Agent now used to collect logs from a machine's guest OS, driven by data collection rules; it took over from the Log Analytics agent (MMA).
Also called AMA, AMA.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104AZ-700SC-500AI-103AI-200AZ-400AZ-802ALZ
Each book explains Azure Monitor agent in context, with comparison tables and the common traps.
Terms in this definition
- Agent
A specialised form of Microsoft Copilot set up for one particular job, pairing instructions with knowledge and skills. You can create one in Copilot Studio, SharePoint or Agent Builder, and administrators control them from the Microsoft 365 admin center.
- OVER
Gives a T-SQL window function its window: PARTITION BY, ORDER BY and, if wanted, a ROWS or RANGE frame. Rankings and running totals can then be worked out while every row is kept.
- Log Analytics agent
Older MMA/OMS monitoring agent, retired in August 2024. The Azure Monitor Agent, configured with data collection rules, replaces it.
Related terms
- Azure Arc-enabled servers
Servers running Windows or Linux outside Azure that become Azure resources once the Azure Connected Machine agent is installed; data collection rules can then drive the Azure Monitor agent on them.
- Azure Connected Machine Resource Administrator
Gives full control over Azure Arc-enabled servers and their extensions, including onboarding them again, which covers rolling out the Azure Monitor Agent to those machines. It is one of the built-in Azure roles.
- CEF via AMA
Sentinel data connector in which a Linux forwarder runs the Azure Monitor Agent with a DCR to receive CEF messages; it supersedes the older CEF connector built on the Log Analytics agent.
- Change Tracking and Inventory
Uses the Azure Monitor Agent to follow changes to files, registry keys, software and services inside guest operating systems, keeping the records in Log Analytics.
- Custom Logs via AMA
Collects text-file logs into a _CL table, using the Azure Monitor Agent plus a data collection rule, from Windows or Linux machines or a log forwarder. It is a Microsoft Sentinel data connector still in preview.
- Data collection rule
Rule in Azure Monitor specifying what the Azure Monitor Agent or Logs Ingestion API gathers (XPath event filters, for example), any transformation applied, and the destination.
- Guest data
Telemetry captured within a virtual machine's operating system: Windows events, Syslog, perf counters, IIS logs and text logs. Azure Monitor Agent has to be installed, with a data collection rule, before any of it is gathered.
- Linux log forwarder
Linux machine set aside to collect syslog and CEF messages from devices on port 514 using rsyslog or syslog-ng, then pass them via the Azure Monitor Agent into a Microsoft Sentinel workspace.