Azure Observability Component Map

Last updated:

The Telemetry Pipeline

Azure observability telemetry pipeline Four kinds of telemetry source, each requiring a different collection mechanism, converging on a single Log Analytics workspace, with platform metrics drawn as a separate pipeline that bypasses the workspace entirely. SOURCES EACH NEEDS ITS OWN COLLECTOR WHERE IT LANDS WHAT READS IT Azure resources PaaS, network, vaults VMs, guest OS inside the machine Application code requests, traces Subscription control plane events Diagnostic Settings one per resource ✗ forget one, blind spot Monitor Agent no DCR means no data Application Insights sampling on by default ✗ counts read low Activity Log on by default, 90 days Storage account archive, indefinite Event Hub a buffer, not storage Log Analytics workspace queried with KQL 30d default 2y max retention Sentinel runs on the workspace Alert rules log and activity Action Groups email, webhook, runbook A SEPARATE PIPELINE · METRICS NEVER ENTER THE WORKSPACE Every resource emits metrics free Platform metrics 93 days, no ingestion cost Metric alerts near real time no setting, no agent, no cost both tracks end here telemetry flow requires metrics, a separate pipeline ✗ silent gap

Found this useful? Share it:

Share on LinkedIn