官术网_书友最值得收藏!

Querying logs in Azure Monitor

To query logs in Azure monitor, perform the following steps:

  1. Navigate to the Azure portal by opening https://portal.azure.com.
  2. In the left-hand menu, select Monitoring to open the Azure Monitor overview blade. Under Insights, select More. This will open the Log Analytics workspace that we created in the previous step.  
  1. On the overview page, click on Logs in the top menu. This will open the Azure Monitor query editor:
Azure Monitor query editor
  1. Here, you can select some default queries. They are displayed at the bottom part of the screen. There are queries for retrieving unavailable computers, the last heartbeat of a computer, and much more. Add the following queries to the query editor window to retrieve data:
    • This query will retrieve the top 10 computers with the most error events over the past day:
Event | where (EventLevelName == "Error") | where (TimeGenerated > ago(1days)) | summarize ErrorCount = count() by Computer | top 10 by ErrorCount desc

    • This query will create a line chart with the processor utilization for each computer from last week:
Perf | where ObjectName == "Processor" and CounterName == "% Processor Time" | where TimeGenerated between (startofweek(ago(7d)) .. endofweek(ago(7d)) ) | summarize avg(CounterValue) by Computer, bin(TimeGenerated, 5min) | render timechart 
A detailed overview and tutorial on how to get started with the Kusto  Query Language is beyond the scope of this book. If you want to find out more about this query language, you can refer to  https://docs.microsoft.com/en-us/azure/azure-monitor/log-query/get-started-queries.
主站蜘蛛池模板: 定州市| 达拉特旗| 双城市| 金华市| 临安市| 团风县| 德江县| 陆川县| 安图县| 会泽县| 舞阳县| 铜鼓县| 苗栗县| 会宁县| 辽源市| 桑日县| 太仓市| 江安县| 保德县| 即墨市| 丰都县| 永济市| 鸡东县| 贵溪市| 泰安市| 滨州市| 武冈市| 安塞县| 漾濞| 吐鲁番市| 榆树市| 华宁县| 湖口县| 巴楚县| 秦安县| 香河县| 镇原县| 浠水县| 麦盖提县| 深圳市| 兰坪|