SkillByAIOpen interactive version →

Lesson 21 / 25

Azure Monitor, Application Insights and KQL

Collect metrics, logs and traces and query them with KQL.

One platform for telemetry

Azure Monitor collects two main kinds of data. Metrics are lightweight numbers sampled over time (CPU, request count, queue length), good for dashboards and fast alerts. Logs are detailed records stored in a Log Analytics workspace and queried with Kusto Query Language (KQL): activity logs, resource diagnostic logs (enabled through diagnostic settings) and application telemetry. Application Insights is the application performance monitoring part of Azure Monitor: requests, dependencies, exceptions and distributed traces, collected through the Azure Monitor OpenTelemetry distro or auto-instrumentation. Alerts fire on metric thresholds or log queries and notify through action groups (email, SMS, webhook, an ITSM tool).

KQL: slow and failing requests

Run in Application Insights Logs. The pipe | passes each result to the next operator, much like a shell pipeline.

requests
| where timestamp > ago(1h)
| summarize total = count(),
            failed = countif(success == false),
            p95_ms = percentile(duration, 95)
    by name
| extend failure_rate = round(100.0 * failed / total, 2)
| order by p95_ms desc
| take 10

Alert on symptoms users feel

Alerting on every CPU spike causes alert fatigue. Alert on error rate, latency percentiles and queue backlog, which users notice, and keep resource metrics for diagnosis.

Quick check: Where are resource diagnostic logs and Application Insights data queried with KQL?

  • Azure Container Registry
  • Azure Key Vault
  • Log Analytics workspace
  • Blob Archive tier
Answer

Log Analytics workspace — Logs are stored in a Log Analytics workspace, where KQL queries run.