Azure Log Analytics website screenshot

Azure Log Analytics

Azure Log Analytics is a service that helps you collect and analyze data generated by resources in your cloud and on-premises environments, providing query, management, and data collection APIs for monitoring and analytics.

Azure Log Analytics publishes 5 APIs on the APIs.io network, including Ingestion API, Query API, Saved Searches API, and 2 more. Tagged areas include Analytics, Azure, Cloud, Logging, and Monitoring.

The Azure Log Analytics catalog on APIs.io includes 3 JSON-LD contexts and 2 Spectral governance rulesets.

Azure Log Analytics’ developer surface includes authentication, developer portal, documentation, getting-started guide, pricing, support, engineering blog, and 39 more developer resources.

57.4/100 strong ▬ flat Agent 31/100 agent ready open core · MIT Full breakdown ↓
scored 2026-09-08 · rubric v0.20.0
AccessFreemiumSelf serve⚡ Free to try
5 APIs 10 Features 6 Use Cases
AnalyticsAzureCloudLoggingMonitoring

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-09-08 · rubric v0.20.0
Open Source Surface applies to this provider. This product is open source and we read its repository directly, so Open Source Surface carries 10 points of the composite. It is scored from what the repository actually publishes — a security policy, a contribution guide, a release history, a code of conduct — read live from the provider rather than inferred from our own catalog pointers. This facet adds; nothing was taken away to make room for it. An open-source project is not excused from the commercial facets, because exemption would strip it of the points it does earn. If we have the wrong repository, or this product is not open source, say so on your provider repo and we will drop the facet rather than have you publish against it.
Create-or-Update Ergonomics applies to this provider. This API accepts writes, so it carries 10 points of the composite. It is scored from the published contracts themselves: whether a caller can create-or-update in one call, whether the write accepts a key the caller already holds, and whether the response says which branch ran. Without that, every write needs a search-and-branch in front of it, and the first time that check is skipped a duplicate record is created. Scored against the observed mean rather than raw — a provider at the catalog average is unchanged by this facet, not penalised by it.
The six quality facets above are damped to 80 points between them, because the conditional facet above carries the other 20. That is why each facet's contribution is shown against a damped maximum: raising a quality facet moves the composite by 80% of its nominal weight, not 100%. The full arithmetic is at apis.io/rating/.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. Every facet and dimension name above is a link: it opens that measurement's own page — what it means, the exact checks that feed it, how the whole catalog distributes on it, and the providers at the top of it. This rating is computed from github.com/api-evangelist/azure-log-analytics: open an issue to ask a question, or submit a pull request to add artifacts. Submit an artifact on GitHub — free → Manage your own listing — the Influence plan, $499/mo →

APIs 5

Individual APIs this provider publishes, each with its own machine-readable definition.

Azure Log Analytics Ingestion API

Send log data to Log Analytics workspaces

Azure Log Analytics Query API

Execute KQL queries against Log Analytics workspaces

Azure Log Analytics Saved Searches API

Manage saved KQL queries

Azure Log Analytics Tables API

Manage workspace tables

Azure Log Analytics Workspaces API

Manage Log Analytics workspaces

Postman Collections 3

Ready-to-run Postman collections for exercising this provider's APIs.

Open Collections 6

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

API Collection

OPEN COLLECTION

Arazzo Workflows 14

Multi-step API workflows described with the Arazzo specification.

Azure Log Analytics Audit and Clean Up a Saved Search

List saved searches, inspect one, then delete it if it is uncategorized.

ARAZZO

Azure Log Analytics Create Workspace and Baseline Custom Table

Create a workspace, add a baseline custom table, then read the table back.

ARAZZO

Azure Log Analytics Cross-Workspace Query

Discover subscription workspaces, then run one KQL query spanning several of them.

ARAZZO

Azure Log Analytics Discover and Query Workspace

Find a workspace in a subscription, confirm it, then run a KQL query against it.

ARAZZO

Azure Log Analytics Ingest Logs and Verify

Confirm a target table exists, upload logs via a DCR, then query to verify.

ARAZZO

Azure Log Analytics Browse Saved Searches and Run One

List a workspace's saved searches, fetch one's KQL, then execute it.

ARAZZO

Azure Log Analytics Inspect Table Schema then Query

List a workspace's tables, inspect one table's schema, then query that table.

ARAZZO

Azure Log Analytics Validate then Save a KQL Query

Run a KQL query to validate it, then persist it as a saved search.

ARAZZO

Azure Log Analytics Provision Custom Table then Ingest and Verify

Create a custom table, upload logs through a DCR, then query the table to verify.

ARAZZO

Azure Log Analytics Query Workspace by Name (GET)

Confirm a workspace exists, then run a KQL query via the GET query endpoint.

ARAZZO

Azure Log Analytics Resolve Workspace by Resource Group and Run KQL

Narrow workspaces to a resource group, resolve one, then run a KQL query.

ARAZZO

Azure Log Analytics Run a Saved Search

Fetch a saved search's KQL definition, then execute it against the workspace.

ARAZZO

Azure Log Analytics Update Workspace Retention and Verify

Read a workspace's current retention, patch it, then read it back to confirm.

ARAZZO

Azure Log Analytics Workspace Inventory Report

Resolve a workspace, then list its tables and its saved searches together.

ARAZZO

Scroll for all 14

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Azure Log Analytics Rate Limits

19 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Features 10

Notable capabilities this provider offers.

Kusto Query Language

Full KQL query language support for complex log analytics and data exploration across cloud and on-premises resources.

Custom Log Ingestion

Send custom log data from any source using the Logs Ingestion API with data collection rules and transformations.

Workspace Management

Create, configure, and manage Log Analytics workspaces including data sources, retention policies, and access control.

Saved Searches

Save and reuse KQL queries across workspace sessions for consistent monitoring and reporting.

Data Collection Rules

Define data collection pipelines with transformations that shape incoming data before it reaches the workspace.

Cross-Workspace Queries

Query data across multiple Log Analytics workspaces in a single query for centralized analysis.

Simple Mode Queries

Point-and-click spreadsheet-like query experience for users who do not need full KQL knowledge.

Alert Rule Integration

Create alert rules directly from log queries to enable proactive monitoring and automated responses.

Workspace Failover

Activate and deactivate failover for workspace disaster recovery and high availability.

Data Export

Export query results to Excel, CSV, Power BI, and Grafana dashboards for external analysis.

Scroll for all 10

Semantic Vocabularies 3

JSON-LD contexts and semantic vocabularies used across these APIs.

Azure Log Analytics Ingestion Api Context

3 classes · 10 properties

JSON-LD

Azure Log Analytics Management Api Context

5 classes · 20 properties

JSON-LD

Azure Log Analytics Query Api Context

6 classes · 11 properties

JSON-LD

Spectral Rules 2

Spectral governance rulesets for linting and validating these APIs.

Azure Log Analytics API Rules

5 rules · 3 warnings 2 info

SPECTRAL

Azure Log Analytics API Rules

45 rules · 20 errors 15 warnings 10 info

SPECTRAL

JSON Schema 5

Standalone JSON Schema definitions for this provider's data models.

LogEntry

3 properties

JSON SCHEMA

SavedSearch

5 properties

JSON SCHEMA

Workspace

7 properties

JSON SCHEMA

QueryBody

3 properties

JSON SCHEMA

QueryResults

2 properties

JSON SCHEMA

JSON Structure 5

JSON Structure definitions describing this provider's data shapes.

Ingestion Api Log Entry Structure

3 properties

JSON STRUCTURE

Management Api Saved Search Structure

5 properties

JSON STRUCTURE

Management Api Workspace Structure

7 properties

JSON STRUCTURE

Query Api Query Body Structure

3 properties

JSON STRUCTURE

Query Api Query Results Structure

2 properties

JSON STRUCTURE

Examples 5

Example request and response payloads for these APIs.

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Azure Log Analytics Authentication

apiKey/http/oauth2 · 3 schemes

SECURITY

Azure Log Analytics Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Scopes 1

OAuth scopes governing access to this provider's APIs.

Azure Log Analytics Scopes

1 scope · implicit

1 scopes

SCOPES

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Azure Log Analytics Agentic Access

17 operations · 9 acting

17 operations · 9 acting

AGENTIC

Use Cases 6

What developers build with this provider.

Infrastructure Monitoring

Collect and analyze logs from virtual machines, containers, and network resources to monitor infrastructure health.

Security Investigation

Query security events and audit logs to investigate incidents and detect threats across Azure resources.

Application Performance Monitoring

Analyze application logs and telemetry to identify performance bottlenecks and errors.

Compliance Auditing

Collect and retain audit logs to meet regulatory compliance requirements and generate compliance reports.

Custom Data Integration

Ingest custom log data from third-party systems and on-premises resources using the Logs Ingestion API.

Cost Optimization

Analyze resource usage patterns and log data to identify cost-saving opportunities across Azure deployments.

Integrations 10

Pre-built integrations with other platforms and tools.

Azure Monitor

Core integration with Azure Monitor for unified observability across metrics, logs, and traces.

Microsoft Sentinel

Feed log data into Microsoft Sentinel for SIEM and SOAR capabilities.

Azure Data Explorer

Built on Azure Data Explorer engine, supports the same KQL query language for advanced analytics.

Power BI

Export and visualize log query results in Power BI dashboards for business intelligence reporting.

Grafana

Connect Azure Monitor Logs as a data source in managed Grafana dashboards for visualization.

Azure Workbooks

Create interactive visual reports using log query results within Azure Workbooks.

Azure Automation

Trigger automation runbooks based on log query results and alert rules.

Azure Logic Apps

Integrate log analytics alerts with Logic Apps workflows for automated incident response.

Application Insights

Combine application telemetry from Application Insights with infrastructure logs for full-stack observability.

Azure Resource Manager

Manage Log Analytics resources programmatically through Azure Resource Manager REST APIs.

Scroll for all 10

Resources

Get Started 2

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 16

Pagination, idempotency, versioning, errors, and events

Scroll for all 16

Build 10

SDKs, sample code, and the tooling you integrate with

Scroll for all 10

Access & Security 4

Authentication, authorization, and security posture

Operate 5

Status, limits, changes, and where to get help

Commercial 4

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: azure-log-analytics
name: Azure Log Analytics
description: Azure Log Analytics is a service that helps you collect and analyze data generated by resources in your cloud
  and on-premises environments, providing query, management, and data collection APIs for monitoring and analytics.
type: Index
deliveryModel:
  model: open-core
  license: MIT
  open_source: true
  commercial: true
  callable_host: false
  label: Open core · an OSS project plus a commercial hosted product
  confidence: high
  source:
  - license
  - openapi
  - pricing
  generated: '2026-08-28'
  method: derived
accessModel:
  pricing: freemium
  onboarding: self-serve
  trial: false
  try_now: true
  public: false
  label: Freemium · Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/azure-log-analytics.png
tags:
- Analytics
- Azure
- Cloud
- Logging
- Monitoring
url: https://raw.githubusercontent.com/api-evangelist/azure-log-analytics/refs/heads/main/apis.yml
created: '2024-01-01'
modified: '2026-05-19'
specificationVersion: '0.23'
apis:
- aid: azure-log-analytics:azure-log-analytics-ingestion-api
  name: Azure Log Analytics Ingestion API
  description: Send log data to Log Analytics workspaces
  humanURL: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/api/overview
  baseURL: https://api.loganalytics.azure.com/v1
  tags:
  - Ingestion
  properties:
  - type: OpenAPI
    url: openapi/azure-log-analytics-ingestion-api-openapi.yml
  - type: Documentation
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/api/overview
  - type: APIReference
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/api/request-format
  - type: Authentication
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/api/access-api
  - type: GettingStarted
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/log-analytics-tutorial
  - type: JSONSchema
    url: json-schema/query-api-query-body-schema.json
  - type: JSONSchema
    url: json-schema/query-api-query-results-schema.json
  - type: JSONLD
    url: json-ld/azure-log-analytics-query-api-context.jsonld
  - type: Examples
    url: examples/query-api-query-body-example.json
  - type: Examples
    url: examples/query-api-query-results-example.json
  - type: Documentation
    url: https://learn.microsoft.com/en-us/rest/api/loganalytics/
  - type: APIReference
    url: https://learn.microsoft.com/en-us/rest/api/loganalytics/workspaces
  - type: JSONSchema
    url: json-schema/management-api-workspace-schema.json
  - type: JSONSchema
    url: json-schema/management-api-saved-search-schema.json
  - type: JSONLD
    url: json-ld/azure-log-analytics-management-api-context.jsonld
  - type: Examples
    url: examples/management-api-workspace-example.json
  - type: Examples
    url: examples/management-api-saved-search-example.json
  - type: Documentation
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/logs-ingestion-api-overview
  - type: GettingStarted
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/tutorial-logs-ingestion-code
  - type: Authentication
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/logs-ingestion-api-overview#configuration
  - type: JSONSchema
    url: json-schema/ingestion-api-log-entry-schema.json
  - type: JSONLD
    url: json-ld/azure-log-analytics-ingestion-api-context.jsonld
  - type: Examples
    url: examples/ingestion-api-log-entry-example.json
- aid: azure-log-analytics:azure-log-analytics-query-api
  name: Azure Log Analytics Query API
  description: Execute KQL queries against Log Analytics workspaces
  humanURL: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/api/overview
  baseURL: https://api.loganalytics.azure.com/v1
  tags:
  - Query
  properties:
  - type: OpenAPI
    url: openapi/azure-log-analytics-query-api-openapi.yml
  - type: Documentation
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/api/overview
  - type: APIReference
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/api/request-format
  - type: Authentication
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/api/access-api
  - type: GettingStarted
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/log-analytics-tutorial
  - type: JSONSchema
    url: json-schema/query-api-query-body-schema.json
  - type: JSONSchema
    url: json-schema/query-api-query-results-schema.json
  - type: JSONLD
    url: json-ld/azure-log-analytics-query-api-context.jsonld
  - type: Examples
    url: examples/query-api-query-body-example.json
  - type: Examples
    url: examples/query-api-query-results-example.json
  - type: Documentation
    url: https://learn.microsoft.com/en-us/rest/api/loganalytics/
  - type: APIReference
    url: https://learn.microsoft.com/en-us/rest/api/loganalytics/workspaces
  - type: JSONSchema
    url: json-schema/management-api-workspace-schema.json
  - type: JSONSchema
    url: json-schema/management-api-saved-search-schema.json
  - type: JSONLD
    url: json-ld/azure-log-analytics-management-api-context.jsonld
  - type: Examples
    url: examples/management-api-workspace-example.json
  - type: Examples
    url: examples/management-api-saved-search-example.json
  - type: Documentation
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/logs-ingestion-api-overview
  - type: GettingStarted
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/tutorial-logs-ingestion-code
  - type: Authentication
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/logs-ingestion-api-overview#configuration
  - type: JSONSchema
    url: json-schema/ingestion-api-log-entry-schema.json
  - type: JSONLD
    url: json-ld/azure-log-analytics-ingestion-api-context.jsonld
  - type: Examples
    url: examples/ingestion-api-log-entry-example.json
- aid: azure-log-analytics:azure-log-analytics-saved-searches-api
  name: Azure Log Analytics Saved Searches API
  description: Manage saved KQL queries
  humanURL: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/api/overview
  baseURL: https://api.loganalytics.azure.com/v1
  tags:
  - Saved Searches
  properties:
  - type: OpenAPI
    url: openapi/azure-log-analytics-saved-searches-api-openapi.yml
  - type: Documentation
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/api/overview
  - type: APIReference
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/api/request-format
  - type: Authentication
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/api/access-api
  - type: GettingStarted
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/log-analytics-tutorial
  - type: JSONSchema
    url: json-schema/query-api-query-body-schema.json
  - type: JSONSchema
    url: json-schema/query-api-query-results-schema.json
  - type: JSONLD
    url: json-ld/azure-log-analytics-query-api-context.jsonld
  - type: Examples
    url: examples/query-api-query-body-example.json
  - type: Examples
    url: examples/query-api-query-results-example.json
  - type: Documentation
    url: https://learn.microsoft.com/en-us/rest/api/loganalytics/
  - type: APIReference
    url: https://learn.microsoft.com/en-us/rest/api/loganalytics/workspaces
  - type: JSONSchema
    url: json-schema/management-api-workspace-schema.json
  - type: JSONSchema
    url: json-schema/management-api-saved-search-schema.json
  - type: JSONLD
    url: json-ld/azure-log-analytics-management-api-context.jsonld
  - type: Examples
    url: examples/management-api-workspace-example.json
  - type: Examples
    url: examples/management-api-saved-search-example.json
  - type: Documentation
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/logs-ingestion-api-overview
  - type: GettingStarted
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/tutorial-logs-ingestion-code
  - type: Authentication
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/logs-ingestion-api-overview#configuration
  - type: JSONSchema
    url: json-schema/ingestion-api-log-entry-schema.json
  - type: JSONLD
    url: json-ld/azure-log-analytics-ingestion-api-context.jsonld
  - type: Examples
    url: examples/ingestion-api-log-entry-example.json
- aid: azure-log-analytics:azure-log-analytics-tables-api
  name: Azure Log Analytics Tables API
  description: Manage workspace tables
  humanURL: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/api/overview
  baseURL: https://api.loganalytics.azure.com/v1
  tags:
  - Tables
  properties:
  - type: OpenAPI
    url: openapi/azure-log-analytics-tables-api-openapi.yml
  - type: Documentation
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/api/overview
  - type: APIReference
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/api/request-format
  - type: Authentication
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/api/access-api
  - type: GettingStarted
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/log-analytics-tutorial
  - type: JSONSchema
    url: json-schema/query-api-query-body-schema.json
  - type: JSONSchema
    url: json-schema/query-api-query-results-schema.json
  - type: JSONLD
    url: json-ld/azure-log-analytics-query-api-context.jsonld
  - type: Examples
    url: examples/query-api-query-body-example.json
  - type: Examples
    url: examples/query-api-query-results-example.json
  - type: Documentation
    url: https://learn.microsoft.com/en-us/rest/api/loganalytics/
  - type: APIReference
    url: https://learn.microsoft.com/en-us/rest/api/loganalytics/workspaces
  - type: JSONSchema
    url: json-schema/management-api-workspace-schema.json
  - type: JSONSchema
    url: json-schema/management-api-saved-search-schema.json
  - type: JSONLD
    url: json-ld/azure-log-analytics-management-api-context.jsonld
  - type: Examples
    url: examples/management-api-workspace-example.json
  - type: Examples
    url: examples/management-api-saved-search-example.json
  - type: Documentation
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/logs-ingestion-api-overview
  - type: GettingStarted
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/tutorial-logs-ingestion-code
  - type: Authentication
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/logs-ingestion-api-overview#configuration
  - type: JSONSchema
    url: json-schema/ingestion-api-log-entry-schema.json
  - type: JSONLD
    url: json-ld/azure-log-analytics-ingestion-api-context.jsonld
  - type: Examples
    url: examples/ingestion-api-log-entry-example.json
- aid: azure-log-analytics:azure-log-analytics-workspaces-api
  name: Azure Log Analytics Workspaces API
  description: Manage Log Analytics workspaces
  humanURL: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/api/overview
  baseURL: https://api.loganalytics.azure.com/v1
  tags:
  - Workspaces
  properties:
  - type: OpenAPI
    url: openapi/azure-log-analytics-workspaces-api-openapi.yml
  - type: Documentation
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/api/overview
  - type: APIReference
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/api/request-format
  - type: Authentication
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/api/access-api
  - type: GettingStarted
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/log-analytics-tutorial
  - type: JSONSchema
    url: json-schema/query-api-query-body-schema.json
  - type: JSONSchema
    url: json-schema/query-api-query-results-schema.json
  - type: JSONLD
    url: json-ld/azure-log-analytics-query-api-context.jsonld
  - type: Examples
    url: examples/query-api-query-body-example.json
  - type: Examples
    url: examples/query-api-query-results-example.json
  - type: Documentation
    url: https://learn.microsoft.com/en-us/rest/api/loganalytics/
  - type: APIReference
    url: https://learn.microsoft.com/en-us/rest/api/loganalytics/workspaces
  - type: JSONSchema
    url: json-schema/management-api-workspace-schema.json
  - type: JSONSchema
    url: json-schema/management-api-saved-search-schema.json
  - type: JSONLD
    url: json-ld/azure-log-analytics-management-api-context.jsonld
  - type: Examples
    url: examples/management-api-workspace-example.json
  - type: Examples
    url: examples/management-api-saved-search-example.json
  - type: Documentation
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/logs-ingestion-api-overview
  - type: GettingStarted
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/tutorial-logs-ingestion-code
  - type: Authentication
    url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/logs-ingestion-api-overview#configuration
  - type: JSONSchema
    url: json-schema/ingestion-api-log-entry-schema.json
  - type: JSONLD
    url: json-ld/azure-log-analytics-ingestion-api-context.jsonld
  - type: Examples
    url: examples/ingestion-api-log-entry-example.json
common:
- type: Website
  url: https://www.microsoft.com/
- type: IssueTracker
  url: https://github.com/Azure/azure-rest-api-specs/issues
- type: Releases
  url: https://github.com/Azure/azure-rest-api-specs/releases
- type: SecurityPolicy
  url: https://github.com/Azure/azure-rest-api-specs/blob/main/SECURITY.md
- type: CodeOfConduct
  url: https://github.com/Azure/.github/blob/main/CODE_OF_CONDUCT.md
- type: ContributionGuide
  url: https://github.com/Azure/azure-rest-api-specs/blob/main/.github/CONTRIBUTING.md
- type: License
  name: MIT
  url: https://github.com/Azure/azure-rest-api-specs/blob/main/LICENSE
- type: AgenticAccess
  url: agentic-access/azure-log-analytics-agentic-access.yml
- type: DomainSecurity
  url: security/azure-log-analytics-domain-security.yml
- type: Authentication
  url: authentication/azure-log-analytics-authentication.yml
- type: OAuthScopes
  url: scopes/azure-log-analytics-scopes.yml
- type: PostmanWorkspace
  url: https://www.postman.com/kinlaneapi/azure-log-analytics/overview
- type: Arazzo
  url: arazzo/azure-log-analytics-audit-and-cleanup-saved-search-workflow.yml
  name: Azure Log Analytics Audit and Clean Up a Saved Search
- type: Arazzo
  url: arazzo/azure-log-analytics-create-workspace-and-baseline-table-workflow.yml
  name: Azure Log Analytics Create Workspace and Baseline Custom Table
- type: Arazzo
  url: arazzo/azure-log-analytics-cross-workspace-query-workflow.yml
  name: Azure Log Analytics Cross-Workspace Query
- type: Arazzo
  url: arazzo/azure-log-analytics-discover-and-query-workspace-workflow.yml
  name: Azure Log Analytics Discover and Query Workspace
- type: Arazzo
  url: arazzo/azure-log-analytics-ingest-and-verify-workflow.yml
  name: Azure Log Analytics Ingest Logs and Verify
- type: Arazzo
  url: arazzo/azure-log-analytics-list-saved-searches-and-run-workflow.yml
  name: Azure Log Analytics Browse Saved Searches and Run One
- type: Arazzo
  url: arazzo/azure-log-analytics-list-tables-then-query-workflow.yml
  name: Azure Log Analytics Inspect Table Schema then Query
- type: Arazzo
  url: arazzo/azure-log-analytics-promote-query-to-saved-search-workflow.yml
  name: Azure Log Analytics Validate then Save a KQL Query
- type: Arazzo
  url: arazzo/azure-log-analytics-provision-table-and-ingest-workflow.yml
  name: Azure Log Analytics Provision Custom Table then Ingest and Verify
- type: Arazzo
  url: arazzo/azure-log-analytics-query-workspace-by-name-workflow.yml
  name: Azure Log Analytics Query Workspace by Name (GET)
- type: Arazzo
  url: arazzo/azure-log-analytics-resolve-workspace-and-run-kql-workflow.yml
  name: Azure Log Analytics Resolve Workspace by Resource Group and Run KQL
- type: Arazzo
  url: arazzo/azure-log-analytics-saved-search-to-query-workflow.yml
  name: Azure Log Analytics Run a Saved Search
- type: Arazzo
  url: arazzo/azure-log-analytics-update-workspace-retention-workflow.yml
  name: Azure Log Analytics Update Workspace Retention and Verify
- type: Arazzo
  url: arazzo/azure-log-analytics-workspace-inventory-report-workflow.yml
  name: Azure Log Analytics Workspace Inventory Report
- type: Portal
  url: https://portal.azure.com/
- type: Documentation
  url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/log-analytics-overview
- type: GettingStarted
  url: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/log-analytics-tutorial
- type: Pricing
  url: https://azure.microsoft.com/en-us/pricing/details/monitor/
- type: StatusPage
  url: https://status.azure.com/
- type: Support
  url: https://azure.microsoft.com/en-us/support/
- type: Blog
  url: https://azure.microsoft.com/en-us/blog/tag/azure-log-analytics/
- type: TermsOfService
  url: https://azure.microsoft.com/en-us/support/legal/
- type: PrivacyPolicy
  url: https://privacy.microsoft.com/en-us/privacystatement
- type: GitHubOrganization
  url: https://github.com/Azure
- type: GitHubRepository
  url: https://github.com/Azure/azure-rest-api-specs
- type: CLI
  url: https://learn.microsoft.com/en-us/cli/azure/monitor/log-analytics
- type: SDKs
  url: https://pypi.org/project/azure-monitor-query/
  title: Python SDK
- type: SDKs
  url: https://www.npmjs.com/package/@azure/monitor-query
  title: JavaScript SDK
- type: SDKs
  url: https://pkg.go.dev/github.com/Azure/azure-sdk-for-go/sdk/monitor/query/azlogs
  title: Go SDK
- type: SDKs
  url: https://learn.microsoft.com/en-us/dotnet/api/overview/azure/Monitor.Query-readme
  title: .NET SDK
- type: SDKs
  url: https://learn.microsoft.com/en-us/java/api/overview/azure/monitor-query-readme
  title: Java SDK
- type: RateLimits
  url: https://learn.microsoft.com/en-us/azure/azure-monitor/service-limits#query-api
- type: SpectralRules
  url: rules/azure-log-analytics-spectral-rules.yml
- type: Vocabulary
  url: vocabulary/azure-log-analytics-vocabulary.yaml
- type: Features
  data:
  - name: Kusto Query Language
    description: Full KQL query language support for complex log analytics and data exploration across cloud and on-premises
      resources.
  - name: Custom Log Ingestion
    description: Send custom log data from any source using the Logs Ingestion API with data collection rules and transformations.
  - name: Workspace Management
    description: Create, configure, and manage Log Analytics workspaces including data sources, retention policies, and access
      control.
  - name: Saved Searches
    description: Save and reuse KQL queries across workspace sessions for consistent monitoring and reporting.
  - name: Data Collection Rules
    description: Define data collection pipelines with transformations that shape incoming data before it reaches the workspace.
  - name: Cross-Workspace Queries
    description: Query data across multiple Log Analytics workspaces in a single query for centralized analysis.
  - name: Simple Mode Queries
    description: Point-and-click spreadsheet-like query experience for users who do not need full KQL knowledge.
  - name: Alert Rule Integration
    description: Create alert rules directly from log queries to enable proactive monitoring and automated responses.
  - name: Workspace Failover
    description: Activate and deactivate failover for workspace disaster recovery and high availability.
  - name: Data Export
    description: Export query results to Excel, CSV, Power BI, and Grafana dashboards for external analysis.
- type: UseCases
  data:
  - name: Infrastructure Monitoring
    description: Collect and analyze logs from virtual machines, containers, and network resources to monitor infrastructure
      health.
  - name: Security Investigation
    description: Query security events and audit logs to investigate incidents and detect threats across Azure resources.
  - name: Application Performance Monitoring
    description: Analyze application logs and telemetry to identify performance bottlenecks and errors.
  - name: Compliance Auditing
    description: Collect and retain audit logs to meet regulatory compliance requirements and generate compliance reports.
  - name: Custom Data Integration
    description: Ingest custom log data from third-party systems and on-premises resources using the Logs Ingestion API.
  - name: Cost Optimization
    description: Analyze resource usage patterns and log data to identify cost-saving opportunities across Azure deployments.
- type: Integrations
  data:
  - name: Azure Monitor
    description: Core integration with Azure Monitor for unified observability across metrics, logs, and traces.
  - name: Microsoft Sentinel
    description: Feed log data into Microsoft Sentinel for SIEM and SOAR capabilities.
  - name: Azure Data Explorer
    description: Built on Azure Data Explorer engine, supports the same KQL query language for advanced analytics.
  - name: Power BI
    description: Export and visualize log query results in Power BI dashboards for business intelligence reporting.
  - name: Grafana
    description: Connect Azure Monitor Logs as a data source in managed Grafana dashboards for visualization.
  - name: Azure Workbooks
    description: Create interactive visual reports using log query results within Azure Workbooks.
  - name: Azure Automation
    description: Trigger automation runbooks based on log query results and alert rules.
  - name: Azure Logic Apps
    description: Integrate log analytics alerts with Logic Apps workflows for automated incident response.
  - name: Application Insights
    description: Combine application telemetry from Application Insights with infrastructure logs for full-stack observability.
  - name: Azure Resource Manager
    description: Manage Log Analytics resources programmatically through Azure Resource Manager REST APIs.
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/azure-log-analytics"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/azure-log-analytics/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/azure-log-analytics/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.