View/Query data in Log Storage

Brass Contributor

We have a diagnostic export of audit and sign-in logs to both a Log Storage and Event hub instance with retention of 365 days on the storage account. I need to see the historical data therein. What are my options? Log Analytics only goes back 30 days currently. 

2 Replies

@shockotechcom not really sure but i think you need to ingest them into a log analytics to check the contents, (importing them manually) or accessing the storage account by using Microsoft azure Storage Explorer... 

 

Hope this helps: 

 

https://docs.microsoft.com/en-us/answers/questions/25850/how-to-get-the-access-log-for-the-storage-a...

 

Best Regards. 

 

 

@loadedlouie27 

You may be able to query them with the externaldata operator, which reads them into a query rather than re-ingesting them?

 

https://techcommunity.microsoft.com/t5/azure-sentinel/move-your-azure-sentinel-logs-to-long-term-sto...

See "Query the data" section.