---
title: Query Azure Monitor logs
source: https://docs.newrelic.com/docs/workflow-automation/setup-and-configure/actions-catalog/azure/azure-monitor-querylogs
---

The Azure Monitor Query Logs action runs a [KQL (Kusto Query Language)](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/get-started-queries?tabs=kql) query against an Azure Monitor Log Analytics workspace and returns the result table to your workflow.

## Query Azure Monitor logs [#azure-monitor-querylogs]

Use this action to query log data — for example, application requests, failures, or custom logs — and then branch or notify based on the results.

> #### ⚠️ IMPORTANT
>
> The Azure AD service principal you use must have the **Log Analytics Reader** role on the target workspace.

### Inputs

The following inputs are available for this action:

| Input          | Type   | Description                                                                                                                                                                                                               |
| -------------- | ------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `clientId`     | String | **Required.** An Azure Service Principal clientId (UUID format). Pass as a secret. See how to [register an Azure app.](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/api/register-app-for-token?tabs=portal) |
| `clientSecret` | String | **Required.** An Azure Service Principal clientSecret. Pass as a secret. See how to [register an Azure app.](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/api/register-app-for-token?tabs=portal)           |
| `tenantId`     | String | **Required.** The Azure tenant identifier (UUID format). Can be passed as a secret.                                                                                                                                       |
| `workspaceId`  | String | **Required.** The Log Analytics workspace ID (GUID). For example, `"78460d46-1c7c-494b-90b4-e21288a074d4"`.                                                                                                               |
| `query`        | String | **Required.** The KQL query to run against the workspace. For example, `"AppRequests | take 10"`. Maximum 8000 characters.                                                                                                |
| `timespan`     | String | **Optional.** An ISO-8601 duration that bounds the query time range. For example, `"P7D"` (7 days) or `"PT1H"` (1 hour). When omitted, the query runs without a time constraint.                                          |
| `selectors`    | List   | **Optional.** A list of selectors used to extract or rename specific values from the response. For example, `[{"name": "records", "expression": ".response.tables[0].rows"}]`.                                            |

### Outputs

The following outputs are available for this action:

| Output         | Type    | Description                                                                                                                                                                                                                                                                                |
| -------------- | ------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `success`      | Boolean | Query result status. `true` when the call succeeded (HTTP 2xx). `false` otherwise.                                                                                                                                                                                                         |
| `errorMessage` | String  | Failure reason. The action sets this field when `success` is `false`.                                                                                                                                                                                                                      |
| `response`     | Object  | The full Log Analytics response. Result rows are at `response.tables[0].rows`. Column definitions are at `response.tables[0].columns`. For more information, see the [Azure Monitor Log Analytics API reference](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/api/overview). |

### Example

The following example queries the `AppRequests` table for the last 25 days and sends a summary to a Slack channel.

````yaml
name: query-azure-monitor-logs

steps:
  - name: query_app_requests
    type: action
    action: azure.monitor.queryLogs
    version: 1
    inputs:
      clientId: ${{ :secrets:azure-client-id }}
      clientSecret: ${{ :secrets:azure-client-secret }}
      tenantId: ${{ :secrets:azure-tenant-id }}
      workspaceId: "78460d46-1c7c-494b-90b4-e21288a074d4"
      query: |-
        AppRequests
        | take 10
      timespan: P25D
      selectors:
        - name: records
          expression: ".response.tables[0] as $t | ($t.columns | map(.name)) as $cols | $t.rows | map(. as $row | reduce range(0; ($cols | length)) as $i ({}; . + {($cols[$i]): $row[$i]}))"
  - name: send_slack_notification
    type: action
    action: newrelic.notification.sendSlack
    version: 1
    inputs:
      destinationId: ${{ :secrets:slack-destination-id }}
      channel: ops-alerts
      text: ${{ "*AppRequests* (" + (.steps.query_app_requests.outputs.records | length | tostring) + " rows)\n```\n" + (.steps.query_app_requests.outputs.records | map([(.OperationName // ""), (.ResultCode // ""), (.Url // ""), ((.DurationMs // 0) | tostring) + "ms"] | join(" | ")) | join("\n")) + "\n```" }}
    next: end
````
