Microsoft Azure is an open, flexible, enterprise-grade cloud computing platform. Move faster, do more, and save money with IaaS + PaaS.
The Azure Log integration feature was deprecated on 15 June 2019. AzLog downloads were disabled on 27 June 2018.
Cloud (System and Application)
Supported Model Name/Number
Azure Log Integration
Supported Software Version(s)
Configurable Log Output?
Log Source Type
Syslog - Microsoft Azure Log Integration
Log Processing Policy
The Event logs are available in ‘JSON’, Syslog (LEEF) and MS Event Log formats. The LEEF format is the configuration used by this policy.
- An Azure subscription
- A storage account for Windows Azure Diagnostics (WAD) logging
- A machine that runs the Azure Log Integration service & a machine that would be monitored
Device Configuration Checklist
- Installed Azure Log Integration from the installer
- Post-installation and validation steps
- Integrate Windows VM Logs
- Integrate Azure activity logs
Currently Supported Log Types
Supported Schema Fields
Description, level, resourceGroupName, status
eventName, level, resourceType, status
Description, level, resourceGroupName, resourceId, status
Description, level, resourceGroupName, resourceType, resourceId, status
Parsed Metadata Fields
Product Field Name
LogRhythm Metadata Field
Vendor Message ID
Source IP Address