Skip to main content

Log Analytics

Log Analytics is the log store of Azure Monitor: workspaces that hold logs in tables and answer queries in KQL (Kusto Query Language). The Azure Enterprise Baseline keeps one workspace per audience: audit, security, and the application logs of each stage.

What it does​

A Log Analytics workspace receives data from diagnostic settings, agents and services, stores it in tables such as AzureActivity, SigninLogs or ContainerLogV2, and keeps it for its interactive retention period. Queries can span several workspaces. A data export rule copies chosen tables continuously to a storage account. Access is by Azure RBAC on the workspace or above it; Log Analytics Reader reads every table. Billing is per GB ingested, plus retention beyond 31 days, and an optional daily cap stops ingestion for the day once reached.

How BuiltForProd uses it​

WorkspaceSubscriptionRetentionReceives
law-acme-eus2-audit-auditacme-core-audit365 daysThe Activity Log of every subscription, the Microsoft Entra ID logs, the Baseline's resource logs (firewall, NSGs, VPN, vaults, registry, storage)
law-acme-eus2-security-securityacme-core-security365 daysThe Defender for Cloud continuous export of every subscription; Microsoft Sentinel when switched on
law-acme-eus2-<stage>-appeach plat subscriptionprod 365, staging 90, dev and sandbox 30 daysContainer Insights, Application Insights and the blueprints' resource logs

<stage> is the short stage code, so prod's workspace is law-acme-eus2-prd-app. Retention is a setting in each unit or stage file (30 to 730 days); the comments price ingestion at about $2.30 per GB and retention beyond 31 days at $0.10 per GB-month. No workspace has a daily cap by default (daily_quota_gb = -1), and each is a switch away.

Every workspace accepts Microsoft Entra authentication only (local_authentication_enabled = false), keeps public ingestion and query endpoints (there is no Azure Monitor Private Link Scope), and sits in a resource group with a CanNotDelete lock where it holds evidence. The contract publishes the stage workspace as platform--log-analytics--app-workspace-id, which is how the blueprints find it.

Long-term copies. Data export rules copy AzureActivity, SigninLogs, AuditLogs, SecurityAlert and AzureDiagnostics from the audit workspace, and SecurityAlert and SecurityRecommendation from the security workspace, to the immutable audit storage, where WORM retention holds them for 365 days and lifecycle rules tier them down. The workspace is for querying; the storage account is the record.

KQL alerts. The cis-alerts unit (behind enable_cis_alerts) runs six scheduled query rules on the audit workspace every five minutes and routes them to ag-acme-security-alerts:

RuleSeverityFires on
Tenant root elevate access0Microsoft.Authorization/elevateAccess/action
Role assignment changes1A role assignment written or deleted at management-group or subscription scope
Failed sign-ins210 or more failed interactive sign-ins by one user
Break-glass sign-in0Any sign-in by an acme-breakglass-* account
Conditional Access changes1A policy added, updated or deleted
Key Vault purge or access change1A purge, a vault deletion or an access-policy change

A seventh rule, on the security workspace, raises Defender alerts of High or Critical severity; see Azure Monitor.

Who can query. The Lead Security Auditors, Security Auditors and DevOps Leads groups hold Log Analytics Reader on every subscription, from the observability-link unit, so they can query every workspace from one place with cross-workspace queries; no agent and no link resource is needed. Microsoft Sentinel, when switched on, works on the security workspace.

Terms you will see​

TermMeaning
WorkspaceOne Log Analytics store with its own retention and access.
KQLKusto Query Language, the query language of Log Analytics.
Interactive retentionHow long data stays queryable in the workspace.
Data export ruleA continuous copy of chosen tables to a storage account.
Scheduled query ruleAn alert that runs a KQL query on a schedule.
Cross-workspace queryOne query over several workspaces, by their resource IDs.

Where to read more​