Collect Custom Windows Event Logs in Log Analytics

Log AnalyticsAdding most Windows Event Logs to Log Analytics is a straightforward process.  Simply go to the Advanced properties in the Workspace > Windows Event Logs and start typing the name.  A pre-populated list will appear as shown below.  Selected the log and add it for collection.  But what if the log you are looking for is not listed in Log Analytics?

Computer Groups In Azure Log Analytics

Log AnalyticsComputer Groups in Azure Log Analytics can easily be overlooked yet they are very useful.  Computer Groups are based off custom log searches or linked to Active Directory, SCCM or WSUS and based off groups in those systems.

No Data in Network Overview Tile

This week I noticed an issue with no data showing in the Azure Network (Total), Network Out (Sum) and Network In (Sum) tile in the Azure Virtual Machine Overview.  I recall noticing this before but couldn't remember how long ago that was.  Looking at other VM's, most of my them were missing the Network Total information.  The only servers that were showing data are virtual firewall appliances.

Alerts Based on Rolling Averages in Log Analytics

This post will go over how to create an alert for Log Analytics that evaluates two recent time periods for comparison. It's a little, let's say, "in depth" as far as Log Analytics queries go. The alert is intended to trigger when a variable threshold is met based on the recent baseline as opposed to a static metric. Used with my PingTimeLog tool found here, alerts can be triggered if recent response time goes over a rolling average value. I also include a disk free space alert to identify when a large amount of data is added to a disk.

Continue reading “Alerts Based on Rolling Averages in Log Analytics”