Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Azure Monitor Query SDK for Python. Use for querying Log Analytics workspaces and Azure Monitor metrics. Triggers: "azure-monitor-query", "LogsQueryClient", "MetricsQueryClient", "Log Analytics", "Kusto queries", "Azure metrics".
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 35% | 0% |
| case-02 | ✗→✓ | ▲ Improved | 64% | 0% |
| case-03 | ✗→✓ | ▲ Improved | 82% | 0% |
| case-10 | ✗→✓ | ▲ Improved | 41% | 0% |
| case-11 | ✗→✓ | ▲ Improved | 89% | 0% |
Query logs and metrics from Azure Monitor and Log Analytics workspaces.
bashpip install azure-monitor-query
bash# Log Analytics AZURE_LOG_ANALYTICS_WORKSPACE_ID=<workspace-id> # Required for log queries # Metrics AZURE_METRICS_RESOURCE_URI=/subscriptions/<sub>/resourceGroups/<rg>/providers/<provider>/<type>/<name> # Required for metric queries AZURE_TOKEN_CREDENTIALS=prod # Required only if DefaultAzureCredential is used in production
> 🔑 Two rules apply to every code sample below: > > 1. Prefer DefaultAzureCredential. It works locally (Azure CLI / VS Code / Developer CLI) and in Azure (managed identity, workload identity) with no code change. Avoid connection strings, account/API keys — they bypass Entra audit and rotation. > - Local dev: DefaultAzureCredential works as-is. > - Production: set AZURE_TOKEN_CREDENTIALS=prod (or AZURE_TOKEN_CREDENTIALS=<specific_credential>) to constrain the credential chain to production-safe credentials. > 2. Wrap every client in a context manager so HTTP transports, sockets, and token caches are released deterministically: > - Sync: with <Client>(...) as client: > - Async: async with <Client>(...) as client: and async with DefaultAzureCredential() as credential: (from azure.identity.aio) > > Snippets may abbreviate this setup, but production code should always follow both rules.
pythonfrom azure.identity import DefaultAzureCredential, ManagedIdentityCredential # Local dev: DefaultAzureCredential. Production: set AZURE_TOKEN_CREDENTIALS=prod or AZURE_TOKEN_CREDENTIALS=<specific_credential> credential = DefaultAzureCredential(require_envvar=True) # Or use a specific credential directly in production: # See https://learn.microsoft.com/python/api/overview/azure/identity-readme?view=azure-python#credential-classes # credential = ManagedIdentityCredential()
pythonfrom azure.monitor.query import LogsQueryClient from datetime import timedelta query = """ AppRequests | where TimeGenerated > ago(1h) | summarize count() by bin(TimeGenerated, 5m), ResultCode | order by TimeGenerated desc """ with LogsQueryClient(credential) as client: response = client.query_workspace( workspace_id=os.environ["AZURE_LOG_ANALYTICS_WORKSPACE_ID"], query=query, timespan=timedelta(hours=1) ) for table in response.tables: for row in table.rows: print(row)
pythonfrom datetime import datetime, timezone response = client.query_workspace( workspace_id=workspace_id, query="AppRequests | take 10", timespan=( datetime(2024, 1, 1, tzinfo=timezone.utc), datetime(2024, 1, 2, tzinfo=timezone.utc) ) )
pythonimport pandas as pd response = client.query_workspace(workspace_id, query, timespan=timedelta(hours=1)) if response.tables: table = response.tables[0] df = pd.DataFrame(data=table.rows, columns=[col.name for col in table.columns]) print(df.head())
pythonfrom azure.monitor.query import LogsBatchQuery queries = [ LogsBatchQuery(workspace_id=workspace_id, query="AppRequests | take 5", timespan=timedelta(hours=1)), LogsBatchQuery(workspace_id=workspace_id, query="AppExceptions | take 5", timespan=timedelta(hours=1)) ] responses = client.query_batch(queries) for response in responses: if response.tables: print(f"Rows: {len(response.tables[0].rows)}")
pythonfrom azure.monitor.query import LogsQueryStatus response = client.query_workspace(workspace_id, query, timespan=timedelta(hours=24)) if response.status == LogsQueryStatus.PARTIAL: print(f"Partial results: {response.partial_error}") elif response.status == LogsQueryStatus.FAILURE: print(f"Query failed: {response.partial_error}")
pythonfrom azure.monitor.query import MetricsQueryClient from datetime import timedelta with MetricsQueryClient(credential) as metrics_client: response = metrics_client.query_resource( resource_uri=os.environ["AZURE_METRICS_RESOURCE_URI"], metric_names=["Percentage CPU", "Network In Total"], timespan=timedelta(hours=1), granularity=timedelta(minutes=5) ) for metric in response.metrics: print(f"{metric.name}:") for time_series in metric.timeseries: for data in time_series.data: print(f" {data.timestamp}: {data.average}")
pythonfrom azure.monitor.query import MetricAggregationType response = metrics_client.query_resource( resource_uri=resource_uri, metric_names=["Requests"], timespan=timedelta(hours=1), aggregations=[ MetricAggregationType.AVERAGE, MetricAggregationType.MAXIMUM, MetricAggregationType.MINIMUM, MetricAggregationType.COUNT ] )
pythonresponse = metrics_client.query_resource( resource_uri=resource_uri, metric_names=["Requests"], timespan=timedelta(hours=1), filter="ApiName eq 'GetBlob'" )
pythondefinitions = metrics_client.list_metric_definitions(resource_uri) for definition in definitions: print(f"{definition.name}: {definition.unit}")
pythonnamespaces = metrics_client.list_metric_namespaces(resource_uri) for ns in namespaces: print(ns.fully_qualified_namespace)
pythonfrom azure.monitor.query.aio import LogsQueryClient, MetricsQueryClient from azure.identity.aio import DefaultAzureCredential async def query_logs(): async with DefaultAzureCredential() as credential: async with LogsQueryClient(credential) as client: response = await client.query_workspace( workspace_id=workspace_id, query="AppRequests | take 10", timespan=timedelta(hours=1) ) return response
kusto// Requests by status code AppRequests | summarize count() by ResultCode | order by count_ desc // Exceptions over time AppExceptions | summarize count() by bin(TimeGenerated, 1h) // Slow requests AppRequests | where DurationMs > 1000 | project TimeGenerated, Name, DurationMs | order by DurationMs desc // Top errors AppExceptions | summarize count() by ExceptionType | top 10 by count_
| Client | Purpose | |--------|---------| | LogsQueryClient | Query Log Analytics workspaces | | MetricsQueryClient | Query Azure Monitor metrics |
azure.xxx sync clients with azure.xxx.aio async clients in the same call path. Choose one mode per module.with Client(...) as client: (sync) or async with Client(...) as client: (async). For async DefaultAzureCredential from azure.identity.aio, also use async with credential: so tokens and transports are cleaned up.DefaultAzureCredential for portable auth across local dev and Azure (avoid connection strings / API keys when possible).| File | Contents | |------|----------| | references/capabilities.md | Additional non-hero capabilities, operation-group coverage, and production checklists. | | references/non-hero-scenarios.md | Dedicated non-hero examples for secondary/advanced scenarios. |
Other measured skills in the registry, with their headline benchmark lift.