The Azure Monitor Query Logs action runs a KQL (Kusto Query Language) query against an Azure Monitor Log Analytics workspace and returns the result table to your workflow.
Query Azure Monitor logs
Use this action to query log data — for example, application requests, failures, or custom logs — and then branch or notify based on the results.
重要
The Azure AD service principal you use must have the Log Analytics Reader role on the target workspace.
The following inputs are available for this action:
Input | Type | Description |
|---|---|---|
| String | Required. An Azure Service Principal clientId (UUID format). Pass as a secret. See how to register an Azure app. |
| String | Required. An Azure Service Principal clientSecret. Pass as a secret. See how to register an Azure app. |
| String | Required. The Azure tenant identifier (UUID format). Can be passed as a secret. |
| String | Required. The Log Analytics workspace ID (GUID). For example, |
| String | Required. The KQL query to run against the workspace. For example, |
| String | Optional. An ISO-8601 duration that bounds the query time range. For example, |
| List | Optional. A list of selectors used to extract or rename specific values from the response. For example, |
The following outputs are available for this action:
Output | Type | Description |
|---|---|---|
| Boolean | Query result status. |
| String | Failure reason. The action sets this field when |
| Object | The full Log Analytics response. Result rows are at |
The following example queries the AppRequests table for the last 25 days and sends a summary to a Slack channel.
name: query-azure-monitor-logs
steps: - name: query_app_requests type: action action: azure.monitor.queryLogs version: 1 inputs: clientId: ${{ :secrets:azure-client-id }} clientSecret: ${{ :secrets:azure-client-secret }} tenantId: ${{ :secrets:azure-tenant-id }} workspaceId: "78460d46-1c7c-494b-90b4-e21288a074d4" query: |- AppRequests | take 10 timespan: P25D selectors: - name: records expression: ".response.tables[0] as $t | ($t.columns | map(.name)) as $cols | $t.rows | map(. as $row | reduce range(0; ($cols | length)) as $i ({}; . + {($cols[$i]): $row[$i]}))" - name: send_slack_notification type: action action: newrelic.notification.sendSlack version: 1 inputs: destinationId: ${{ :secrets:slack-destination-id }} channel: ops-alerts text: ${{ "*AppRequests* (" + (.steps.query_app_requests.outputs.records | length | tostring) + " rows)\n```\n" + (.steps.query_app_requests.outputs.records | map([(.OperationName // ""), (.ResultCode // ""), (.Url // ""), ((.DurationMs // 0) | tostring) + "ms"] | join(" | ")) | join("\n")) + "\n```" }} next: end