Azure Data Explorer
Azure Data Explorer is a fully managed, high-performance, and big data analytics platform that is easy to analyze high volumes of data in near real time. This integration helps in monitoring the usage, health, and performance of the Azure Data Explorer cluster resources.
Log and metric types
For Azure Data Explorer, you can collect the following logs and metrics:
- Ingestion Logs. These logs have information about ingestion operations and detailed statistics of batches ready for ingestion (duration, batch size, blobs count, and batching types).
- Commands and Queries: These logs have information about admin commands and queries that have reached a final state.
- Tables: These logs have detailed information about the tables whose extents were scanned during query execution.
- Journal: These logs have detailed information about metadata operations.
- Metrics
- Cluster metrics
- Export metrics
- Ingestion metrics
- Streaming ingest metrics
- Query metrics
- Materialized view metrics
For more details on logs and metrics collected, refer to the supported metrics documentation and logs schema documentation.
Setup
Configure collector
Create a hosted collector if not already configured. Make sure you create the required sources in this collector.
Configure logs collection
Azure service sends monitoring data to Azure Monitor, which can then stream data to Eventhub. Sumo Logic supports collecting logs from Azure Monitor using our Azure Event Hubs source.
You must explicitly enable diagnostic settings for each Azure Data Explorer cluster you want to monitor. You can forward logs to the same event hub provided they satisfy the limitations and permissions as described here.
When you configure the event hubs source, plan your source category to ease the querying process. A hierarchical approach allows you to make use of wildcards. For example: Azure/DataExplorer/Logs.
In this section, you will configure a pipeline for shipping diagnostic logs from Azure Monitor to an Event Hub.
- To set up the Azure Event Hubs source in Sumo Logic, refer to Azure Event Hubs Source for Logs.
- To create the Diagnostic settings in Azure portal, refer to the Azure documentation.
- Choose
Stream to an event hubas the destination. - Select all the
CategoriesunderLogs. - Use the Event hub namespace and Event hub name configured in previous step in destination details section. You can use the default policy
RootManageSharedAccessKeyas the policy name.
- Choose
Configure metrics collection
When you configure the Azure Metrics Source, plan your source category to ease the querying process. A hierarchical approach allows you to make use of wildcards. For example: Azure/DataExplorer/Metrics.
To set up the Azure Metrics source in Sumo Logic, refer to Azure Metrics Source.
Troubleshooting
Metrics collection via Azure Metrics Source
To troubleshoot metrics collection via Azure Metrics Source, follow the instructions in Troubleshooting Azure Metrics Source.