SOLVED

Problem with Log Analytics

%3CLINGO-SUB%20id%3D%22lingo-sub-292601%22%20slang%3D%22en-US%22%3EProblem%20with%20Log%20Analytics%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-292601%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%20I'm%20currently%20monitoring%20servers%20through%20azure%20log%20analytics.%20But%20currently%20I%20have%20a%20tab%20that%20says%20%22others%22%2C%20meaning%20other%20servers%20that%20can't%20be%20displayed.%26nbsp%3BHow%20do%20I%20change%20the%20amount%20of%20displayable%20servers%20to%20like%2C%20top%2010%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-292601%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20Log%20Analytics%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ECustom%20Logs%20and%20Custom%20Fields%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMachine%20Learning%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EQuery%20Language%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EView%20Designer%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-292652%22%20slang%3D%22en-US%22%3ERe%3A%20Problem%20with%20Log%20Analytics%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-292652%22%20slang%3D%22en-US%22%3EOr%20you%20can%20check%20out%20this%20very%20useful%20blog%20by%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F9172%22%20target%3D%22_blank%22%3E%40Stanislav%20Zhelyazkov%3C%2FA%3E%3A%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fcloudadministrator.net%2F2018%2F03%2F22%2Ftop-10-charts-in-azure-log-analytics-and-application-insights%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fcloudadministrator.net%2F2018%2F03%2F22%2Ftop-10-charts-in-azure-log-analytics-and-application-insights%2F%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-292647%22%20slang%3D%22en-US%22%3ERe%3A%20Problem%20with%20Log%20Analytics%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-292647%22%20slang%3D%22en-US%22%3E%3CP%3ETo%20select%20the%20top%2010%20in%20a%20query%2C%20you%20could%20use%20something%20like%20this%20(%3CSTRONG%3Esummarize%20by%20Computer%3C%2FSTRONG%3E%20and%20%3CSTRONG%3Etop%2010%3C%2FSTRONG%3E%3A(%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EEvent%3CBR%20%2F%3E%7C%20where%20(EventLevelName%20%3D%3D%20%22Error%22)%3CBR%20%2F%3E%7C%20where%20(TimeGenerated%20%26gt%3B%20ago(1days))%3CBR%20%2F%3E%7C%20summarize%20ErrorCount%20%3D%20count()%20by%20Computer%3CBR%20%2F%3E%7C%20top%2010%20by%20ErrorCount%20desc%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Deleted
Not applicable

Hi, I'm currently monitoring servers through azure log analytics. But currently I have a tab that says "others", meaning other servers that can't be displayed. How do I change the amount of displayable servers to like, top 10?

 

 

2 Replies

To select the top 10 in a query, you could use something like this (summarize by Computer and top 10:(

 

Event
| where (EventLevelName == "Error")
| where (TimeGenerated > ago(1days))
| summarize ErrorCount = count() by Computer
| top 10 by ErrorCount desc


best response confirmed by Stanislav Zhelyazkov (MVP)