Within Azure Monitor, the store for log data: records of logs and performance counters are kept in Log Analytics workspaces, where KQL queries retrieve them.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Azure Monitor Logs in context, with comparison tables and the common traps.
Terms in this definition
- Azure Monitor
Observability platform for Azure that brings together metrics, logs and traces from both Azure and hybrid resources so they can be analysed and alerted on.
- Performance
Routing method in Traffic Manager that directs users to whichever endpoint offers the lowest latency.
- Dedicated cluster
To encrypt Azure Monitor Logs with your own keys, the Log Analytics workspace must be linked to this cluster tier. Setting a CMK on a storage account gives Log Analytics no such protection.
- WHERE
Limits a SELECT, UPDATE or DELETE to just the rows meeting a condition. Omit it, and the statement hits every row.
- KQL
Kusto Query Language, used read-only to query Azure Data Explorer, Log Analytics and Microsoft Sentinel; log alert rules are written in it too.
Related terms
- Azure DevOps auditing
Records configuration and security changes across an organisation for 90 days. Export or view it on the Auditing page, or stream it to Event Grid, Splunk or Azure Monitor Logs.
- T-SQL
The dialect of SQL that Microsoft uses for Azure SQL and SQL Server. Azure Monitor logs are queried with KQL instead.