All skills
microsoft avatar

/azure-monitor-ingestion-py

@e19efc2
by microsoftmicrosoft/skills3.1k stars
351

Azure Monitor Ingestion SDK for Python. Use for sending custom logs to Log Analytics workspace via Logs Ingestion API. Triggers: "azure-monitor-ingestion", "LogsIngestionClient", "custom logs", "DCR", "data collection rule", "Log Analytics".

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-monitor-ingestion-py

This session only. Nothing lands on disk.

referencesnon-hero-scenarios.md

≈529 tokens on demand. Your agent reads this file only when SKILL.md points to it.

azure-monitor-ingestion-py non-hero scenarios

These scenarios are intentionally separate from hero flows in SKILL.md. They cover secondary/advanced patterns typically used after the primary end-to-end path is working.

Async Client

import asyncio
from azure.monitor.ingestion.aio import LogsIngestionClient
from azure.identity.aio import DefaultAzureCredential

async def upload_logs():
    async with DefaultAzureCredential() as credential:
        async with LogsIngestionClient(
            endpoint=endpoint,
            credential=credential
        ) as client:
            await client.upload(
                rule_id=rule_id,
                stream_name=stream_name,
                logs=logs
            )

asyncio.run(upload_logs())

Sovereign Clouds

from azure.identity import AzureAuthorityHosts, DefaultAzureCredential
from azure.monitor.ingestion import LogsIngestionClient

# Azure Government
credential = DefaultAzureCredential(authority=AzureAuthorityHosts.AZURE_GOVERNMENT)
with LogsIngestionClient(
    endpoint="https://example.ingest.monitor.azure.us",
    credential=credential,
    credential_scopes=["https://monitor.azure.us/.default"]
) as client:
    # client.upload(...)
    ...

Batching Behavior

The SDK automatically:

  • Splits logs into chunks of 1MB or less
  • Compresses each chunk with gzip
  • Uploads chunks in parallel

No manual batching needed for large log sets.

Client Types

Client Purpose
LogsIngestionClient Sync client for uploading logs
LogsIngestionClient (aio) Async client for uploading logs

Key Concepts

Concept Description
DCE Data Collection Endpoint — ingestion URL
DCR Data Collection Rule — defines schema, transformations, destination
Stream Named data flow within a DCR
Custom Table Target table in Log Analytics (ends with _CL)

DCR Stream Name Format

Stream names follow patterns:

  • Custom-<TableName>_CL — For custom tables
  • Microsoft-<TableName> — For built-in tables

Source: SKILL.md on GitHub

1 warning15d4 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill provides functionality to send custom logs to Azure Monitor. It follows established security best practices, such as recommending the use of DefaultAzureCredential for authentication. A potential security consideration is the ingestion of data from local files, which is expected for a logging utility. See the detailed analysis for additional context.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

  • Runlayer7mo

    2/2 files flagged

Signed by skilld at e19efc2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 months ago
Other metadata
metadata
{
  "author": "Microsoft",
  "version": "1.0.0",
  "package": "azure-monitor-ingestion"
}

README badge

README badge for microsoft/skills/azure-monitor-ingestion-py