Log Analytics
Log Analytics is the log store of Azure Monitor: workspaces that hold logs in tables and answer queries in KQL (Kusto Query Language). The Azure Enterprise Baseline keeps one workspace per audience: audit, security, and the application logs of each stage.
What it does
A Log Analytics workspace receives data from diagnostic settings, agents and services, stores it in tables such as AzureActivity, SigninLogs or ContainerLogV2, and keeps it for its interactive retention period. Queries can span several workspaces. A data export rule copies chosen tables continuously to a storage account. Access is by Azure RBAC on the workspace or above it; Log Analytics Reader reads every table. Billing is per GB ingested, plus retention beyond 31 days, and an optional daily cap stops ingestion for the day once reached.
How BuiltForProd uses it
| Workspace | Subscription | Retention | Receives |
|---|---|---|---|
law-acme-eus2-audit-audit | acme-core-audit | 365 days | The Activity Log of every subscription, the Microsoft Entra ID logs, the Baseline's resource logs (firewall, NSGs, VPN, vaults, registry, storage) |
law-acme-eus2-security-security | acme-core-security | 365 days | The Defender for Cloud continuous export of every subscription; Microsoft Sentinel when switched on |
law-acme-eus2-<stage>-app | each plat subscription | prod 365, staging 90, dev and sandbox 30 days | Container Insights, Application Insights and the blueprints' resource logs |
<stage> is the short stage code, so prod's workspace is law-acme-eus2-prd-app. Retention is a setting in each unit or stage file (30 to 730 days); the comments price ingestion at about $2.30 per GB and retention beyond 31 days at $0.10 per GB-month. No workspace has a daily cap by default (daily_quota_gb = -1), and each is a switch away.
Every workspace accepts Microsoft Entra authentication only (local_authentication_enabled = false), keeps public ingestion and query endpoints (there is no Azure Monitor Private Link Scope), and sits in a resource group with a CanNotDelete lock where it holds evidence. The contract publishes the stage workspace as platform--log-analytics--app-workspace-id, which is how the blueprints find it.
Long-term copies. Data export rules copy AzureActivity, SigninLogs, AuditLogs, SecurityAlert and AzureDiagnostics from the audit workspace, and SecurityAlert and SecurityRecommendation from the security workspace, to the immutable audit storage, where WORM retention holds them for 365 days and lifecycle rules tier them down. The workspace is for querying; the storage account is the record.
KQL alerts. The cis-alerts unit (behind enable_cis_alerts) runs six scheduled query rules on the audit workspace every five minutes and routes them to ag-acme-security-alerts:
| Rule | Severity | Fires on |
|---|---|---|
| Tenant root elevate access | 0 | Microsoft.Authorization/elevateAccess/action |
| Role assignment changes | 1 | A role assignment written or deleted at management-group or subscription scope |
| Failed sign-ins | 2 | 10 or more failed interactive sign-ins by one user |
| Break-glass sign-in | 0 | Any sign-in by an acme-breakglass-* account |
| Conditional Access changes | 1 | A policy added, updated or deleted |
| Key Vault purge or access change | 1 | A purge, a vault deletion or an access-policy change |
A seventh rule, on the security workspace, raises Defender alerts of High or Critical severity; see Azure Monitor.
Who can query. The Lead Security Auditors, Security Auditors and DevOps Leads groups hold Log Analytics Reader on every subscription, from the observability-link unit, so they can query every workspace from one place with cross-workspace queries; no agent and no link resource is needed. Microsoft Sentinel, when switched on, works on the security workspace.
Terms you will see
| Term | Meaning |
|---|---|
| Workspace | One Log Analytics store with its own retention and access. |
| KQL | Kusto Query Language, the query language of Log Analytics. |
| Interactive retention | How long data stays queryable in the workspace. |
| Data export rule | A continuous copy of chosen tables to a storage account. |
| Scheduled query rule | An alert that runs a KQL query on a schedule. |
| Cross-workspace query | One query over several workspaces, by their resource IDs. |
Where to read more
- Azure Enterprise Baseline overview, Azure Web App Blueprint overview and Azure Data and ETL Blueprint overview.
- Azure Monitor for the diagnostic settings and alerts that feed the workspaces.
- Observable for what the platform records and why.