All Apps and Add-ons

Parsing fields from Azure Log Analytics KQL Grabber

Path Finder

Has anyone successfully parsed fields from the data gathered with Azure Log Analytics KQL Grabber?
We are working on pulling Log Analytics logs from Azure using KQL Grabber which works great for doing this. We are finding because KQL sends everything to the sourcetype KQL, we can't consistently parse fields out for our different inputs we have defined within KQL.

Labels (1)
0 Karma

Path Finder

In the latest version, you have the possibility to define sourcetype per stanza. I guess this can help you. 

As workaround you can always go to inputs.conf and hardcode the sourcetype there. That's general approach regardless the addon that you are using.

0 Karma