Where Azure Monitor keeps log data for querying with KQL. Microsoft Sentinel, VM insights and workspace-based Application Insights all depend on one.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104AZ-700SC-500AI-300AI-103AZ-900SC-900SC-200SC-300AZ-802DP-800ALZ
Each book explains Log Analytics workspace in context, with comparison tables and the common traps.
Terms in this definition
- WHERE
Limits a SELECT, UPDATE or DELETE to just the rows meeting a condition. Omit it, and the statement hits every row.
- Azure Monitor
Observability platform for Azure that brings together metrics, logs and traces from both Azure and hybrid resources so they can be analysed and alerted on.
- KQL
Kusto Query Language, used read-only to query Azure Data Explorer, Log Analytics and Microsoft Sentinel; log alert rules are written in it too.
- Microsoft Sentinel
Microsoft's cloud-native SIEM, with SOAR capabilities, which stores and queries its data in a Log Analytics workspace.
- VM insights
Monitors VM performance in Azure Monitor and offers a dependency Map, though Map and the Dependency agent are deprecated and retire on 30 June 2028. Change auditing and NSG rule evaluation are outside its remit.
- Workspace-based Application Insights
The current form of Application Insights, which writes its data into a Log Analytics workspace. The older classic type is retired and no longer accepts incoming telemetry.
- ALL
A DAX function that ignores any filters and gives back every row of a table or every value of the named columns. Used within CALCULATE, it works as a modifier that clears filters, although REMOVEFILTERS states that intent more clearly where it is available.
Related terms
- Activity log alert
Alert rule without state that triggers on a matching Activity log event, deleting a management lock for instance. A scope, a condition and an action group are required; a Log Analytics workspace is not.
- Azure Monitor workspace
Workspace that holds only Prometheus metrics; log data belongs in a Log Analytics workspace instead.
- Azure SQL auditing
Azure SQL feature that sends audit logs to Event Hubs, a Log Analytics workspace (the only KQL-queryable option) or a storage account, which in the portal must be in the server's region and can't be premium FileStorage or legacy BlobStorage.
- Conditional Access insights and reporting
Using sign-in data sent to a Log Analytics workspace, this workbook estimates what all your Conditional Access policies, report-only ones included, would do together over a chosen window between 4 hours and 90 days. It needs an Entra ID P1 licence and a role of Security Reader or above.
- Continuous export
Streams Defender for Cloud recommendations and alerts out to Event Hubs or to a Log Analytics workspace, either as they happen or in weekly snapshots; Azure Policy can apply the setting at scale.
- Daily cap
Limit on a Log Analytics workspace that halts data ingestion for the rest of the day once a set volume is hit.
- Dedicated cluster
To encrypt Azure Monitor Logs with your own keys, the Log Analytics workspace must be linked to this cluster tier. Setting a CMK on a storage account gives Log Analytics no such protection.
- Defender for Servers Plan 2
Top Defender for Servers tier, which includes FIM, JIT VM access, agentless scanning and, from August 2023, Defender for DNS alerts. You turn it on per subscription or per Log Analytics workspace.