How to get started with Azure log Analytics

If you’re interested in getting your hands dirty with Azure Log Analytics, here’s a few resources and tips on how to get started.

The Video’s

If you’re looking for some imagination of what Azure Log Analytics is all about and what you can do with it, here’s a couple of videos I recommend watching.

The Documentation

You can of course just go and try things out, but I strongly recommend to read through the documentation, there’s lots of useful information in there, furthermore it will most likely also provide you with some ideas how to do things differently.


If you’re totally new to Log Analytics, I recommend to first watch the videos. Next go to the Log Analytics Query language site and begin with the Getting Started tutorial.

What I find especially cool about this tutorial is that you can learn with real data. Microsoft provides access to a demo environment where you can try out all the query statements that then are processed against real data. You can access these workspaces directly using one of the below links.

Update! November 2020: Ido from the Microsoft Azure Log Analytics team contacted me and told me that the previous demo portals are about to be retired, therefore I have updated the links above. (thanks Ido to bring this up)

Or while going through the tutorial, when selecting “Run Query”.

Furthermore, I recommend to take a look at the query explorer, where you find a lot of example queries for the various solutions. If you have your own workspace, you can copy paste the queries from the demo environment and run them against your own data.

As an example, here are the security events from my devices I run at home.

As always, I hope you enjoyed reading, and hopefully this provided you with some ideas on how to get started with learning about Azure Log Analytics.

Leave a Reply