Scheduled Azure Monitor alert rule built on a KQL query; it evaluates Log Analytics data either for an entire workspace or for just one resource.
Also called log alert.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Log search alert in context, with comparison tables and the common traps.
Terms in this definition
- Azure Monitor
Observability platform for Azure that brings together metrics, logs and traces from both Azure and hybrid resources so they can be analysed and alerted on.
- Alert rule
Azure Monitor definition made up of a scope naming the target resources, a condition setting the signal and logic, and optionally action groups. A separate rule is needed for every signal that has different recipients.
- KQL
Kusto Query Language, used read-only to query Azure Data Explorer, Log Analytics and Microsoft Sentinel; log alert rules are written in it too.
- Dedicated cluster
To encrypt Azure Monitor Logs with your own keys, the Log Analytics workspace must be linked to this cluster tier. Setting a CMK on a storage account gives Log Analytics no such protection.
- Workspace
Teams in Power BI and Microsoft Fabric collaborate in this folder-style container, which groups items such as reports, semantic models and lakehouses, controls who can access them and is assigned a capacity.
Related terms
- Simple log search alert
Rather than aggregating rows across a time window, this kind of Azure Monitor log search alert checks every row separately to raise alerts close to real time.