Jan 12 2018
10:39 AM
- last edited on
Apr 07 2022
04:51 PM
by
TechCommunityAP
Jan 12 2018
10:39 AM
- last edited on
Apr 07 2022
04:51 PM
by
TechCommunityAP
I'm trying to use the new PowerShell based API (Invoke-LogAnalyticsQuery - see below) and the return payload only includes the Tables array and not the Results array as documented..
Jan 14 2018 01:05 AM
SolutionHi Brady,
First, I must comment on your query. You should avoid queries that has 'search * | where Type =='. Instead the query below should just be: 'Heartbeat | take 10'. Search * is very inefficient way to use the system.
Regarding the results array. I ran the same code but didn't managed to reproduce. I got both tables and results.
Sorry
Meir
Jan 15 2018 05:50 PM
Meir, thanks for the pointer on query optimization. I did figure out that I am getting the results. It seems the shape of the JSON result you get back from Invoke-LogAnalyticsQuery doesn't match what is documented at:
https://dev.loganalytics.io/documentation/Tools/PowerShell-Cmdlets.
Thanks again.
Jan 18 2018 02:54 PM
Adding @Chris Suich
Feb 03 2018 10:33 AM
And please provide a signed version of Invoke-LogAnalyticsQuery. Changing execution policies is not a good practice. This command is fragile too - lots of bad gateways. Makes it challenging to piece together data. Thank you.
Feb 03 2018 01:14 PM
Hi Brady,
The returned payload should include the results array. Can you inspect the payload using Get-Member (as shown in screenshot) to check for it? The flag -IncludeTabularView will add the tabular view, but the results array will always be on the payload.
Feb 03 2018 01:48 PM
Thanks for the feedback Mark. We are working to provide a better set of cmdlets integrated with Azure Powershell, which will be available from the PowerShell gallery. They should be available in the next release of AzureRM PowerShell module. These should have better stability and will be signed.
Feb 05 2018 09:55 AM
Thanks. I did verify I am getting the results you indicate in the Results array is there. The documentation for the CMDLET is a bit confusing (https://dev.loganalytics.io/documentation/Tools/PowerShell-Cmdlets) but I see what's going on now. I also vote for a properly signed supported module here. Thanks a lot for the help.
Feb 23 2018 12:52 PM
Following up on this, we've made the a cmdlet available for querying as part of the Azure RM cmdlets in the gallery. If you don't already have them, see here: https://docs.microsoft.com/en-us/powershell/azure/install-azurerm-ps?view=azurermps-5.3.0
Documentation for the new cmdlet is here: https://docs.microsoft.com/en-us/powershell/module/azurerm.operationalinsights/invoke-azurermoperati...
Try it out and let us know what you think!
Jan 14 2018 01:05 AM
SolutionHi Brady,
First, I must comment on your query. You should avoid queries that has 'search * | where Type =='. Instead the query below should just be: 'Heartbeat | take 10'. Search * is very inefficient way to use the system.
Regarding the results array. I ran the same code but didn't managed to reproduce. I got both tables and results.
Sorry
Meir