All skills
microsoft avatar

/azure-diagnostics

@ae5e585
by microsoftmicrosoft/skills3.1k stars
351

Debug Azure production issues on Azure using AppLens, Azure Monitor, resource health, and safe triage. WHEN: debug production issues, troubleshoot app service, app service high CPU, app service deployment failure, troubleshoot container apps, troubleshoot functions, troubleshoot AKS, VM RDP, Linux SSH, VM black screen, can't connect to VM, reset VM password, NSG or firewall blocking, kubectl cannot connect, kube-system/CoreDNS failures, pod pending, crashloop, node not ready, upgrade failures, analyze logs, KQL, insights, image pull failures, cold start issues, health probe failures, resource health, root cause of errors, troubleshoot event hubs, troubleshoot service bus, messaging SDK error, AMQP connection failure, message lock lost, service bus dead letter.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-diagnostics

This session only. Nothing lands on disk.

referencesazure-resource-graph.md

≈751 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Azure Resource Graph Queries for Diagnostics

Azure Resource Graph (ARG) enables fast, cross-subscription resource querying using KQL via az graph query. Use it to check resource health, find degraded resources, and correlate incidents.

How to Query

Use the extension_cli_generate MCP tool to generate az graph query commands:

mcp_azure_mcp_extension_cli_generate
  intent: "query Azure Resource Graph to <describe what you want to diagnose>"
  cli-type: "az"

Or construct directly:

az graph query -q "<KQL>" --query "data[].{name:name, type:type}" -o table

⚠️ Prerequisite: az extension add --name resource-graph

Key Tables

Table Contains
Resources All ARM resources (name, type, location, properties, tags)
HealthResources Resource health availability status
ServiceHealthResources Azure service health events and incidents
ResourceContainers Subscriptions, resource groups, management groups

Diagnostics Query Patterns

Check resource health status across resources:

HealthResources
| where type =~ 'microsoft.resourcehealth/availabilitystatuses'
| project name, availabilityState=properties.availabilityState, reasonType=properties.reasonType

Find resources in unhealthy or degraded state:

HealthResources
| where type =~ 'microsoft.resourcehealth/availabilitystatuses'
| where properties.availabilityState != 'Available'
| project name, state=properties.availabilityState, reason=properties.reasonType, summary=properties.summary

Query active service health incidents:

ServiceHealthResources
| where type =~ 'microsoft.resourcehealth/events'
| where properties.Status == 'Active'
| project name, title=properties.Title, impact=properties.Impact, status=properties.Status

Find resources by provisioning state (failed/stuck deployments):

Resources
| where properties.provisioningState != 'Succeeded'
| project name, type, resourceGroup, provisioningState=properties.provisioningState

Find App Services in stopped or error state:

Resources
| where type =~ 'microsoft.web/sites'
| where properties.state != 'Running'
| project name, state=properties.state, resourceGroup, location

Find Container Apps with provisioning issues:

Resources
| where type =~ 'microsoft.app/containerapps'
| where properties.provisioningState != 'Succeeded'
| project name, provisioningState=properties.provisioningState, resourceGroup

Tips

  • Use =~ for case-insensitive type matching (resource types are lowercase)
  • Navigate properties with properties.fieldName
  • Use --first N to limit result count
  • Use --subscriptions to scope to specific subscriptions
  • Combine ARG health data with Azure Monitor metrics for full picture
  • Check HealthResources before deep-diving into application logs

Source: SKILL.md on GitHub

1 warning15d4 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill is designed for Azure diagnostics and troubleshooting, providing a comprehensive set of guides and scripts that utilize standard tools like the Azure CLI and kubectl. It includes some security considerations, such as the ingestion of logs which provides a surface for indirect prompt injection, and the use of privileged debug pods for advanced diagnostics. These are used within the skill's intended functionality and are accompanied by appropriate guidance for user approval.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

  • Runlayer7mo

    4/4 files flagged

Signed by skilld at ae5e585. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "author": "Microsoft",
  "version": "1.2.6"
}

README badge

README badge for microsoft/skills/azure-diagnostics