Retrieve data from the logs in Azure Monitor with Azure Portal
- Navigate to the Azure portal by opening https://portal.azure.com.
- In the left-hand menu, select Monitoring to open the Azure Monitor overview blade.
- Under Insights, select More. This will open the Log Analytics workspace that we created in the previous step.
- On the overview page, click on Logs in the top menu. This will open the Azure Monitor query
editor:
- Here, you can select some default queries. They are displayed at the bottom part of the screen. There are queries for retrieving unavailable computers, the last heartbeat of a computer, and much more. Add the following queries to the query editor window to retrieve data:
- This query will retrieve the top 10 computers with the most error events over the past day:
Event | where (EventLevelName == "Error") | where (TimeGenerated > ago(1days)) | summarize ErrorCount
- This query will create a line chart with the processor utilization for each computer from
last week:Perf | where ObjectName == "Processor" and CounterName == "% Processor Time" | where TimeGenerated
- This query will retrieve the top 10 computers with the most error events over the past day: