# Azure Monitor, Application Insights and KQL — Azure

Source: https://www.skillbyai.com/en/azure/o-monitor

> Collect metrics, logs and traces and query them with KQL.

## One platform for telemetry

**Azure Monitor** collects two main kinds of data. **Metrics** are lightweight numbers sampled over time (CPU, request count, queue length), good for dashboards and fast alerts. **Logs** are detailed records stored in a **Log Analytics workspace** and queried with **Kusto Query Language (KQL)**: activity logs, resource diagnostic logs (enabled through **diagnostic settings**) and application telemetry. **Application Insights** is the application performance monitoring part of Azure Monitor: requests, dependencies, exceptions and distributed traces, collected through the Azure Monitor **OpenTelemetry** distro or auto-instrumentation. **Alerts** fire on metric thresholds or log queries and notify through **action groups** (email, SMS, webhook, an ITSM tool).

## KQL: slow and failing requests

Run in Application Insights *Logs*. The pipe `|` passes each result to the next operator, much like a shell pipeline.

```text
requests
| where timestamp > ago(1h)
| summarize total = count(),
            failed = countif(success == false),
            p95_ms = percentile(duration, 95)
    by name
| extend failure_rate = round(100.0 * failed / total, 2)
| order by p95_ms desc
| take 10
```

## Alert on symptoms users feel

Alerting on every CPU spike causes alert fatigue. Alert on error rate, latency percentiles and queue backlog, which users notice, and keep resource metrics for diagnosis.

**Quiz:** Where are resource diagnostic logs and Application Insights data queried with KQL?

- [ ] Azure Container Registry
- [ ] Azure Key Vault
- [x] Log Analytics workspace
- [ ] Blob Archive tier

*Answer:* Log Analytics workspace. Logs are stored in a Log Analytics workspace, where KQL queries run.
