Type of Azure Monitor alert driven by a KQL query over Log Analytics data. Logs that exist only in Event Hubs or storage accounts are out of its reach.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Log alert in context, with comparison tables and the common traps.
Terms in this definition
- Azure Monitor
Observability platform for Azure that brings together metrics, logs and traces from both Azure and hybrid resources so they can be analysed and alerted on.
- KQL
Kusto Query Language, used read-only to query Azure Data Explorer, Log Analytics and Microsoft Sentinel; log alert rules are written in it too.
- OVER
Gives a T-SQL window function its window: PARTITION BY, ORDER BY and, if wanted, a ROWS or RANGE frame. Rankings and running totals can then be worked out while every row is kept.
- Dedicated cluster
To encrypt Azure Monitor Logs with your own keys, the Log Analytics workspace must be linked to this cluster tier. Setting a CMK on a storage account gives Log Analytics no such protection.
- Azure Event Hubs
Azure service for ingesting telemetry at high volume over HTTPS or AMQP; diagnostic settings can send data to it.
- General-purpose v1
The older storage account kind (
Storage), which lacks access tiers, Archive and premium file shares and retires on 13 October 2026. Converting to ZRS requires first upgrading to GPv2, a one-way change. - AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.