAN%3EIf%20I%20look%20at%20the%20CallerIPAddress%20column%20it%20appears%20AzureMetrics%2C%20AzureActivity%20and%20ReservedCommonFields%20but%20there%20is%20no%20HttpMethod_s%20there.%3C%2FSPAN%3E%3C%2FDIV%3E%0A%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CDIV%3E%3CSPAN%3ESo%20my%20question%20is%20%3A%20Is%20there%20a%20documented%20to%20get%20activity%20grouped%20by%20HttpMethods%20and%20CallerIPAddresses%20%3F%3C%2FSPAN%3E%3C%2FDIV%3E%0A%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CDIV%3E%3CSPAN%3EThanks%3C%2FSPAN%3E%3C%2FDIV%3E%0A%3CDIV%3E%3CSPAN%3ERegis%3C%2FSPAN%3E%3C%2FDIV%3E%0A%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-147932%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20Log%20Analytics%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EQuery%20Language%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-148191%22%20slang%3D%22en-US%22%3ERe%3A%20AzureDiagnostics%20log%20management%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-148191%22%20slang%3D%22en-US%22%3E%3CP%3EHi%3C%2FP%3E%0A%3CP%3EAzureActivity%20table%20contains%20the%20azure%20activity%20log%20if%20you%20have%20configure%20it%20to%20be%20send%20to%20Log%20Analytics.%20This%20log%20does%20contain%20HTTP%20methods%20but%20only%20for%20certain%20operations%20so%20basically%20your%20Activity%20log%20needs%20to%20have%20such%20operations.%20HTTP%20method%20in%20AzureActivity%20table%20is%20located%20in%20json%20object%20called%20HTTPRequest.%20Inside%20the%20json%20object%20you%20have%20a%20few%20fields%20one%20of%20which%20is%20method.%20So%20in%20your%20case%20the%20query%20will%20look%20like%20this%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%3EAzureActivity%0A%7C%20summarize%20count(CallerIpAddress)%20by%20tostring(parsejson(HTTPRequest).method)%20%2C%20bin(TimeGenerated%2C%202m)%3C%2FPRE%3E%0A%3CP%3EAzureDiagnostics%20table%26nbsp%3Bcan%20contain%20diagnostics%20logs%20from%20multiple%20azure%20services.%20For%20a%20full%20list%20of%20supported%20services%20see%20here%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fmonitoring-and-diagnostics%2Fmonitoring-diagnostic-logs-schema%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fmonitoring-and-diagnostics%2Fmonitoring-diagnostic-logs-schema%3C%2FA%3E%20.%20Of%20course%20with%20this%20log%20you%20will%20have%20to%20configure%20the%20resources%20you%20have%20to%20send%20the%20logs%20to%20Log%20Analytics.%3C%2FP%3E%0A%3CP%3EThe%20situation%20is%20the%20same%20with%20AzureMetrics%20table.%20See%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fmonitoring-and-diagnostics%2Fmonitoring-supported-metrics%26nbsp%3B%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fmonitoring-and-diagnostics%2Fmonitoring-supported-metrics%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ESo%20both%20of%20these%20tables%20will%20depend%20on%20what%20services%20you've%20configured%20to%20send%20logs%20to%20Log%20Analytics.%20If%20any%20of%20the%20services%20does%20not%20have%20HttpMethod%20field%20than%20such%20will%20not%20be%20present%20in%20Log%20Analytics.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Microsoft

Hi,

I am running the following query 

AzureDiagnostics
| summarize count(CallerIPAddress) by HttpMethod_s , bin(TimeGenerated, 2m)
that gives me the type of request grouped by IP Address for a period of time
 
But when I look at the documentation there is no "AzureDiagnostics" log management category. the query works fine though.
 
If I look at the CallerIPAddress column it appears AzureMetrics, AzureActivity and ReservedCommonFields but there is no HttpMethod_s there.
 
So my question is : Is there a documented to get activity grouped by HttpMethods and CallerIPAddresses ?
 
Thanks
Regis
1 Reply
best response confirmed by Stanislav Zhelyazkov (MVP)
Solution

Hi

AzureActivity table contains the azure activity log if you have configure it to be send to Log Analytics. This log does contain HTTP methods but only for certain operations so basically your Activity log needs to have such operations. HTTP method in AzureActivity table is located in json object called HTTPRequest. Inside the json object you have a few fields one of which is method. So in your case the query will look like this:

 

AzureActivity
| summarize count(CallerIpAddress) by tostring(parsejson(HTTPRequest).method) , bin(TimeGenerated, 2m)

AzureDiagnostics table can contain diagnostics logs from multiple azure services. For a full list of supported services see here: https://docs.microsoft.com/en-us/azure/monitoring-and-diagnostics/monitoring-diagnostic-logs-schema . Of course with this log you will have to configure the resources you have to send the logs to Log Analytics.

The situation is the same with AzureMetrics table. See https://docs.microsoft.com/en-us/azure/monitoring-and-diagnostics/monitoring-supported-metrics 

So both of these tables will depend on what services you've configured to send logs to Log Analytics. If any of the services does not have HttpMethod field than such will not be present in Log Analytics.