Azure Monitor log Analytics 示例查询。

Azure Monitor资源日志是由描述这些服务或资源的作的Azure服务发出的日志。 导出到 Log Analytics 工作区时日志存储在表中。 本系列文章包含用于从 Log Analytics 表中检索数据的示例查询。 查询也可以在Log Analytics工作区中使用。

按表列出的示例查询

AACAudit

AACHttpRequest

AADCustomSecurityAttributeAuditLogs

AADDomainServicesAccountLogon

AADDomainServicesAccountManagement

AADDomainServicesDirectoryServiceAccess

AADDomainServicesLogonLogoff

AADDomainServicesPolicyChange

AADDomainServicesPrivilegeUse

AADDomainServicesSystemSecurity

AADGraphActivityLogs

AADManagedIdentitySignInLogs

AADNonInteractiveUserSignInLogs

AADProvisioningLogs

AADRiskyUsers

AADServicePrincipalRiskEvents

AADServicePrincipalSignInLogs

AAD 用户风险事件

ABAPAuditLog

ABSBotRequests

ACICollaborationAudit

ACLTransactionLogs

ACLUserDefinedLogs

ACRConnectedClientList

ACREntraAuthenticationAuditLog

ACSAdvancedMessagingOperations

ACSAuthIncomingOperations

ACSBillingUsage

ACSCallAutomationIncomingOperations

ACSCallAutomationMediaSummary

ACSCallAutomationStreamingUsage

ACSCallClientMediaStatsTimeSeries

ACSCallClientOperations

ACSCallDiagnostics

ACS通话诊断更新

ACSCallRecordingIncomingOperations

ACSCallRecordingSummary

ACSCallSummary

ACSCallSummaryUpdates

ACSCallSurvey

ACSChatIncomingOperations

ACSEmailSendMailOperational

ACSEmailStatusUpdateOperational

ACSJobRouterIncomingOperations

ACSRoomsIncomingOperations

ACSSMSIncomingOperations

ADAssessmentRecommendation

ADFActivityRun

ADFPipelineRun

ADFSSignInLogs

ADFTriggerRun

ADTDataHistoryOperation

ADTDigitalTwinsOperation

ADTEventRoutesOperation

ADTModelsOperation

ADTQueryOperation

ADXIngestionBatching

ADXTableUsageStatistics

AEWComputePipelinesLogs

AEWExperimentAssignmentSummary

AEWExperimentScorecardMetricPairs

AEWExperimentScorecards

AFSAuditLogs

AGCAccessLogs

AGSGrafanaLoginEvents

AGSUpdateEvents

AHCIDiagnosticLogs

AHDSDicomAuditLogs

AHDSDicomDiagnosticLogs

AHDSMedTechDiagnosticLogs

AKSAudit

AKSAuditAdmin

AKSControlPlane

ALBHealthEvent

AMSKeyDeliveryRequests

AMSLiveEventOperations

AMSMediaAccountHealth

AMSStreamingEndpointRequests

AOIDatabaseQuery

AOIDigestion

AOIStorage

ASCDeviceEvents

ASRJobs

ASRReplicatedItems

ASimAlertEventLogs

ASimDnsActivityLogs

ATCExpressRouteCircuitIpfix

AVNMConnectivityConfigurationChange

AVNMIPAMPoolAllocationChange

AVNMNetworkGroupMembershipChange

AVNMRuleCollectionChange

AVSSyslog

AWSCloudTrail

AWSGuardDuty

AWSVPCFlow

AZFWApplicationRule

AZFWDnsQuery

AZFWFatFlow

AZFWFlowTrace

AZFWIdpsSignature

AZFW内部FQDN解析失败

AZFWNatRule

AZFWNetworkRule

AZFWThreatIntel

AZKVAuditLogs

AZMSDiagnosticErrorLogs

AZMSHybridConnectionsEvents

AZMSOperationalLogs

AZMSRunTimeAuditLogs

AZMSVnetConnectionEvents

AddonAzureBackupJobs

AddonAzureBackupStorage

AegDataPlaneRequests

AegDeliveryFailureLogs

AegPublishFailureLogs

AggregatedSecurityAlert

AgriFoodApplicationAuditLogs

AgriFoodFarmManagementLogs

AgriFoodJobProcessedLogs

AlertEvidence

AlertInfo

AmlComputeClusterEvent

AmlComputeCpuGpuUtilization

AmlComputeJobEvent

AmlDataSetEvent

AmlEnvironmentEvent

AmlModelsEvent

AmlOnlineEndpointConsoleLog

AmlOnlineEndpointEventLog

AmlOnlineEndpointTrafficLog

AmlRegistryWriteEventsLog

异常

ApiManagementGatewayLogs

AppDependencies

AppExceptions

AppPageViews

AppPlatformLogsforSpring

AppPlatformSystemLogs

AppRequests

AppServiceAppLogs

AppServiceAuditLogs

AppServiceAuthenticationLogs

AppServiceConsoleLogs

AppServiceFileAuditLogs

AppServiceHTTPLogs

AutoscaleEvaluationsLog

AutoscaleScaleActionsLog

AzureActivity

AzureAttestationDiagnostics

AzureBackupOperations

AzureDiagnostics

AzureLoadTestingOperation

AzureMetrics

CCFApplicationLogs

CIEventsAudit

CIEventsOperational

CassandraLogs

ChaosStudioExperimentEventLogs

CloudAppEvents

CloudHsmServiceOperationAuditLogs

CommonSecurityLog

通信合规活动

ConfidentialWatchlist

配置变更

ConfigurationData

ContainerImageInventory

ContainerInventory

ContainerLog

ContainerLogV2

ContainerNetworkLogs

ContainerNodeInventory

ContainerRegistryLoginEvents

ContainerRegistryRepositoryEvents

ContainerServiceLog

CopilotActivity

CoreAzureBackup

CrowdStrikeAlerts

CrowdStrikeCases

CrowdStrikeDetections

CrowdStrikeIncidents

DCRLogErrors

DNSQueryLogs

DataSetOutput

DataSetRuns

DataTransferOperations

DatabricksBudgetPolicyCentral

DataverseActivity

DevCenterAgentHealthLogs

DevCenterBillingEventLogs

DevCenterDiagnosticLogs

DevCenterResourceOperationLogs

DeviceCalendar

DeviceCleanup

DeviceHardwareHealth

DeviceHealth

DeviceSkypeHeartbeat

设备TVM安全配置评估

DeviceTvmSoftwareInventory

设备Tvm软件漏洞

DnsEvents

DurableTaskSchedulerLogs

EGNFailedHttpDataPlaneOperations

EGNFailedMqttConnections

EGNMqttDisconnections

EGNSuccessfulHttpDataPlaneOperations

EGNSuccessfulMqttConnections

EdgeActionConsoleLog

电子邮件附件信息

EmailEvents

EmailPostDeliveryEvents

EmailUrlInfo

事件

FailedIngestion

FunctionAppLogs

GCPAuditLogs

心跳

IdentityDirectoryEvents

身份登录事件

IdentityQueryEvents

IlumioInsights

InsightsMetrics

KubeEvents

KubeMonAgentEvents

KubeNodeInventory

KubePodInventory

KubeServices

LAJobLogs

LAQueryLogs

LASummaryLogs

LogicAppWorkflowRuntime

MDCDetectionDNSEvents

MDCDetectionFimEvents

MDCDetectionGatingValidationEvents

MNFDeviceUpdates

MNFSystemSessionHistoryUpdates

MNFSystemStateMessageUpdates

MeshControlPlane

MicrosoftDataShareReceivedSnapshotLog

MicrosoftDataShareSentSnapshotLog

MicrosoftGraphActivityLogs

MicrosoftPurviewInformationProtection

MySqlAuditLogs

MySqlSlowLogs

NGXOperationLogs

NGXSecurityLogs

NTARuleRecommendation

NWConnectionMonitorPathResult

NWConnectionMonitorTestResult

NetworkSessions

NginxUpstreamUpdateLogs

OEPAirFlowTask

OEPDataplaneLogs

OEWExperimentAssignmentSummary

OEWExperimentScorecardMetricPairs

OEWExperimentScorecards

OLPSupplyChainEntityOperations

OTelEvents

OTelLogs

OTelSpans

OfficeActivity

OktaSystemLogs

PGSQLAutovacuumStats

PGSQLDbTransactionsStats

PGSQLPgBouncer

PGSQLPgStatActivitySessions

PGSQLQueryStoreRuntime

PGSQLQueryStoreWaits

PGSQLServerLogs

Perf

PerfInsightsImpactedResources

PowerAppsActivity

PowerAutomateActivity

PowerBIActivity

PowerPlatformAdminActivity

PowerPlatformConnectorActivity

PowerPlatformDlpActivity

ProjectActivity

ProtectionStatus

PurviewSecurityLogs

QualysKnowledgeBase

REDConnectionEvents

ResourceManagementPublicAccessLogs

RetinaNetworkFlowLogs

SCGPoolExecutionLog

SCGPoolRequestLog

SQL评估建议

SVMPoolExecutionLog

SVMPoolRequestLog

SecurityAttackPathData

SecurityEvent

SentinelAudit

SignalRServiceDiagnosticLogs

SigninLogs

StorageBlobLogs

StorageCacheOperationEvents

StorageCacheUpgradeEvents

StorageCacheWarningEvents

存储恶意软件扫描结果

SucceededIngestion

SynapseLinkEvent

Syslog

TOUserAudits

TOUserDiagnostics

TSIIngress

UCDOAggregatedStatus

UCDOStatus

更新

UpdateRunProgress

UpdateSummary

UrlClickEvents

用法

VCoreMongoRequests

VIAudit

VIIndexing

W3CIISLog

WOUserAudits

WOUserDiagnostics

WVDAgentHealthStatus

WVDCheckpoints

WVDConnectionNetworkData

WVDConnections

WVDErrors

WaaSDeploymentStatus

WaaSUpdateStatus

Watchlist

WindowsEvent

WireData

WorkloadDiagnosticLogs

ZTSRequest

后续步骤