Bird
Raised Fist0
Azurecloud~5 mins

Log Analytics workspace in Azure - Commands & Configuration

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Introduction
A Log Analytics workspace collects and stores data from your cloud and on-premises resources. It helps you search, analyze, and visualize logs to understand what is happening in your environment.
When you want to monitor the health and performance of your Azure resources in one place.
When you need to collect logs from multiple virtual machines to troubleshoot issues.
When you want to create alerts based on specific events or metrics in your infrastructure.
When you want to analyze security events across your cloud environment.
When you want to visualize trends and patterns from collected log data.
Config File - log_analytics_workspace.bicep
log_analytics_workspace.bicep
param workspaceName string = 'example-law'
param location string = 'eastus'

resource logAnalyticsWorkspace 'Microsoft.OperationalInsights/workspaces@2021-06-01' = {
  name: workspaceName
  location: location
  sku: {
    name: 'PerGB2018'
  }
  properties: {
    retentionInDays: 30
  }
}

output workspaceId string = logAnalyticsWorkspace.id

This Bicep file creates a Log Analytics workspace named 'example-law' in the East US region.

The sku defines the pricing tier, here 'PerGB2018' which is a common choice.

retentionInDays sets how long logs are kept, here 30 days.

The output workspaceId gives the resource ID for use in other deployments.

Commands
This command deploys the Log Analytics workspace to the resource group 'example-rg' using the Bicep template. It sets the workspace name and location.
Terminal
az deployment group create --resource-group example-rg --template-file log_analytics_workspace.bicep --parameters workspaceName=example-law location=eastus
Expected OutputExpected
{ "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/example-rg/providers/Microsoft.Resources/deployments/deploymentName", "name": "deploymentName", "properties": { "provisioningState": "Succeeded" }, "type": "Microsoft.Resources/deployments" }
→
--resource-group - Specifies the Azure resource group where the workspace will be created
→
--template-file - Points to the Bicep file defining the workspace
→
--parameters - Sets parameters like workspace name and location
This command retrieves details about the created Log Analytics workspace to verify it exists and check its properties.
Terminal
az monitor log-analytics workspace show --resource-group example-rg --workspace-name example-law
Expected OutputExpected
{ "customerId": "00000000-0000-0000-0000-000000000000", "location": "eastus", "name": "example-law", "retentionInDays": 30, "sku": { "name": "PerGB2018" }, "type": "Microsoft.OperationalInsights/workspaces" }
→
--resource-group - Specifies the resource group of the workspace
→
--workspace-name - Specifies the name of the workspace to show
Key Concept

If you remember nothing else from this pattern, remember: a Log Analytics workspace is your central place to collect and analyze logs from your Azure resources.

Common Mistakes
Trying to create a workspace without specifying the resource group
Azure needs a resource group to organize resources; without it, the command fails.
Always include the --resource-group flag with a valid resource group name.
Using an invalid or unsupported location for the workspace
Not all Azure regions support Log Analytics workspaces, so deployment fails if the location is unsupported.
Use a supported Azure region like 'eastus', 'westus2', or 'centralus'.
Not setting retentionInDays and expecting logs to be kept indefinitely
Logs are kept only for the retention period; if not set, default retention applies which may be shorter than expected.
Explicitly set retentionInDays in the configuration to control how long logs are stored.
Summary
Use a Bicep template to define and deploy a Log Analytics workspace with desired settings.
Deploy the workspace using Azure CLI with resource group and parameters specified.
Verify the workspace creation by retrieving its details with Azure CLI.

Practice

(1/5)
1. What is the main purpose of a Log Analytics workspace in Azure?
easy
A. To provide a user interface for managing Azure subscriptions
B. To host virtual machines and databases
C. To collect and store logs and metrics from cloud resources
D. To create backups of your data automatically

Solution

  1. Step 1: Understand the role of Log Analytics workspace

    A Log Analytics workspace is designed to gather and keep logs and metrics from various Azure resources.
  2. Step 2: Compare with other Azure services

    Hosting VMs, managing subscriptions, or backups are handled by other Azure services, not Log Analytics workspace.
  3. Final Answer:

    To collect and store logs and metrics from cloud resources -> Option C
  4. Quick Check:

    Log Analytics workspace = log and metric collection [OK]
Hint: Logs and metrics collection is the key function [OK]
Common Mistakes:
  • Confusing Log Analytics workspace with VM hosting
  • Thinking it manages subscriptions
  • Assuming it handles backups
2. Which of the following is the correct way to specify the retention period when creating a Log Analytics workspace in Azure CLI?
easy
A. --retention 30
B. --retention-time 30
C. --retention-days 30
D. --retention-period 30

Solution

  1. Step 1: Recall Azure CLI parameter for retention

    The correct parameter to set retention period in days is --retention-time.
  2. Step 2: Verify other options

    Options like --retention, --retention-days, or --retention-period are not valid Azure CLI parameters for this setting.
  3. Final Answer:

    --retention-time 30 -> Option B
  4. Quick Check:

    Retention period uses --retention-time [OK]
Hint: Retention period uses --retention-time flag [OK]
Common Mistakes:
  • Using incorrect parameter names
  • Confusing retention-time with retention-days
  • Omitting the unit (days)
3. Given the following Azure CLI command to create a Log Analytics workspace, what will be the retention period in days?
az monitor log-analytics workspace create --resource-group MyGroup --workspace-name MyWorkspace --location eastus --retention-time 45
medium
A. 45 days
B. 30 days
C. 90 days
D. Default retention period

Solution

  1. Step 1: Identify the retention parameter in the command

    The command uses --retention-time 45, which sets the retention period explicitly to 45 days.
  2. Step 2: Understand retention period effect

    This means logs and metrics will be kept for 45 days before automatic deletion.
  3. Final Answer:

    45 days -> Option A
  4. Quick Check:

    --retention-time 45 means 45 days retention [OK]
Hint: Look for --retention-time value in command [OK]
Common Mistakes:
  • Assuming default retention instead of specified
  • Confusing retention-time with other parameters
  • Ignoring the explicit retention-time flag
4. You tried to create a Log Analytics workspace with this command but got an error:
az monitor log-analytics workspace create --resource-group MyGroup --workspace-name MyWorkspace --location eastus --retention 30
What is the likely cause of the error?
medium
A. The location eastus is not supported
B. The resource group MyGroup does not exist
C. The workspace name is too short
D. The parameter --retention is invalid; it should be --retention-time

Solution

  1. Step 1: Check the parameter names in the command

    The command uses --retention, which is not a valid parameter for retention period in Azure CLI.
  2. Step 2: Identify the correct parameter

    The correct parameter to specify retention days is --retention-time. Using the wrong parameter causes a syntax error.
  3. Final Answer:

    The parameter --retention is invalid; it should be --retention-time -> Option D
  4. Quick Check:

    Use --retention-time, not --retention [OK]
Hint: Retention parameter must be --retention-time [OK]
Common Mistakes:
  • Using --retention instead of --retention-time
  • Assuming location eastus is invalid
  • Ignoring resource group existence
5. You want to create a Log Analytics workspace that stores logs for 60 days and is located in the same region as your Azure virtual machines in westus2. Which Azure CLI command correctly achieves this?
hard
A. az monitor log-analytics workspace create --resource-group MyGroup --workspace-name MyWorkspace --location westus2 --retention-time 60
B. az monitor log-analytics workspace create --resource-group MyGroup --workspace-name MyWorkspace --location eastus --retention-time 60
C. az monitor log-analytics workspace create --resource-group MyGroup --workspace-name MyWorkspace --location westus2 --retention 60
D. az monitor log-analytics workspace create --resource-group MyGroup --workspace-name MyWorkspace --location westus2

Solution

  1. Step 1: Match location with VM region

    The workspace must be in westus2 to match the VM region.
  2. Step 2: Set retention period correctly

    The retention period must be 60 days, so use --retention-time 60.
  3. Step 3: Verify command correctness

    The command az monitor log-analytics workspace create --resource-group MyGroup --workspace-name MyWorkspace --location westus2 --retention-time 60 uses the correct location and retention parameter. The command with --location eastus uses wrong location. The command with --retention 60 uses invalid retention parameter. The command without retention omits the period setting.
  4. Final Answer:

    az monitor log-analytics workspace create --resource-group MyGroup --workspace-name MyWorkspace --location westus2 --retention-time 60 -> Option A
  5. Quick Check:

    Location and retention-time must match requirements [OK]
Hint: Match location and use --retention-time for retention [OK]
Common Mistakes:
  • Using wrong location
  • Using --retention instead of --retention-time
  • Omitting retention period