Reports in Azure that you can interact with, mixing KQL queries, metrics, parameters and text. Send Intune logs to Log Analytics and you can build them on that data.
Also called workbooks.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Azure Monitor workbooks in context, with comparison tables and the common traps.
Terms in this definition
- KQL
Kusto Query Language, used read-only to query Azure Data Explorer, Log Analytics and Microsoft Sentinel; log alert rules are written in it too.
- Intune
Microsoft's device management service, once branded Microsoft Endpoint Manager. Its compliance policies are what the compliant-device grant in Conditional Access relies on.
- Dedicated cluster
To encrypt Azure Monitor Logs with your own keys, the Log Analytics workspace must be linked to this cluster tier. Setting a CMK on a storage account gives Log Analytics no such protection.
Related terms
- ACE
Power Query relies on this OLE DB provider to open Access files and older .xls or .xlsb Excel workbooks. Cloud services cannot have it installed, so scheduled refresh of such files goes through a gateway on a machine where ACE is present.
- Content hub
Lets you browse and install Microsoft Sentinel solutions, or standalone items such as playbooks, workbooks, hunting queries, analytics rules and data connectors, all supplied out of the box.
- Microsoft Sentinel Contributor
Built-in Azure role that includes everything Responder can do and can also create and modify workbooks, analytics rules and content hub solutions.
- Microsoft Sentinel Reader
Built-in Azure role for viewing incidents, workbooks and data in Sentinel; it can't change incidents.
- Microsoft Sentinel solution
Bundle of Sentinel content for a product or scenario, such as playbooks, workbooks, connectors and analytics rules. Unlike standalone content, it installs from the content hub as one unit and you update it by hand.
- OLE DB
A Microsoft interface for data access. Power Query can connect through it generically, and legacy Excel files (.xls and .xlsb) are read with the ACE provider, which cloud services can't install; refreshing such workbooks therefore requires a gateway.
- Power BI Report Server
Lets organisations keep Power BI reports, Excel workbooks and paginated reports inside their own network, published through a web portal they host themselves. Content comes from a dedicated edition of Power BI Desktop, and licences come with P SKUs or with SQL Server Enterprise plus Software Assurance.
- Release annotations
Deployment markers that appear on Application Insights charts (Failures, Performance, Usage) and in workbooks. For supported Functions and App Service tasks, Azure Pipelines adds them without extra setup.