官术网_书友最值得收藏!

Querying logs in Azure Monitor

To query logs in Azure monitor, perform the following steps:

  1. Navigate to the Azure portal by opening https://portal.azure.com.
  2. In the left-hand menu, select Monitoring to open the Azure Monitor overview blade. Under Insights, select More. This will open the Log Analytics workspace that we created in the previous step.  
  1. On the overview page, click on Logs in the top menu. This will open the Azure Monitor query editor:
Azure Monitor query editor
  1. Here, you can select some default queries. They are displayed at the bottom part of the screen. There are queries for retrieving unavailable computers, the last heartbeat of a computer, and much more. Add the following queries to the query editor window to retrieve data:
    • This query will retrieve the top 10 computers with the most error events over the past day:
Event | where (EventLevelName == "Error") | where (TimeGenerated > ago(1days)) | summarize ErrorCount = count() by Computer | top 10 by ErrorCount desc

    • This query will create a line chart with the processor utilization for each computer from last week:
Perf | where ObjectName == "Processor" and CounterName == "% Processor Time" | where TimeGenerated between (startofweek(ago(7d)) .. endofweek(ago(7d)) ) | summarize avg(CounterValue) by Computer, bin(TimeGenerated, 5min) | render timechart 
A detailed overview and tutorial on how to get started with the Kusto  Query Language is beyond the scope of this book. If you want to find out more about this query language, you can refer to  https://docs.microsoft.com/en-us/azure/azure-monitor/log-query/get-started-queries.
主站蜘蛛池模板: 定远县| 嘉鱼县| 茂名市| 西峡县| 岑溪市| 新竹市| 凤山县| 宜州市| 丽水市| 南溪县| 额济纳旗| 土默特右旗| 泸溪县| 五大连池市| 富源县| 维西| 寿光市| 恩施市| 成武县| 五莲县| 南木林县| 融水| 呼和浩特市| 苏尼特左旗| 读书| 涪陵区| 芜湖县| 五大连池市| 大连市| 油尖旺区| 环江| 醴陵市| 资兴市| 天祝| 湘潭县| 平谷区| 射洪县| 泰兴市| 高要市| 临猗县| 阜城县|