Log Analytics
Welcome to the "Azure Log Analytics ":https://azure.microsoft.com/en-us/services/log-analytics/ Feedback page. We appreciate your feedback and look forward to hearing from you. Use this site for new ideas and bug reports or to request help.
NOTE – Log Analytics is now a part of Operations Management Suite. Learn more at http://microsoft.com/OMS
- For general discussion/question and answers (not ideas and bug reports) use the MSDN Forum
- Onboarding issues? Read this troubleshooting guide
- How do I do XYZ? Try our documentation
- Customers with Premier support can log support cases via Premier
- Customers with Azure support agreements can log support cases in the Azure portal
-
Service Map support on Ubuntu
Ability to install the Dependency Agent on Ubuntu
420 votes -
Support other Antivirus products in Malware Assessment
I added the Malware Assessment Intelligence Pack today, and it seems to be listing all of my servers as not having any real time AV protection. The servers in question are running Symantec Endpoint Protection. I looked in the description of the intelligence pack to see what AV products it works with, but didn't find that info.
[Edited during forum migration: comments/responses in the old forum included Symantec and Sophos]
398 votesWe’re looking at using information from the Windows Security Center to collect status from non-Microsoft antimalware products.
-
Multi tenancy: Collect Azure Health logs from different Azure tenants
We manage Azure tenants for multiple companies. We want one central monitoring and automation Workspace to manage all these different tenants.
Although you can collect data from vm agents in different Azure tenants as well as data from different Office365 tenants it is not possible to get the Azure Health logs from different tenants into one OMS Workspace.377 votesYou can send Azure Activity Logs (aka operational events/audit events) for multiple subscriptions to a single log analytics workspace.
Is this what you mean by Health logs? If so, you can query for them with Type=AzureActivity Category=ServiceHealth
Additional guidance for service providers:
https://docs.microsoft.com/en-us/azure/log-analytics/log-analytics-service-providers-Richard
-
270 votes
We’ll watch interest. Can you comment/provide scenarios/use cases? is the idea to collect (thru the agent? or from azure subscription?) certificates and show/allow searching their properties?
-
Provide an Intelligence Pack for System Center Service Manager
Create an intelligence pack for System Center Service Manager to provide additional analytical data for problem management, incident analysis, and configuration item analysis.
266 votesCan you provide a RANKED list of what is MOST and LEAST important for the various capabilities and scenarios that SM provides? i.e. you listed
- problem management
- incident management
- configuration items
… -
Azure Operational Insights for on-premises
We want to install "Azure Operational Insights" to on-promises.
Many of customer can not upload their logs to Azure (legal or etc...).250 votesThanks for the suggestion, we’ll be looking to see how much support this request gets.
At the moment we don’t have plans to make this service available to run on-premises.
Regards
Richard -
Support Nano Server
Support Nano Server
245 votesWe’ll leverage the work done to have SCOM monitor Nano server to also bring support for Nano server to report to OMS.
-
Improve multitenancy for managed services providers
Currently we can have one subscription per MG and/or consolidate multiple MGs into one single subscription. What's missing is the ability to have groups of different systems from the same MG to report to different subscriptions. In management as a service scenario for SMB customers it's often impractical to have 1 MG per customer, rather multiple customers are consolidated into one infrastructure (MG) and then access is limited via scoping. Bring this to Advisor, please.
244 votesWe’ll be working to bring this functionality in stages over the next several months.
One of the first steps is to ensure that workspace creation and configuration can be done programmatically.
We’re also looking at how to report across multiple workspaces.
-
Open up the capacity management pack for other systems/counters without VMM
Would be great to be able to do some capacity planning on other counters or systems (sql dabatabase, scsm, scom orchestrator). You have a great engine in the backend so please utilize it fully. for example: would be great to be able to import other SCOM data like SQL perf counters so I can do capacity planning on my SQL servers. Or to be able to do capacity planning on physical hosts that are not managed by VMM.
213 votesThe capacity planning solution is in the process of being updated to address the following customer reported challenges:
• Hard dependency on VMM+SCOM
• Inability to customize\filter based on groups
• Hourly data aggregation (data lag)
• No VM level insights
• Data reliabilityBenefits of the new capacity solution
• Support granular data collection (improved reliability and accuracy)
• Support for Hyper-V
• Visualization of metrics in PowerBI
• Customizability using the Solution Designer
• Insights on VM level utilizationWhen will the new capacity planning solution be released?
We are planning to release a private preview to customers Q1-FY17 and public preview in Q2.What happened to the existing Capacity Planning solution in the gallery?
Due to the limitations of the existing solution we disabled it from the gallery and will re-enable it when our quality bar is met with the new solution.What happens to customer using…
-
StorSimple Management from OMS
Could it be possible to add StorSimple to the OMS dashboard? I would like to see monitoring, usage, updates and snapshots from within the dashboard.
210 votesThanks for the idea, Ben. Let’s see how much traction this feedback receives from the community.
-
Support for ARM Backup and Site Recovery vaults
Support for ARM Backup and Site Recovery vaults, as well as multiple vaults per workspace.
OMS only supports Classic (ASM) vaults, and it also supports only 1 Backup vault per OMS workspace, this sounds like a big limitation.202 votesWe’ll be providing a new solution to support Recovery Vaults
-
198 votes
This is a seeded idea we have considered. Please vote if this is the next thing you would like ‘Change Tracking’ to track.
-
Allow to print, email, and schedule Capacity Reports
It would be good to be able to generate reports that could be printed, emailed, and scheduled for regular delivery. This would make consuming and disseminating the capacity analytics much easier.
186 votesI am interested in understanding – would this be a requirement for just (or mainly) the Capacity Intelligence Pack’s screens/pages, or should this be something ‘generic’ for all Intelligence packs?
It might be not really easy nor feasible nor forward looking to properly ‘print’ the current hand-coded pages / dashboards.
The direction we are thinking for the product is more around the SEARCH feature, to eventually allow you to do your own queries and analytics…
See these related ideas that are based on search and would ALSO enable the scenario of ‘consuming the data outside of the portal’
what do you think?
-
Access read only Dashboard directly from URL
Maybe IT can be (partially) achieved by RBAC but we would like to have the possibility to access a read-only version of the dashboard just bij entering a URL. The dashboard should not have a timeout. this way we can put the dashboard on a big screen (and when the possibility of multiple dashboard is enabled) we kan put multiple big screens on our service desk.
Access to this dashboard should be restricted by IP address and/or an URL or something like this.
180 votesNot something we currently prioritized, but let’s see how much interest it generates.
So far we indeed think of this more in terms of spreading knowledge/information to the right people thru RBAC on their devices (i.e. see Mobile app to always be close to the data…).
-
Collect IIS Logs from Windows Azure Diagnostics storage (WAD) for Azure Web Sites
Azure WebSites write to WAD in a different folder structure. The work of this other idea http://feedback.azure.com/forums/267889-azure-operations-insights/suggestions/6519377-collect-iis-logs-from-windows-azure-diagnostics-st enables reading those IIS logs for Azure Cloud Services (i.e. web role instances) but not for Azure Web sites.
This new idea is for the latter scope.147 votesCloud Services / Virtual Machines write with a different container/folder structure in Azure blob than Azure WebSites. Our current ingestion processes the former, not the latter.
Anyhow, also consider the ‘generic’ idea of a platform feature to ingest your own logs http://feedback.azure.com/forums/267889-azure-operational-insights/suggestions/7928931-collect-data-from-custom-containers-in-storage-acc
-
Allow to create multiple Dashboards
Need option to create more custom Dashboards. Within a Dashboard we need option to segregate tiles into different custom categories\Headings like all tiles of IIS into one area of Dashboard and all SQL into another.
123 votesHi, we also now have an API – so you can take your search results in your visualization tool of choice http://feedback.azure.com/forums/267889-azure-operational-insights/suggestions/6519057-programmatically-submit-search-requests-and-receiv
we are also exploring intergating with PowerBI http://feedback.azure.com/forums/267889-azure-operational-insights/suggestions/6519374-integrate-with-powerbi-allow-to-query-and-refresAs for the ‘in portal’ dashboards, ‘My Dashboard’ is meant to be just the beginning to introduce a new paradigm of pinning searches as tiles.
We have a vision to eventually allow to create/export/package multiple dashboards, both for users and for partners/vendors – check these other ideas
http://feedback.azure.com/forums/267889-azure-operational-insights/suggestions/6519372-allow-to-export-an-intelligence-pack-bundle-that-c that you can move across workspaces and http://feedback.azure.com/forums/267889-azure-operational-insights/suggestions/6519273-allow-me-to-submit-an-inteligence-pack-bundle-to-t -
BizTalk Server Intelligence pack
Create an Intelligence pack for BizTalk Server, something similar to BizTalk Server 2013 Monitoring Management Pack:
- Application Views
- Application Artifacts Views
- Deployment Views
- BAM Component Views
- BAM Alerts
etcAs a MS partner company we have several customers very interested in this feature!!
120 votesThat’s a quote a lot of votes from a bunch of new users in a very short time, although 9 people are from the same two companies and 7 other are anonymous, and a few other ones. Let’s see how generally applicable/widespread the demand is.
Also see the comment from Daniele M. below for general considerations about monitoring scenarios.
Let’s also clarify (this is not clear in the request): is the request to support:
a) ‘traditional’ on-premises BizTalk
or
b) Azure BizTalk services
? -
Show Contextual data such as CPU and RAM for servers
When I click over a list that shows servers and select a given server from the list it would be nice to get a quick overview of the system. Such as OS SKU, CPU, RAM, Disk Free and so on.
119 votesWe have not forgotten about this but this is a multi-faceted feedback that expresses a desire (show me/let me pivot to contextual data), but besides the graphical interaction we need to bring the right capabilities and the right data types to the platform first.
A first step in this direction is the common ‘Computer’ field – http://feedback.azure.com/forums/267889-azure-operations-insights/suggestions/6519266-unify-standardize-computer-field-across-intellig
that allows you to pivot from one data type to another, and to join different data types thru sub-searches http://feedback.azure.com/forums/267889-azure-operational-insights/suggestions/6519234-filter-groups-of-computers-thru-subqueries-in-n
(which anyhow are generic and work with other fields too)We are starting to discuss what a UX for ‘context’ could look like, but we are not finished with bringing in new data types to make that really compelling :-)
One example of such ‘context’ is in the form of tracking configuration changes – http://feedback.azure.com/forums/267889-azure-operations-insights/suggestions/6519185-need-configuration-change-tracking-solution-softw so you can move from a troubleshooting scenario (capacity or events) to a ‘context’ of what has changed…
-
Use Windows Event Forwarding (WEF) to send events to OpInsights
Would it be cool if you could configure Windows Server WEF (Windows Event Forwarding - http://technet.microsoft.com/en-us/library/cc748890.aspx ) to send to Advisor for Log Management scenario, without using the SCOM agent ?
Alternatively, if one already has a forwarder/collector (WEF/WEC) architecture in place, could it be possible to use just one SCOM agent/gateway to pull the 'forwarded' logs stored on that collector from that single box to the cloud.118 votesThis is an idea we heard from a customer. Are other folks using WEF as a central/intermediate collection point?
-
One Overall OMS Dashboard integraded with SCOM - Cisco Prime -Solarwinds
Lot of Enterprise organizations have Multi monitor environment Like Microsoft SCOM for Servers in the Datacenter, Cisco Prime for network infrastructure like WiFi and SolarWinds for Network components. Monitoring from outside to inside like Microsoft OMS could be the Service in the middle and make One single Dashboard for the Business, but also for IT Pro's.
98 votes4 comments · Agent Management, Data Metering and Usage (Portal) · Flag idea as inappropriate… · Admin →Thanks you for taking the time to provide this feedback. We are looking at developing a centralized alerting view which will support monitoring tools like Nagios, Zabbix, Solarwinds. If you are interested in participating on the private preview of this solution please email me.
- Don't see your idea?
