Skip to content

Commit 13293c4

Browse files
committed
ingestion api and remove samples
1 parent 8dc218a commit 13293c4

File tree

7 files changed

+70
-287
lines changed

7 files changed

+70
-287
lines changed

.openpublishing.redirection.azure-monitor.json

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6628,6 +6628,11 @@
66286628
"source_path_from_root": "/articles/azure-monitor/essentials/data-collection.md",
66296629
"redirect_url": "/azure/azure-monitor/essentials/data-collection-rules",
66306630
"redirect_document_id": false
6631+
},
6632+
{
6633+
"source_path_from_root": "/articles/azure-monitor/agents/resource-manager-agent.md",
6634+
"redirect_url": "/azure/azure-monitor/essentials/data-collection-rule-create-edit?tabs=arm#manually-create-a-dcr",
6635+
"redirect_document_id": false
66316636
}
66326637
]
66336638
}

articles/azure-monitor/agents/resource-manager-data-collection-rules.md

Lines changed: 0 additions & 216 deletions
This file was deleted.

articles/azure-monitor/essentials/data-collection-rule-create-edit.md

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -294,10 +294,6 @@ resource association 'Microsoft.Insights/dataCollectionRuleAssociations@2021-09-
294294
```
295295
---
296296

297-
The following tutorials include examples of manually creating DCRs.
298-
299-
- [Send data to Azure Monitor using Logs ingestion API (Resource Manager templates)](../logs/tutorial-logs-ingestion-api.md)
300-
- [Add transformation in workspace data collection rule to Azure Monitor using Resource Manager templates](../logs/tutorial-workspace-transformations-api.md)
301297

302298
## Edit a DCR
303299
To edit a DCR, you can use any of the methods described in the previous section to create a DCR using a modified version of the JSON.
22.3 KB
Loading

articles/azure-monitor/logs/logs-ingestion-api-overview.md

Lines changed: 65 additions & 65 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: Logs Ingestion API in Azure Monitor
33
description: Send data to a Log Analytics workspace using REST API or client libraries.
44
ms.topic: conceptual
5-
ms.date: 11/15/2023
5+
ms.date: 03/23/2024
66

77
---
88

@@ -17,70 +17,6 @@ The data sent by your application to the API must be formatted in JSON and match
1717

1818
:::image type="content" source="../essentials/media/data-collection-rule-overview/overview-log-ingestion-api.png" lightbox="../essentials/media/data-collection-rule-overview/overview-log-ingestion-api.png" alt-text="Diagram that shows an overview of logs ingestion API." border="false":::
1919

20-
21-
## Supported tables
22-
23-
Data sent to the ingestion API can be sent to the following tables:
24-
25-
| Tables | Description |
26-
|:---|:---|
27-
| Custom tables | Any custom table that you create in your Log Analytics workspace. The target table must exist before you can send data to it. Custom tables must have the `_CL` suffix. |
28-
| Azure tables | The following Azure tables are currently supported. Other tables may be added to this list as support for them is implemented.<br><br>
29-
- [ADAssessmentRecommendation](/azure/azure-monitor/reference/tables/adassessmentrecommendation)<br>
30-
- [ADSecurityAssessmentRecommendation](/azure/azure-monitor/reference/tables/adsecurityassessmentrecommendation)<br>
31-
- [ASimAuditEventLogs](/azure/azure-monitor/reference/tables/asimauditeventlogs)<br>
32-
- [ASimAuthenticationEventLogs](/azure/azure-monitor/reference/tables/asimauthenticationeventlogs)<br>
33-
- [ASimDhcpEventLogs](/azure/azure-monitor/reference/tables/asimdhcpeventlogs)<br>
34-
- [ASimDnsActivityLogs](/azure/azure-monitor/reference/tables/asimdnsactivitylogs)<br>
35-
- ASimDnsAuditLogs<br>
36-
- [ASimFileEventLogs](/azure/azure-monitor/reference/tables/asimfileeventlogs)<br>
37-
- [ASimNetworkSessionLogs](/azure/azure-monitor/reference/tables/asimnetworksessionlogs)<br>
38-
- [ASimProcessEventLogs](/azure/azure-monitor/reference/tables/asimprocesseventlogs)<br>
39-
- [ASimRegistryEventLogs](/azure/azure-monitor/reference/tables/asimregistryeventlogs)<br>
40-
- [ASimUserManagementActivityLogs](/azure/azure-monitor/reference/tables/asimusermanagementactivitylogs)<br>
41-
- [ASimWebSessionLogs](/azure/azure-monitor/reference/tables/asimwebsessionlogs)<br>
42-
- [AWSCloudTrail](/azure/azure-monitor/reference/tables/awscloudtrail)<br>
43-
- [AWSCloudWatch](/azure/azure-monitor/reference/tables/awscloudwatch)<br>
44-
- [AWSGuardDuty](/azure/azure-monitor/reference/tables/awsguardduty)<br>
45-
- [AWSVPCFlow](/azure/azure-monitor/reference/tables/awsvpcflow)<br>
46-
- [AzureAssessmentRecommendation](/azure/azure-monitor/reference/tables/azureassessmentrecommendation)<br>
47-
- [CommonSecurityLog](/azure/azure-monitor/reference/tables/commonsecuritylog)<br>
48-
- [DeviceTvmSecureConfigurationAssessmentKB](/azure/azure-monitor/reference/tables/devicetvmsecureconfigurationassessmentkb)<br>
49-
- [DeviceTvmSoftwareVulnerabilitiesKB](/azure/azure-monitor/reference/tables/devicetvmsoftwarevulnerabilitieskb)<br>
50-
- [ExchangeAssessmentRecommendation](/azure/azure-monitor/reference/tables/exchangeassessmentrecommendation)<br>
51-
- [ExchangeOnlineAssessmentRecommendation](/azure/azure-monitor/reference/tables/exchangeonlineassessmentrecommendation)<br>
52-
- [GCPAuditLogs](/azure/azure-monitor/reference/tables/gcpauditlogs)<br>
53-
- [GoogleCloudSCC](/azure/azure-monitor/reference/tables/googlecloudscc)<br>
54-
- [SCCMAssessmentRecommendation](/azure/azure-monitor/reference/tables/sccmassessmentrecommendation)<br>
55-
- [SCOMAssessmentRecommendation](/azure/azure-monitor/reference/tables/scomassessmentrecommendation)<br>
56-
- [SecurityEvent](/azure/azure-monitor/reference/tables/securityevent)<br>
57-
- [SfBAssessmentRecommendation](/azure/azure-monitor/reference/tables/sfbassessmentrecommendation)<br>
58-
- [SfBOnlineAssessmentRecommendation](/azure/azure-monitor/reference/tables/sfbonlineassessmentrecommendation)<br>
59-
- [SharePointOnlineAssessmentRecommendation](/azure/azure-monitor/reference/tables/sharepointonlineassessmentrecommendation)<br>
60-
- [SPAssessmentRecommendation](/azure/azure-monitor/reference/tables/spassessmentrecommendation)<br>
61-
- [SQLAssessmentRecommendation](/azure/azure-monitor/reference/tables/sqlassessmentrecommendation)<br>
62-
- StorageInsightsAccountPropertiesDaily<br>
63-
- StorageInsightsDailyMetrics<br>
64-
- StorageInsightsHourlyMetrics<br>
65-
- StorageInsightsMonthlyMetrics<br>
66-
- StorageInsightsWeeklyMetrics<br>
67-
- [Syslog](/azure/azure-monitor/reference/tables/syslog)<br>
68-
- [UCClient](/azure/azure-monitor/reference/tables/ucclient)<br>
69-
- [UCClientReadinessStatus](/azure/azure-monitor/reference/tables/ucclientreadinessstatus)<br>
70-
- [UCClientUpdateStatus](/azure/azure-monitor/reference/tables/ucclientupdatestatus)<br>
71-
- [UCDeviceAlert](/azure/azure-monitor/reference/tables/ucdevicealert)<br>
72-
- [UCDOAggregatedStatus](/azure/azure-monitor/reference/tables/ucdoaggregatedstatus)<br>
73-
- [UCDOStatus](/azure/azure-monitor/reference/tables/ucdostatus)<br>
74-
- [UCServiceUpdateStatus](/azure/azure-monitor/reference/tables/ucserviceupdatestatus)<br>
75-
- [UCUpdateAlert](/azure/azure-monitor/reference/tables/ucupdatealert)<br>
76-
- [WindowsClientAssessmentRecommendation](/azure/azure-monitor/reference/tables/windowsclientassessmentrecommendation)<br>
77-
- [WindowsEvent](/azure/azure-monitor/reference/tables/windowsevent)<br>
78-
- [WindowsServerAssessmentRecommendation](/azure/azure-monitor/reference/tables/windowsserverassessmentrecommendation)<br>
79-
80-
81-
> [!NOTE]
82-
> Column names must start with a letter and can consist of up to 45 alphanumeric characters and underscores (`_`). `_ResourceId`, `id`, `_ResourceId`, `_SubscriptionId`, `TenantId`, `Type`, `UniqueId`, and `Title` are reserved column names. Custom columns you add to an Azure table must have the suffix `_CF`.
83-
8420
## Configuration
8521
The following table describes each component in Azure that you must configure before you can use the Logs Ingestion API.
8622

@@ -171,6 +107,70 @@ Ensure that the request body is properly encoded in UTF-8 to prevent any issues
171107

172108
See [Sample code to send data to Azure Monitor using Logs ingestion API](tutorial-logs-ingestion-code.md?tabs=powershell#sample-code) for an example of the API call using PowerShell.
173109

110+
111+
## Supported tables
112+
113+
Data sent to the ingestion API can be sent to the following tables:
114+
115+
| Tables | Description |
116+
|:---|:---|
117+
| Custom tables | Any custom table that you create in your Log Analytics workspace. The target table must exist before you can send data to it. Custom tables must have the `_CL` suffix. |
118+
| Azure tables | The following Azure tables are currently supported. Other tables may be added to this list as support for them is implemented.<br><br>
119+
- [ADAssessmentRecommendation](/azure/azure-monitor/reference/tables/adassessmentrecommendation)<br>
120+
- [ADSecurityAssessmentRecommendation](/azure/azure-monitor/reference/tables/adsecurityassessmentrecommendation)<br>
121+
- [ASimAuditEventLogs](/azure/azure-monitor/reference/tables/asimauditeventlogs)<br>
122+
- [ASimAuthenticationEventLogs](/azure/azure-monitor/reference/tables/asimauthenticationeventlogs)<br>
123+
- [ASimDhcpEventLogs](/azure/azure-monitor/reference/tables/asimdhcpeventlogs)<br>
124+
- [ASimDnsActivityLogs](/azure/azure-monitor/reference/tables/asimdnsactivitylogs)<br>
125+
- ASimDnsAuditLogs<br>
126+
- [ASimFileEventLogs](/azure/azure-monitor/reference/tables/asimfileeventlogs)<br>
127+
- [ASimNetworkSessionLogs](/azure/azure-monitor/reference/tables/asimnetworksessionlogs)<br>
128+
- [ASimProcessEventLogs](/azure/azure-monitor/reference/tables/asimprocesseventlogs)<br>
129+
- [ASimRegistryEventLogs](/azure/azure-monitor/reference/tables/asimregistryeventlogs)<br>
130+
- [ASimUserManagementActivityLogs](/azure/azure-monitor/reference/tables/asimusermanagementactivitylogs)<br>
131+
- [ASimWebSessionLogs](/azure/azure-monitor/reference/tables/asimwebsessionlogs)<br>
132+
- [AWSCloudTrail](/azure/azure-monitor/reference/tables/awscloudtrail)<br>
133+
- [AWSCloudWatch](/azure/azure-monitor/reference/tables/awscloudwatch)<br>
134+
- [AWSGuardDuty](/azure/azure-monitor/reference/tables/awsguardduty)<br>
135+
- [AWSVPCFlow](/azure/azure-monitor/reference/tables/awsvpcflow)<br>
136+
- [AzureAssessmentRecommendation](/azure/azure-monitor/reference/tables/azureassessmentrecommendation)<br>
137+
- [CommonSecurityLog](/azure/azure-monitor/reference/tables/commonsecuritylog)<br>
138+
- [DeviceTvmSecureConfigurationAssessmentKB](/azure/azure-monitor/reference/tables/devicetvmsecureconfigurationassessmentkb)<br>
139+
- [DeviceTvmSoftwareVulnerabilitiesKB](/azure/azure-monitor/reference/tables/devicetvmsoftwarevulnerabilitieskb)<br>
140+
- [ExchangeAssessmentRecommendation](/azure/azure-monitor/reference/tables/exchangeassessmentrecommendation)<br>
141+
- [ExchangeOnlineAssessmentRecommendation](/azure/azure-monitor/reference/tables/exchangeonlineassessmentrecommendation)<br>
142+
- [GCPAuditLogs](/azure/azure-monitor/reference/tables/gcpauditlogs)<br>
143+
- [GoogleCloudSCC](/azure/azure-monitor/reference/tables/googlecloudscc)<br>
144+
- [SCCMAssessmentRecommendation](/azure/azure-monitor/reference/tables/sccmassessmentrecommendation)<br>
145+
- [SCOMAssessmentRecommendation](/azure/azure-monitor/reference/tables/scomassessmentrecommendation)<br>
146+
- [SecurityEvent](/azure/azure-monitor/reference/tables/securityevent)<br>
147+
- [SfBAssessmentRecommendation](/azure/azure-monitor/reference/tables/sfbassessmentrecommendation)<br>
148+
- [SfBOnlineAssessmentRecommendation](/azure/azure-monitor/reference/tables/sfbonlineassessmentrecommendation)<br>
149+
- [SharePointOnlineAssessmentRecommendation](/azure/azure-monitor/reference/tables/sharepointonlineassessmentrecommendation)<br>
150+
- [SPAssessmentRecommendation](/azure/azure-monitor/reference/tables/spassessmentrecommendation)<br>
151+
- [SQLAssessmentRecommendation](/azure/azure-monitor/reference/tables/sqlassessmentrecommendation)<br>
152+
- StorageInsightsAccountPropertiesDaily<br>
153+
- StorageInsightsDailyMetrics<br>
154+
- StorageInsightsHourlyMetrics<br>
155+
- StorageInsightsMonthlyMetrics<br>
156+
- StorageInsightsWeeklyMetrics<br>
157+
- [Syslog](/azure/azure-monitor/reference/tables/syslog)<br>
158+
- [UCClient](/azure/azure-monitor/reference/tables/ucclient)<br>
159+
- [UCClientReadinessStatus](/azure/azure-monitor/reference/tables/ucclientreadinessstatus)<br>
160+
- [UCClientUpdateStatus](/azure/azure-monitor/reference/tables/ucclientupdatestatus)<br>
161+
- [UCDeviceAlert](/azure/azure-monitor/reference/tables/ucdevicealert)<br>
162+
- [UCDOAggregatedStatus](/azure/azure-monitor/reference/tables/ucdoaggregatedstatus)<br>
163+
- [UCDOStatus](/azure/azure-monitor/reference/tables/ucdostatus)<br>
164+
- [UCServiceUpdateStatus](/azure/azure-monitor/reference/tables/ucserviceupdatestatus)<br>
165+
- [UCUpdateAlert](/azure/azure-monitor/reference/tables/ucupdatealert)<br>
166+
- [WindowsClientAssessmentRecommendation](/azure/azure-monitor/reference/tables/windowsclientassessmentrecommendation)<br>
167+
- [WindowsEvent](/azure/azure-monitor/reference/tables/windowsevent)<br>
168+
- [WindowsServerAssessmentRecommendation](/azure/azure-monitor/reference/tables/windowsserverassessmentrecommendation)<br>
169+
170+
171+
> [!NOTE]
172+
> Column names must start with a letter and can consist of up to 45 alphanumeric characters and underscores (`_`). `_ResourceId`, `id`, `_ResourceId`, `_SubscriptionId`, `TenantId`, `Type`, `UniqueId`, and `Title` are reserved column names. Custom columns you add to an Azure table must have the suffix `_CF`.
173+
174174
## Limits and restrictions
175175

176176
For limits related to the Logs Ingestion API, see [Azure Monitor service limits](../service-limits.md#logs-ingestion-api).
31.8 KB
Loading

articles/azure-monitor/toc.yml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1433,8 +1433,6 @@ items:
14331433
items:
14341434
- name: Overview
14351435
href: resource-manager-samples.md
1436-
- name: Agents
1437-
href: agents/resource-manager-agent.md
14381436
- name: Alerts
14391437
items:
14401438
- name: Log search alert rules

0 commit comments

Comments
 (0)