To encrypt Azure Monitor Logs with your own keys, the Log Analytics workspace must be linked to this cluster tier. Setting a CMK on a storage account gives Log Analytics no such protection.
Also called Log Analytics.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Dedicated cluster in context, with comparison tables and the common traps.
Terms in this definition
- Azure Monitor Logs
Within Azure Monitor, the store for log data: records of logs and performance counters are kept in Log Analytics workspaces, where KQL queries retrieve them.
- Log Analytics workspace
Where Azure Monitor keeps log data for querying with KQL. Microsoft Sentinel, VM insights and workspace-based Application Insights all depend on one.
- Archive
Offline access tier for blobs, cheapest to store yet dearest to access. Reading a blob means rehydrating it first, which can take as long as 15 hours.
- Customer-managed keys
RSA or RSA-HSM key of 2048, 3072 or 4096 bits that you keep in Key Vault or Managed HSM to wrap a storage account's encryption key. You can switch it on later, except for tables and queues, whose CMK support must be chosen at creation.
- Storage account
The top-level resource in Azure Storage, giving a unique namespace for table, queue, file and blob data. Location, performance and kind are set when it is created and cannot change.
Related terms
- AADRiskyUsers
A Log Analytics table listing the users that Microsoft Entra ID Protection flags as risky, with each user's risk level and state. It is populated once you export the RiskyUsers category through diagnostic settings.
- AADUserRiskEvents
A Log Analytics table recording the user risk detections raised by Microsoft Entra ID Protection. Data arrives once the UserRiskEvents category is exported through diagnostic settings.
- Access control mode
Whether people can read Log Analytics data through their rights on individual resources depends on this workspace setting. Since March 2019 new workspaces default to the option that honours resource-context Azure RBAC as well as workspace rights; the stricter choice demands explicit access to the workspace or its tables.
- ADX
Azure Data Explorer is Microsoft's KQL-based service for analysing large volumes of data. Log Analytics can reach it through the adx() function, though queries and jobs in the Sentinel data lake cannot.
- AGWFirewallLogs
Log Analytics table, resource-specific, that stores WAF events from Application Gateway. Front Door uses different tables.
- AmlOnlineEndpointConsoleLog
Table in Log Analytics capturing console output from Azure Machine Learning online endpoint containers, useful when a container will not start or handles requests incorrectly.
- Application Insights
APM service within Azure Monitor providing application telemetry, availability tests, usage analytics and Application Map. Data from workspace-based instances lives in Log Analytics.
- ARG
Azure Resource Graph lets you run KQL over deployed resources in many subscriptions at once. Log Analytics and advanced hunting can call it with arg(), while analytics rules and lake queries cannot.