Azure Monitor Log Analytics 示例查询。

Azure Monitor 资源日志是 Azure 服务发出的日志,用于描述这些服务或资源的操作。 日志导出到 Log Analytics 工作区后,会存储在表中。 本系列文章包含用于从 Log Analytics 表中检索数据的示例查询。 这些查询也可以在 Log Analytics 工作区中使用。

按表列出的示例查询

AACAudit

AACHttpRequest

AAD自定义安全属性审核日志

AAD域服务账户登录

AADDomainServicesAccountManagement

AADDomainServicesDirectoryServiceAccess

AAD域服务登录注销

AAD域服务策略更改

AADDomainServicesPrivilegeUse

AADGraphActivityLogs

AADManagedIdentitySignInLogs

AAD非互动用户登录日志

AADProvisioningLogs

AADRiskyUsers

AADServicePrincipalRiskEvents

AADServicePrincipalSignInLogs

AADUserRiskEvents

ABAPAuditLog

ABSBotRequests

ACICollaborationAudit

ACRConnectedClientList

ACREntra认证审计日志

ACS高级消息操作

ACSAuthIncomingOperations

ACSBillingUsage

ACSCallAutomationIncomingOperations

ACSCallAutomation媒体摘要

ACSCallAutomationStreamingUsage

ACSCallClientMediaStatsTimeSeries

ACSCallClientOperations

ACSCallDiagnostics

ACS通话诊断更新

ACSCallRecordingIncomingOperations

ACS通话录音概要

ACSCallSummary

ACSCallSummaryUpdates

ACSCallSurvey

ACSChatIncomingOperations

ACSEmailSendMailOperational

ACS邮件状态更新正常

ACSJobRouterIncomingOperations

ACSRoomsIncomingOperations

ACSSMSIncomingOperations

ADAssessmentRecommendation

ADFActivityRun

ADFPipelineRun

ADFSSignInLogs

ADFTriggerRun

ADTDataHistoryOperation

ADTDigitalTwinsOperation

ADTEventRoutesOperation

ADTModelsOperation

ADTQueryOperation

ADXIngestionBatching

ADX表格使用统计

AEWComputePipelinesLogs

AEWExperimentAssignmentSummary

AEWExperimentScorecardMetricPairs

AEWExperimentScorecards

AFSAuditLogs

AGCAccessLogs

AGSGrafanaLoginEvents

AHDSDicomAuditLogs

AHDSDicomDiagnosticLogs

AHDSMedTechDiagnosticLogs

AKSAudit

AKSAuditAdmin

AKSControlPlane

ALBHealthEvent

AMS密钥交付请求

AMSLiveEventOperations

AMSMediaAccountHealth

AMS流媒体端点请求

AOIDatabaseQuery

AOIDigestion

AOIStorage

ASCDeviceEvents

ASRJobs

ASRReplicatedItems

ASimDnsActivityLogs

ATCExpressRouteCircuitIpfix

AVNM连接配置更改

AVNMIPAMPoolAllocationChange

AVNm网络组成员变更

AVNMRuleCollectionChange

AVSSyslog

AWSCloudTrail

AWSGuardDuty

AWSVPCFlow

AZFWApplicationRule

AZFWDnsQuery

AZFWFatFlow

AZFWFlowTrace

AZFWIdpsSignature

AZFW内部FQDN解析失败

AZFWNatRule

AZFWNetworkRule

AZFWThreatIntel

AZKVAuditLogs

AZMSDiagnosticErrorLogs

AZMS混合连接事件

AZMSOperationalLogs

AZMS运行时审核日志

AZMSVnetConnectionEvents

AddonAzureBackupJobs

AddonAzureBackupStorage

AegDataPlaneRequests

AegDeliveryFailureLogs

AegPublishFailureLogs

AggregatedSecurityAlert

AgriFoodApplicationAuditLogs

AgriFoodFarmManagementLogs

AgriFoodJobProcessedLogs

AlertEvidence

AlertInfo

AmlComputeClusterEvent

AmlCompute CPU GPU 利用率

AmlComputeJobEvent

AmlDataSetEvent

AmlEnvironmentEvent

AmlModelsEvent

AmlOnlineEndpointConsoleLog

Aml在线端点事件日志

AmlOnlineEndpointTrafficLog (在线终端流量日志)

AmlRegistryWriteEventsLog

异常

ApiManagementGatewayLogs

AppDependencies

AppExceptions

AppPageViews

AppPlatformLogsforSpring

AppPlatformSystemLogs

AppRequests

AppServiceAppLogs

AppServiceAuditLogs

AppServiceAuthenticationLogs

AppServiceConsoleLogs

AppServiceFileAuditLogs

AppServiceHTTPLogs

AutoscaleEvaluationsLog

AutoscaleScaleActionsLog

AzureActivity

AzureAttestationDiagnostics

AzureBackupOperations

AzureDiagnostics

AzureLoadTestingOperation

AzureMetrics

CCFApplicationLogs

CIEventsAudit

CIEventsOperational

CassandraLogs

ChaosStudioExperimentEventLogs

CloudAppEvents

CloudHsmServiceOperationAuditLogs

CommonSecurityLog

通信合规活动

ConfidentialWatchlist

配置更改

ConfigurationData

ContainerImageInventory

ContainerInventory

ContainerLog

ContainerLogV2

ContainerNodeInventory

ContainerRegistryLoginEvents

容器注册表库事件

ContainerServiceLog

CoreAzureBackup

DCRLogErrors

DNSQueryLogs

DataTransferOperations

Databricks预算政策中心

DataverseActivity

DevCenterAgentHealthLogs

DevCenterBillingEventLogs

DevCenterDiagnosticLogs

DevCenterResourceOperationLogs

DeviceCalendar

DeviceCleanup

DeviceHardwareHealth

DeviceHealth

DeviceSkypeHeartbeat

设备TVM安全配置评估

DeviceTvmSoftwareInventory

设备Tvm软件漏洞

DnsEvents

EGNFailedHttpDataPlaneOperations

EGNFailedMqttConnections

EGNMqttDisconnections

EGNSuccessfulHttpDataPlaneOperations

EGNSuccessfulMqttConnections(成功的MQTT连接)

电子邮件附件信息

EmailEvents

EmailPostDeliveryEvents

EmailUrlInfo

事件

数据导入失败

FunctionAppLogs

GCPAuditLogs

检测信号

IdentityDirectoryEvents

身份登录事件

IdentityQueryEvents

IlumioInsights

InsightsMetrics

KubeEvents

KubeMonAgentEvents

KubeNodeInventory

KubePodInventory

KubeServices

LAQueryLogs

LASummaryLogs

LogicAppWorkflowRuntime

MDCDetectionDNSEvents

MDCDetectionFimEvents

MDCDetectionGatingValidationEvents

MNFDeviceUpdates

MNF系统会话历史更新

MNF系统状态消息更新

微软数据共享接收快照日志 (MicrosoftDataShareReceivedSnapshotLog)

MicrosoftDataShareSentSnapshotLog

MicrosoftGraphActivityLogs

MicrosoftPurviewInformationProtection

NGXOperationLogs

NGXSecurityLogs

NW连接监控路径结果

NWConnectionMonitorTestResult

NatGatewayFlowlogsV1

NetworkSessions

NginxUpstreamUpdateLogs

OEPAirFlowTask

OEPDataplaneLogs

OEWExperimentAssignmentSummary

OEWExperimentScorecardMetricPairs

OEWExperimentScorecards

OLPSupplyChainEntityOperations

OfficeActivity

OktaSystemLogs

Perf

PowerAppsActivity

PowerAutomateActivity

PowerBIActivity

PowerPlatformAdminActivity

PowerPlatformConnectorActivity

PowerPlatformDlpActivity

ProjectActivity

ProtectionStatus

PurviewSecurityLogs

REDConnectionEvents

ResourceManagementPublicAccessLogs

RetinaNetworkFlowLogs

SCGPoolExecutionLog

SCGPoolRequestLog

SQL评估建议 (SQLAssessmentRecommendation)

SVMPoolExecutionLog

SVMPoolRequestLog

SecurityAttackPathData

SecurityEvent

SentinelAudit

SignalRServiceDiagnosticLogs

SigninLogs

StorageBlobLogs

存储缓存操作事件

存储缓存升级事件

存储缓存警告事件

存储恶意软件扫描结果

成功摄取

SynapseLinkEvent

Syslog

TOUserAudits

TOUserDiagnostics

TSIIngress

UCDOAggregatedStatus

UCDOStatus

更新

UpdateRunProgress

UpdateSummary

UrlClickEvents

使用情况

VCoreMongoRequests

VIAudit

VIIndexing

W3CIISLog

WOUserAudits

WOUserDiagnostics

WVDAgentHealthStatus

WVDCheckpoints

WVDConnectionNetworkData

WVDConnections

WVDErrors

WaaSDeploymentStatus

WaaSUpdateStatus

监视列表

WindowsEvent

WireData

WorkloadDiagnosticLogs

后续步骤