Azure Monitor Log Analytics 示例查询

Azure Monitor 资源日志是 Azure 服务发出的日志,用于描述这些服务或资源的操作。 日志导出到 Log Analytics 工作区后,会存储在表中。 本系列文章包含用于从 Log Analytics 表中检索数据的示例查询。 这些查询也可以在 Log Analytics 工作区中使用。

按表列出的示例查询

AACAudit

AACHttpRequest

AAD自定义安全属性审核日志

AAD域服务帐户登录

AADDomainServicesAccountManagement

AADDomainServicesDirectoryServiceAccess

AAD域服务登录注销

AADDomainServices策略变更

AADDomainServicesPrivilegeUse

AADManagedIdentitySignInLogs

AAD非互动用户登录日志

AADProvisioningLogs

AADRiskyUsers

AADServicePrincipalRiskEvents

AADServicePrincipalSignInLogs

AADUserRiskEvents(用户风险事件)

ABAPAuditLog

ABSBotRequests

ACICollaborationAudit

ACRConnectedClientList

ACREntra身份验证审计日志

ACS高级消息操作

ACSAuthIncomingOperations

ACSBillingUsage

ACSCallAutomationIncomingOperations

ACSCallAutomation媒体摘要

ACSCallClientMediaStatsTimeSeries

ACSCallClientOperations

ACSCallDiagnostics

ACS通话诊断更新

ACSCallRecordingIncomingOperations

ACS通话录音摘要

ACSCallSummary

ACS通话摘要更新

ACSCallSurvey

ACSChatIncomingOperations

ACSEmailSendMailOperational

ACS邮件状态更新正常

ACSJobRouterIncomingOperations

ACSRoomsIncomingOperations

ACSSMSIncomingOperations

ADAssessmentRecommendation

ADFActivityRun

ADFPipelineRun

ADFSSignInLogs

ADFTriggerRun

ADTDataHistoryOperation

ADTDigitalTwinsOperation

ADTEventRoutesOperation

ADTModelsOperation

ADTQueryOperation

ADXIngestionBatching

ADX表格使用统计

AEWComputePipelinesLogs

AEWExperimentAssignmentSummary

AEW实验计分卡度量对

AEWExperimentScorecards

AFSAuditLogs

AGCAccessLogs

AGSGrafanaLoginEvents

AHDSDicomAuditLogs

AHDSDicomDiagnosticLogs

AHDSMedTechDiagnosticLogs

AKSAudit

AKSAuditAdmin

AKSControlPlane

ALBHealthEvent

AMS密钥交付请求

AMSLiveEventOperations

AMSMediaAccountHealth

AMS串流端点请求

AOIDatabaseQuery

AOIDigestion

AOIStorage

ASCDeviceEvents

ASRJobs

ASR复制项

ASimDnsActivityLogs

ATCExpressRouteCircuitIpfix

AVNM连接配置更改

AVNMIPAMPoolAllocationChange

AVNM网络群组成员变更

AVNM规则集更改

AVSSyslog

AWSCloudTrail

AWSGuardDuty

AWSVPCFlow

AZFWApplicationRule

AZFWDnsQuery

AZFWFatFlow

AZFWFlowTrace

AZFWIdpsSignature

AZFW内部FQDN解析失败

AZFWNatRule

AZFWNetworkRule

AZFWThreatIntel

AZKVAuditLogs

AZMSDiagnosticErrorLogs

AZMS混合连接事件

AZMSOperationalLogs

AZMS运行时审核日志

AZMSVnetConnectionEvents

AddonAzureBackupJobs

AddonAzureBackupStorage

AegDataPlaneRequests

AegDeliveryFailureLogs

AegPublishFailureLogs

AggregatedSecurityAlert

AgriFoodApplicationAuditLogs

AgriFoodFarmManagementLogs

AgriFoodJobProcessedLogs (农业食品工作处理日志)

AlertEvidence

AlertInfo

AmlComputeClusterEvent

AmlCompute CPU GPU 利用率

AmlComputeJobEvent

AmlDataSetEvent

AmlEnvironmentEvent

AmlModelsEvent

AmlOnlineEndpointConsoleLog

AmlOnlineEndpointEventLog

AmlOnlineEndpointTrafficLog

AmlRegistryWriteEventsLog

异常

ApiManagementGatewayLogs

AppDependencies

AppExceptions

AppPageViews

AppPlatformLogsforSpring

AppPlatformSystemLogs

AppRequests

AppServiceAppLogs

AppServiceAuditLogs

AppServiceAuthenticationLogs

AppServiceConsoleLogs

AppServiceFileAuditLogs

AppServiceHTTPLogs

AutoscaleEvaluationsLog

自动缩放操作日志

AzureActivity

AzureAttestationDiagnostics

AzureBackupOperations

AzureDiagnostics

AzureLoadTestingOperation

AzureMetrics

CCFApplicationLogs

CIEventsAudit

CIEventsOperational

CassandraLogs

ChaosStudioExperimentEventLogs

CloudAppEvents

CloudHsmServiceOperationAuditLogs

CommonSecurityLog

通信合规活动

ConfidentialWatchlist

配置变更

ConfigurationData

ContainerImageInventory

ContainerInventory

ContainerLog

ContainerLogV2

ContainerNodeInventory

容器注册登录事件

容器注册表库事件

ContainerServiceLog

CoreAzureBackup

DCRLogErrors

DNSQueryLogs

DataTransferOperations

Databricks预算政策中心

DataverseActivity

DevCenterBillingEventLogs

DevCenterDiagnosticLogs

DevCenterResourceOperationLogs

DeviceCalendar

DeviceCleanup

DeviceHardwareHealth

DeviceHealth

DeviceSkypeHeartbeat

设备TVM安全配置评估

DeviceTvmSoftwareInventory

设备Tvm软件漏洞

DnsEvents

EGN失败的Http数据平面操作

EGN失败Mqtt连接

EGNMqttDisconnections

EGN成功的Http数据平面操作

EGNSuccessfulMqttConnections(成功的MQTT连接)

电子邮件附件信息

电子邮件事件

电子邮件投递后事件

EmailUrlInfo

事件

数据导入失败

FunctionAppLogs

GCPAuditLogs

Heartbeat

IdentityDirectoryEvents

身份登录事件

IdentityQueryEvents

InsightsMetrics

KubeEvents

KubeMonAgentEvents

KubeNodeInventory

KubePodInventory

KubeServices

LAQueryLogs

LASummaryLogs

LogicAppWorkflowRuntime

MDCDetectionDNSEvents

MDCDetectionFimEvents

MDCDetectionGatingValidationEvents

MNFDeviceUpdates

MNF系统会话历史更新

MNF系统状态消息更新

微软数据共享接收快照日志 (MicrosoftDataShareReceivedSnapshotLog)

MicrosoftDataShareSentSnapshotLog

MicrosoftGraphActivityLogs

MicrosoftPurviewInformationProtection

NGXOperationLogs

NGXSecurityLogs

NW连接监控路径结果

NWConnectionMonitorTestResult

NatGatewayFlowlogsV1

NetworkSessions

NginxUpstreamUpdateLogs

OEPAirFlowTask

OEPDataplaneLogs

OEWExperimentAssignmentSummary

OEW实验成绩卡指标对

OEWExperimentScorecards

OLPSupplyChainEntityOperations

OfficeActivity

性能

PowerAppsActivity

PowerAutomateActivity

PowerBIActivity

PowerPlatformAdminActivity

PowerPlatformConnectorActivity

PowerPlatformDlpActivity

ProjectActivity

ProtectionStatus

PurviewSecurityLogs

REDConnectionEvents

ResourceManagementPublicAccessLogs

RetinaNetworkFlowLogs

SCGPoolExecutionLog

SCGPoolRequestLog

SQL评估建议

SVMPoolExecutionLog

SVMPoolRequestLog

SecurityAttackPathData

SecurityEvent

SentinelAudit

SignalRServiceDiagnosticLogs

SigninLogs

StorageBlobLogs

存储缓存操作事件

存储缓存升级事件

存储缓存警告事件

存储恶意软件扫描结果

成功输入

SynapseLinkEvent

Syslog

TOUserAudits

TOUserDiagnostics

TSIIngress

UCDOAggregatedStatus

UCDOStatus

更新

UpdateRunProgress

UpdateSummary

UrlClickEvents

使用情况

VCoreMongoRequests

VIAudit

VIIndexing

W3CIISLog

WOUserAudits

WOUserDiagnostics

WVDAgentHealthStatus

WVDCheckpoints

WVDConnectionNetworkData

WVDConnections

WVDErrors

WaaSDeploymentStatus

WaaSUpdateStatus

监视列表

WindowsEvent

WireData

WorkloadDiagnosticLogs

后续步骤