Azure Monitor Agent for Linux is bloatware
Hello Azure community, For the past 2-3 weeks I have been getting CPU and memory alerts for VMs which have been stable for years. Looking into the problem, it was always Azure Monitor Agent or one the Azure extensions causing the spike in load. It's…
Getting a 403 error when linking a workspace for Windows Update for Business reports in Azure Monitor
Getting a 403 error when linking a workspace for Windows Update for Business reports in Azure Monitor Reference Azure > Monitor > workbooks > Windows Update for Business reports > Get Started When ever i try to save the settings for…

Guidance on Filtering AppTraces Logs to Optimize Sentinel Workspace Usage
Hi Community, I'm seeking advice on how to filter out AppTraces logs from being ingested into our Sentinel workspace. These logs are consuming significant storage space and, being categorized under Analytics logs, are contributing to increased costs.…
Cannot Get Action Group -> Email Azure Resource Manager Role to send notifications to Monitoring Readers
I have a notification action group setup that has a single notification type to Email Azure Resource Manager Role -> Monitoring Readers. In the subscription IAM tab I have 3 users in the Monitoring Roles Group. All of these users are active…
Free units for alert rules on Azure
Could you please let me know if you have any information about alert rules. The document of azure monitor pricing says "10 monitored metric time-series per month13" about Native Metrics, but it does not mention scope, such as if it is per…
Data not being refreshed in the Log Analytics demo
I'm currently working through the KQL learning path. The logs in the Log Analytics Demo environment don't seem to be refreshing. This is supposed to be a training ground for KQL but for example there is no data in the SecurityEvent table for several…
Azure DCR Rules
If we write a DCR to ingest VMInsights Metrics into Log Analytics workspace as shown below: "dataSources": { "performanceCounters": [ { "streams":…
azure monitor agent only sending system logs to log analytics
azure monitor agent only sending system logs to log analytics even if i deselect system and only select application logs - still only sends all system logs to analytics
Consolidate azure container apps alert query to setup alert on all container apps
Hi, We would like to write alert queries for all container apps in a single place which will conver all the container apps with the name (regex or wildcard pattern). We dont want to create alert rules for common resources like cpu, memory and disk…

Time range (for last month) in Kusto Query language in Logs Analytics Workspace
Hi, We use Log Analytics Workspace to collect logs for our customer tenants under a resource hosted in Azure. Previously we would select Time Range feature to select the hits per tenant for the last calendar month and I was looking to set it in the…
Azure Monitor in External Tenant
Hi, We are setting up an Entra External ID tenant to house external users of a web app that we host. I presently stream our internal diagnostics logs to an Event Hub in our workforce tenant and then to an IDR. I found this article and was successful at…
"Sev3 Azure Monitor Alert VM Availability" after this alert my code and phpmyadmin database not recover how recover this
After receiving a Sev3 (Severity 3) Azure Monitor Alert related to VM Availability, my virtual machine (VM) experienced data loss. How can I investigate the cause of this issue, recover the lost data, and prevent such incidents in the future?
Log Analytics API
Hi, I am trying to access my log analytics workspace through postman. I saw some documents and followed them but they weren't successful. My specific requirement is I have a FHIR service with audit logs enabled and streamed to Log analytics workspace. I…
How to embed search results in alert from logic app?
Hi, I know that: "Log alert rules from API version 2020-05-01 use this payload type, which only supports common schema. Search results aren't embedded in the log alerts payload when you use this version. Use dimensions to provide context to fired…
Need more details regarding Microsoft Azure Alert Signal named "All Administrative Operations"
While I am going through the below page which explains how to create an alert with Signal named "All Administrative Operations". I am interested in what specific operations the signal "All Administrative Operations" includes. Is the…
Trigger notification and action when VM goes down
Trigger notification and action (ansible play book or standalone python script) when VM goes down. Our requirement is need to trigger an alert and action once vm shut down. I tried vm-poweroff-alert but I am not getting any alerts (email configured) when…
Alert email in Azure Monitor to report failure in Azure Pipeline
Hello, Is there an example on how to create an Alert in Azure Monitor to report a failure in an Azure Data Factory Pipeline? Thank You, Michael
Type of log to identify failed Windows Defender update?
Hi everyone, I am trying to set up Log Analytic Workspace that will capture any critical and security updates in the Windows VMs which I believe will also include the failed Windows Defender update logs. Now I would like to have an action taken whenever…
Azure Monitor Log Ingestion API - Error when POSTing to Syslog table
Hi, I'm trying to use the Log Ingestion API to POST data to the Syslog table in Log Analytics but I am unable to get it working. The documentation suggests this should be possible:…
AzureActivity Table PrincipalId + UserPrincipalName from another Table in KQL
Good morning all I am following Microsoft's official documentation for adding an alert rule that fires when a user adds another user or service principal to a privileged role assignment (e.g. Owner, Contributor). I have achieved this by streaming logs to…
