Azure Log Analytics
Azure Log Analytics is a service that helps you collect and analyze data generated by resources in your cloud and on-premises environments, providing query, management, and data collection APIs for monitoring and analytics.
Azure Log Analytics publishes 5 APIs on the APIs.io network, including Ingestion API, Query API, Saved Searches API, and 2 more. Tagged areas include Analytics, Azure, Cloud, Logging, and Monitoring.
The Azure Log Analytics catalog on APIs.io includes 3 JSON-LD contexts and 2 Spectral governance rulesets.
Azure Log Analytics’ developer surface includes authentication, developer portal, documentation, getting-started guide, pricing, support, engineering blog, and 32 more developer resources.
Kin Score
APIs 5
Individual APIs this provider publishes, each with its own machine-readable definition.
Azure Log Analytics Ingestion API
Send log data to Log Analytics workspaces
Azure Log Analytics Query API
Execute KQL queries against Log Analytics workspaces
Azure Log Analytics Saved Searches API
Manage saved KQL queries
Azure Log Analytics Tables API
Manage workspace tables
Azure Log Analytics Workspaces API
Manage Log Analytics workspaces
Postman Collections 3
Ready-to-run Postman collections for exercising this provider's APIs.
Arazzo Workflows 14
Multi-step API workflows described with the Arazzo specification.
Azure Log Analytics Audit and Clean Up a Saved Search
List saved searches, inspect one, then delete it if it is uncategorized.
ARAZZOAzure Log Analytics Create Workspace and Baseline Custom Table
Create a workspace, add a baseline custom table, then read the table back.
ARAZZOAzure Log Analytics Cross-Workspace Query
Discover subscription workspaces, then run one KQL query spanning several of them.
ARAZZOAzure Log Analytics Discover and Query Workspace
Find a workspace in a subscription, confirm it, then run a KQL query against it.
ARAZZOAzure Log Analytics Ingest Logs and Verify
Confirm a target table exists, upload logs via a DCR, then query to verify.
ARAZZOAzure Log Analytics Browse Saved Searches and Run One
List a workspace's saved searches, fetch one's KQL, then execute it.
ARAZZOAzure Log Analytics Inspect Table Schema then Query
List a workspace's tables, inspect one table's schema, then query that table.
ARAZZOAzure Log Analytics Validate then Save a KQL Query
Run a KQL query to validate it, then persist it as a saved search.
ARAZZOAzure Log Analytics Provision Custom Table then Ingest and Verify
Create a custom table, upload logs through a DCR, then query the table to verify.
ARAZZOAzure Log Analytics Query Workspace by Name (GET)
Confirm a workspace exists, then run a KQL query via the GET query endpoint.
ARAZZOAzure Log Analytics Resolve Workspace by Resource Group and Run KQL
Narrow workspaces to a resource group, resolve one, then run a KQL query.
ARAZZOAzure Log Analytics Run a Saved Search
Fetch a saved search's KQL definition, then execute it against the workspace.
ARAZZOAzure Log Analytics Update Workspace Retention and Verify
Read a workspace's current retention, patch it, then read it back to confirm.
ARAZZOAzure Log Analytics Workspace Inventory Report
Resolve a workspace, then list its tables and its saved searches together.
ARAZZOScroll for all 14
Pricing Plans 1
Published pricing tiers and plan structures.
Rate Limits 1
Documented rate limits and quota policies.
Azure Log Analytics Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Features 10
Notable capabilities this provider offers.
Kusto Query Language
Full KQL query language support for complex log analytics and data exploration across cloud and on-premises resources.
Custom Log Ingestion
Send custom log data from any source using the Logs Ingestion API with data collection rules and transformations.
Workspace Management
Create, configure, and manage Log Analytics workspaces including data sources, retention policies, and access control.
Saved Searches
Save and reuse KQL queries across workspace sessions for consistent monitoring and reporting.
Data Collection Rules
Define data collection pipelines with transformations that shape incoming data before it reaches the workspace.
Cross-Workspace Queries
Query data across multiple Log Analytics workspaces in a single query for centralized analysis.
Simple Mode Queries
Point-and-click spreadsheet-like query experience for users who do not need full KQL knowledge.
Alert Rule Integration
Create alert rules directly from log queries to enable proactive monitoring and automated responses.
Workspace Failover
Activate and deactivate failover for workspace disaster recovery and high availability.
Data Export
Export query results to Excel, CSV, Power BI, and Grafana dashboards for external analysis.
Scroll for all 10
Semantic Vocabularies 3
JSON-LD contexts and semantic vocabularies used across these APIs.
Spectral Rules 2
Spectral governance rulesets for linting and validating these APIs.
Azure Log Analytics API Rules
SPECTRALAzure Log Analytics API Rules
SPECTRALJSON Schema 5
Standalone JSON Schema definitions for this provider's data models.
LogEntry
JSON SCHEMASavedSearch
JSON SCHEMAWorkspace
JSON SCHEMAQueryBody
JSON SCHEMAQueryResults
JSON SCHEMAJSON Structure 5
JSON Structure definitions describing this provider's data shapes.
Ingestion Api Log Entry Structure
JSON STRUCTUREManagement Api Saved Search Structure
JSON STRUCTUREManagement Api Workspace Structure
JSON STRUCTUREQuery Api Query Body Structure
JSON STRUCTUREQuery Api Query Results Structure
JSON STRUCTUREExamples 5
Example request and response payloads for these APIs.
Query Api Query Body Example
EXAMPLESecurity Posture 2
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Scopes 1
OAuth scopes governing access to this provider's APIs.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Use Cases 6
What developers build with this provider.
Infrastructure Monitoring
Collect and analyze logs from virtual machines, containers, and network resources to monitor infrastructure health.
Security Investigation
Query security events and audit logs to investigate incidents and detect threats across Azure resources.
Application Performance Monitoring
Analyze application logs and telemetry to identify performance bottlenecks and errors.
Compliance Auditing
Collect and retain audit logs to meet regulatory compliance requirements and generate compliance reports.
Custom Data Integration
Ingest custom log data from third-party systems and on-premises resources using the Logs Ingestion API.
Cost Optimization
Analyze resource usage patterns and log data to identify cost-saving opportunities across Azure deployments.
Integrations 10
Pre-built integrations with other platforms and tools.
Azure Monitor
Core integration with Azure Monitor for unified observability across metrics, logs, and traces.
Microsoft Sentinel
Feed log data into Microsoft Sentinel for SIEM and SOAR capabilities.
Azure Data Explorer
Built on Azure Data Explorer engine, supports the same KQL query language for advanced analytics.
Power BI
Export and visualize log query results in Power BI dashboards for business intelligence reporting.
Grafana
Connect Azure Monitor Logs as a data source in managed Grafana dashboards for visualization.
Azure Workbooks
Create interactive visual reports using log query results within Azure Workbooks.
Azure Automation
Trigger automation runbooks based on log query results and alert rules.
Azure Logic Apps
Integrate log analytics alerts with Logic Apps workflows for automated incident response.
Application Insights
Combine application telemetry from Application Insights with infrastructure logs for full-stack observability.
Azure Resource Manager
Manage Log Analytics resources programmatically through Azure Resource Manager REST APIs.
Scroll for all 10
Resources
Get Started 2
Portal, sign-up, and the first successful call
Documentation 1
Reference material describing how the API behaves
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 16
Pagination, idempotency, versioning, errors, and events
Scroll for all 16
Build 9
SDKs, sample code, and the tooling you integrate with
Scroll for all 9
Access & Security 3
Authentication, authorization, and security posture
Operate 3
Status, limits, changes, and where to get help
Commercial 3
Pricing, plans, and the legal terms of use
Company 1
The organization behind the API