• /
  • EnglishEspañolFrançais日本語한국어Português
  • ログイン今すぐ開始

Query Azure Monitor logs

|View as Markdown (English)

The Azure Monitor Query Logs action runs a KQL (Kusto Query Language) query against an Azure Monitor Log Analytics workspace and returns the result table to your workflow.

Query Azure Monitor logs

Use this action to query log data — for example, application requests, failures, or custom logs — and then branch or notify based on the results.

重要

The Azure AD service principal you use must have the Log Analytics Reader role on the target workspace.

The following inputs are available for this action:

Input

Type

Description

clientId

String

Required. An Azure Service Principal clientId (UUID format). Pass as a secret. See how to register an Azure app.

clientSecret

String

Required. An Azure Service Principal clientSecret. Pass as a secret. See how to register an Azure app.

tenantId

String

Required. The Azure tenant identifier (UUID format). Can be passed as a secret.

workspaceId

String

Required. The Log Analytics workspace ID (GUID). For example, "78460d46-1c7c-494b-90b4-e21288a074d4".

query

String

Required. The KQL query to run against the workspace. For example, "AppRequests | take 10". Maximum 8000 characters.

timespan

String

Optional. An ISO-8601 duration that bounds the query time range. For example, "P7D" (7 days) or "PT1H" (1 hour). When omitted, the query runs without a time constraint.

selectors

List

Optional. A list of selectors used to extract or rename specific values from the response. For example, [{"name": "records", "expression": ".response.tables[0].rows"}].

The following outputs are available for this action:

Output

Type

Description

success

Boolean

Query result status. true when the call succeeded (HTTP 2xx). false otherwise.

errorMessage

String

Failure reason. The action sets this field when success is false.

response

Object

The full Log Analytics response. Result rows are at response.tables[0].rows. Column definitions are at response.tables[0].columns. For more information, see the Azure Monitor Log Analytics API reference.

The following example queries the AppRequests table for the last 25 days and sends a summary to a Slack channel.

name: query-azure-monitor-logs
steps:
- name: query_app_requests
type: action
action: azure.monitor.queryLogs
version: 1
inputs:
clientId: ${{ :secrets:azure-client-id }}
clientSecret: ${{ :secrets:azure-client-secret }}
tenantId: ${{ :secrets:azure-tenant-id }}
workspaceId: "78460d46-1c7c-494b-90b4-e21288a074d4"
query: |-
AppRequests
| take 10
timespan: P25D
selectors:
- name: records
expression: ".response.tables[0] as $t | ($t.columns | map(.name)) as $cols | $t.rows | map(. as $row | reduce range(0; ($cols | length)) as $i ({}; . + {($cols[$i]): $row[$i]}))"
- name: send_slack_notification
type: action
action: newrelic.notification.sendSlack
version: 1
inputs:
destinationId: ${{ :secrets:slack-destination-id }}
channel: ops-alerts
text: ${{ "*AppRequests* (" + (.steps.query_app_requests.outputs.records | length | tostring) + " rows)\n```\n" + (.steps.query_app_requests.outputs.records | map([(.OperationName // ""), (.ResultCode // ""), (.Url // ""), ((.DurationMs // 0) | tostring) + "ms"] | join(" | ")) | join("\n")) + "\n```" }}
next: end
Copyright © 2026 New Relic株式会社。

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.