Table exists but the query cannot find it

%3CLINGO-SUB%20id%3D%22lingo-sub-1062794%22%20slang%3D%22en-US%22%3ETable%20exists%20but%20the%20query%20cannot%20find%20it%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1062794%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20at%20least%20two%20instances%20where%20I%20receive%20data%20in%20Log%20Analytics%20(OfficeActivity%20from%20Office%20365%20via%20the%20Azure%20Sentinel%20connector)%20yet%2C%20when%20I%20try%20to%20query%20it%2C%20the%20table%20cannot%20be%20found%3A%3C%2FP%3E%3CP%3EExample%20query%3A%3C%2FP%3E%3CDIV%3E%3CDIV%3E%3CSPAN%3EOfficeActivity%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%7C%20limit%2010%3C%2FSPAN%3E%3C%2FDIV%3E%3C%2FDIV%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EResult%3A%3C%2FP%3E%3CP%3E%3CSPAN%3E'take'%20operator%3A%20Failed%20to%20resolve%20table%20or%20column%20expression%20named%20'OfficeActivity'%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EThe%20connector%20has%20been%20configured%20several%20days%20ago%20and%20I%20know%20that%20the%20logs%20are%20received%3A%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F161402iA15FFD7F8DF32FB6%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22clipboard_image_0.png%22%20title%3D%22clipboard_image_0.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhile%20I%20tried%20to%20connect%20from%203%20different%20ISPs%20with%20no%20luck%2C%20it%20seems%20that%20from%20some%20locations%2C%20the%20data%20is%20accessible%20so%20it%20must%20be%20something%20about%20these%20tables%20being%20replicated%20through%20Azure.%20I%20have%20contributor%20role%20to%20the%20subscription.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20thoughts%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1062794%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20Log%20Analytics%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1071993%22%20slang%3D%22en-US%22%3ERe%3A%20Table%20exists%20but%20the%20query%20cannot%20find%20it%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1071993%22%20slang%3D%22en-US%22%3E%3CP%3EHi%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F353788%22%20target%3D%22_blank%22%3E%40AdiGrio%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThis%20must%20be%20some%20temporary%20issue%20with%20the%20search%20service.%20Is%20your%20issue%20resolved%20now%20or%20you%20still%20experience%20it%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1072018%22%20slang%3D%22en-US%22%3ERe%3A%20Table%20exists%20but%20the%20query%20cannot%20find%20it%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1072018%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F9172%22%20target%3D%22_blank%22%3E%40Stanislav%20Zhelyazkov%3C%2FA%3E%26nbsp%3BThank%20you%20for%20the%20reply.%20Unfortunately%2C%20the%20issue%20persists.%20It%20seems%20that%20the%20tables%20that%20are%20affected%20are%20OfficeActivity%20and%20custom%20logs%2C%20weeks%20after%20the%20tables%20have%20been%20created%20(with%20data%20streaming%20in%20on%20regular%20basis).%20Just%20trying%20to%20create%20alerts%20in%20Azure%20Sentinel%20using%20these%20tables%20is%20failing%20as%20the%20KQL%20scripts%20cannot%20be%20validated%20(since%20the%20tables%20%22don't%20exist%22).%20Some%20succeed%20after%20several%20tries.%20One%20particular%20subscription%20is%20based%20on%20South%20Africa%20North%20region%20and%20the%20other%20in%20Canada%20Central%20so%20maybe%20is%20something%20about%20that%3F%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1072031%22%20slang%3D%22en-US%22%3ERe%3A%20Table%20exists%20but%20the%20query%20cannot%20find%20it%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1072031%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F353788%22%20target%3D%22_blank%22%3E%40AdiGrio%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20only%20way%20that%20you%20are%20not%20seeing%20these%20tables%20could%20be%20by%20two%20issues%3A%3C%2FP%3E%0A%3CP%3E-%20You%20do%20not%20have%20permissions.%20If%20you%20have%20Contributor%20permissions%20on%20the%20subscription%20where%20the%20workspace%20is%20that%20shouldn't%20be%20problem%3C%2FP%3E%0A%3CP%3E-%20When%20you%20have%20opened%20Logs%20blade%20you%20scoped%20it%20to%20something%20else%20(you%20can%20now%20scope%20per%20subscription%2C%20resource%20group%20or%20specific%20resource)%20instead%20of%20the%20actual%20workspace%20resource.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThere%20isn't%20any%20replication%20in%20Log%20Analytics%20workspace%20happening%20that%20could%20be%20preventing%20you%20from%20searching%20(as%20far%20as%20I%20know)%20these%20tables.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ECan%20you%20describe%20the%20steps%20on%20how%20you%20query%20the%20logs%3F%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20none%20of%20the%20above%20is%20the%20problem%20you%20might%20want%20to%20open%20official%20case%20to%20MS%20support%20to%20investigate.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

Hi,

 

I have at least two instances where I receive data in Log Analytics (OfficeActivity from Office 365 via the Azure Sentinel connector) yet, when I try to query it, the table cannot be found:

Example query:

OfficeActivity
| limit 10

 

Result:

'take' operator: Failed to resolve table or column expression named 'OfficeActivity'

 

The connector has been configured several days ago and I know that the logs are received:

 

clipboard_image_0.png

 

While I tried to connect from 3 different ISPs with no luck, it seems that from some locations, the data is accessible so it must be something about these tables being replicated through Azure. I have contributor role to the subscription.

 

Any thoughts?

3 Replies

Hi@AdiGrio 

This must be some temporary issue with the search service. Is your issue resolved now or you still experience it?

@Stanislav Zhelyazkov Thank you for the reply. Unfortunately, the issue persists. It seems that the tables that are affected are OfficeActivity and custom logs, weeks after the tables have been created (with data streaming in on regular basis). Just trying to create alerts in Azure Sentinel using these tables is failing as the KQL scripts cannot be validated (since the tables "don't exist"). Some succeed after several tries. One particular subscription is based on South Africa North region and the other in Canada Central so maybe is something about that? 

@AdiGrio 

The only way that you are not seeing these tables could be by two issues:

- You do not have permissions. If you have Contributor permissions on the subscription where the workspace is that shouldn't be problem

- When you have opened Logs blade you scoped it to something else (you can now scope per subscription, resource group or specific resource) instead of the actual workspace resource.

 

There isn't any replication in Log Analytics workspace happening that could be preventing you from searching (as far as I know) these tables.

 

Can you describe the steps on how you query the logs?

 

If none of the above is the problem you might want to open official case to MS support to investigate.