Skip to content

Azure Monitor Data Collector

Azure Monitor Data Collector (azure-monitor)

Section titled “Azure Monitor Data Collector (azure-monitor)”

Specialized preset that wraps azure-monitor output parameters so deployments can ship datasets into Azure Log Analytics/Sentinel without hand-authoring http-post jobs.

Observability Enterprise edition json

output:
azure-monitor:
shared-key: ~
workspace-id: ~
JSON
{
"output": {
"azure-monitor": {
"shared-key": null,
"workspace-id": null
}
}
}

A ✓ marks a field that accepts a context variable such as {{ VARIABLE }}.

Authentication
Field Type Required Description
shared-key string Base64-encoded workspace shared key.
Diagnostics
Field Type Required Description
test-url url (string) Override endpoint during dry-runs (bypasses workspace+api_version).
Examples: https://example.com/path
Endpoint
Field Type Required Description
workspace-id string Azure Log Analytics workspace ID (customer ID).
ingestion-uri string Full ingestion URI (defaults to https://{workspace}.ods.opinsights.azure.com/api/logs?api-version=2016-04-01).
api-version string API version appended when ingestion_uri is omitted.
Payload
Field Type Required Description
log-type string Log-Type assigned inside Azure Monitor.
body-field field (string) Restrict the payload to this field (must contain JSON).
Examples: data_field
time-generated-field field (string) ISO 8601 timestamp field mapped to time-generated-field.
Examples: data_field
resource-id string Azure Resource ID applied via x-ms-AzureResourceId.
Processing
Field Type Required Description
batch Batch Batching behavior for upstream events.
Reliability
Field Type Required Description
retry Retry Retry policy applied to Azure Monitor requests.
Field Type Required Description
fixed-size number (integer) maximum number of events in an output batch.
Examples: 42, 1.2e-10
max-bytes number (integer) Close the batch before adding an event that would make the serialized request payload exceed this many bytes.
Examples: 42, 1.2e-10
mode Mode If ‘document’ send on end of document generated by input. If ‘fixed’, use fixed_size.
Allowed values: fixed, document
timeout time-interval (string) interval after which the batch is sent, to keep throughput going (default 100ms).
Default: 100ms
Examples: 500ms, 2h
header multiline-text (string) put a header line before the batch.
footer multiline-text (string) put a header line after the last line of the batch.
use-document-marker boolean (bool) Enrich the job metadata with a document marker (for document handling in batch mode).
Default: false
wrap-as-json boolean (bool) Format the output batch as a JSON array.
Default: false
Field Type Required Description
strategy Strategy Backoff strategy to use (default exponential).
Allowed values: exponential, linear, fixed
base string Base delay before retrying (e.g. “200ms”).
max string Maximum delay between retries.
jitter boolean (bool) Whether to add jitter to retry delays.
Default: false
Field Type Required Description
max-attempts number (integer) Maximum attempts before giving up.
Examples: 42, 1.2e-10
forever boolean (bool) Retry indefinitely until cancelled.
Default: false
backoff Backoff Backoff strategy configuration.
Value Aliases Name Description
fixed fixed
document document
Value Aliases Name Description
exponential exponential
linear linear
fixed fixed