官术网_书友最值得收藏!

Querying logs in Azure Monitor

To query logs in Azure monitor, perform the following steps:

  1. Navigate to the Azure portal by opening https://portal.azure.com.
  2. In the left-hand menu, select Monitoring to open the Azure Monitor overview blade. Under Insights, select More. This will open the Log Analytics workspace that we created in the previous step.  
  1. On the overview page, click on Logs in the top menu. This will open the Azure Monitor query editor:
Azure Monitor query editor
  1. Here, you can select some default queries. They are displayed at the bottom part of the screen. There are queries for retrieving unavailable computers, the last heartbeat of a computer, and much more. Add the following queries to the query editor window to retrieve data:
    • This query will retrieve the top 10 computers with the most error events over the past day:
Event | where (EventLevelName == "Error") | where (TimeGenerated > ago(1days)) | summarize ErrorCount = count() by Computer | top 10 by ErrorCount desc

    • This query will create a line chart with the processor utilization for each computer from last week:
Perf | where ObjectName == "Processor" and CounterName == "% Processor Time" | where TimeGenerated between (startofweek(ago(7d)) .. endofweek(ago(7d)) ) | summarize avg(CounterValue) by Computer, bin(TimeGenerated, 5min) | render timechart 
A detailed overview and tutorial on how to get started with the Kusto  Query Language is beyond the scope of this book. If you want to find out more about this query language, you can refer to  https://docs.microsoft.com/en-us/azure/azure-monitor/log-query/get-started-queries.
主站蜘蛛池模板: 平阳县| 乌兰浩特市| 南通市| 大同县| 泾阳县| 东港市| 贺兰县| 云安县| 涟源市| 海林市| 苗栗市| 安庆市| 工布江达县| 界首市| 凤山市| 家居| 泰和县| 云阳县| 叶城县| 浑源县| 和林格尔县| 温州市| 永州市| 永泰县| 老河口市| 平凉市| 调兵山市| 青阳县| 南川市| 开阳县| 凌云县| 平顶山市| 上林县| 增城市| 赣州市| 本溪| 错那县| 金溪县| 临澧县| 孟津县| 嵊州市|