Azure Monitor Data Collector
Azure Monitor Data Collector (azure-monitor)
Section titled “Azure Monitor Data Collector (azure-monitor)”Specialized preset that wraps azure-monitor output parameters so deployments can ship datasets into Azure Log Analytics/Sentinel without hand-authoring http-post jobs.
Observability Enterprise edition json
Minimal example
Section titled “Minimal example”output: azure-monitor: shared-key: ~ workspace-id: ~JSON
{ "output": { "azure-monitor": { "shared-key": null, "workspace-id": null } }}Contents
Section titled “Contents”A ✓ marks a field that accepts a context variable such as
{{ VARIABLE }}.
Authentication
Section titled “Authentication”Authentication
| Field | Type | Required | Description |
|---|---|---|---|
shared-key |
string |
✅ | Base64-encoded workspace shared key. |
Diagnostics
Section titled “Diagnostics”Diagnostics
| Field | Type | Required | Description |
|---|---|---|---|
test-url |
url (string) |
Override endpoint during dry-runs (bypasses workspace+api_version). Examples: https://example.com/path |
Endpoint
Section titled “Endpoint”Endpoint
| Field | Type | Required | Description |
|---|---|---|---|
workspace-id |
string |
✅ | Azure Log Analytics workspace ID (customer ID). |
ingestion-uri |
string |
Full ingestion URI (defaults to https://{workspace}.ods.opinsights.azure.com/api/logs?api-version=2016-04-01). | |
api-version |
string |
API version appended when ingestion_uri is omitted. |
Payload
Section titled “Payload”Payload
| Field | Type | Required | Description |
|---|---|---|---|
log-type |
string |
Log-Type assigned inside Azure Monitor. | |
body-field |
field (string) |
Restrict the payload to this field (must contain JSON). Examples: data_field |
|
time-generated-field |
field (string) |
ISO 8601 timestamp field mapped to time-generated-field.Examples: data_field |
|
resource-id |
string |
Azure Resource ID applied via x-ms-AzureResourceId. |
Processing
Section titled “Processing”Processing
| Field | Type | Required | Description |
|---|---|---|---|
batch |
Batch |
Batching behavior for upstream events. |
Reliability
Section titled “Reliability”Reliability
| Field | Type | Required | Description |
|---|---|---|---|
retry |
Retry |
Retry policy applied to Azure Monitor requests. |
Schema
Section titled “Schema”- Batch Fields
- Retry - Backoff Fields
- Retry Fields
- Batch - Mode Options
- Retry - Backoff - Strategy Options
Batch Fields
Section titled “Batch Fields”| Field | Type | Required | Description |
|---|---|---|---|
fixed-size ✓ |
number (integer) |
maximum number of events in an output batch. Examples: 42, 1.2e-10 |
|
max-bytes ✓ |
number (integer) |
Close the batch before adding an event that would make the serialized request payload exceed this many bytes. Examples: 42, 1.2e-10 |
|
mode |
Mode |
✅ | If ‘document’ send on end of document generated by input. If ‘fixed’, use fixed_size.Allowed values: fixed, document |
timeout |
time-interval (string) |
✅ | interval after which the batch is sent, to keep throughput going (default 100ms). Default: 100msExamples: 500ms, 2h |
header |
multiline-text (string) |
put a header line before the batch. | |
footer |
multiline-text (string) |
put a header line after the last line of the batch. | |
use-document-marker ✓ |
boolean (bool) |
Enrich the job metadata with a document marker (for document handling in batch mode). Default: false |
|
wrap-as-json ✓ |
boolean (bool) |
Format the output batch as a JSON array. Default: false |
Retry - Backoff Fields
Section titled “Retry - Backoff Fields”| Field | Type | Required | Description |
|---|---|---|---|
strategy |
Strategy |
Backoff strategy to use (default exponential). Allowed values: exponential, linear, fixed |
|
base |
string |
Base delay before retrying (e.g. “200ms”). | |
max |
string |
Maximum delay between retries. | |
jitter ✓ |
boolean (bool) |
Whether to add jitter to retry delays. Default: false |
Retry Fields
Section titled “Retry Fields”| Field | Type | Required | Description |
|---|---|---|---|
max-attempts |
number (integer) |
Maximum attempts before giving up. Examples: 42, 1.2e-10 |
|
forever ✓ |
boolean (bool) |
Retry indefinitely until cancelled. Default: false |
|
backoff |
Backoff |
Backoff strategy configuration. |
Batch - Mode Options
Section titled “Batch - Mode Options”| Value | Aliases | Name | Description |
|---|---|---|---|
fixed |
fixed | ||
document |
document |
Retry - Backoff - Strategy Options
Section titled “Retry - Backoff - Strategy Options”| Value | Aliases | Name | Description |
|---|---|---|---|
exponential |
exponential | ||
linear |
linear | ||
fixed |
fixed |