Skip to main content

Log Analytics Workspace

The centralized data store in Azure Monitor where log and telemetry data from multiple resources is collected, retained, and queried using KQL, serving as the backend for alerts, dashboards, and diagnostics.

Log Analytics Workspace

A Log Analytics Workspace is where all your log data actually lives — VMs, App Services, and other resources send their diagnostic logs here to be queried with KQL.

Why It Matters in Production

Razorpay routes diagnostic logs from every production resource into a single centralized Log Analytics Workspace, so a security incident spanning multiple services can be investigated with one KQL query instead of hopping between resource-specific log blades.

Bash
az monitor log-analytics workspace create \
--resource-group razorpay-prod-rg --workspace-name razorpay-prod-logs
Remember

Log Analytics pricing is based on data ingestion volume and retention period — set retention deliberately per table to control cost on high-volume logs.

Frequently Asked Questions

What actually gets stored in a Log Analytics Workspace, and how is it queried?

A workspace ingests structured log records — VM performance counters, Application Insights traces, Azure resource diagnostic logs, custom application logs — into tables within a single Log Analytics store. Every table is queried with KQL (Kusto Query Language), the same query engine used by Azure Sentinel and Application Insights. Retention is configurable per table, commonly 30-730 days, and data beyond that can be archived at lower cost rather than deleted.

What's a common workspace design mistake teams make in Azure Monitor?

Creating one workspace per subscription or per team without a retention/cost strategy is the most frequent mistake — ingestion and retention are billed per GB, and verbose diagnostic categories (like all NSG flow logs or full IIS logs) can silently balloon costs. A better pattern is consolidating workspaces per region or org boundary for correlation across resources, then using table-level retention overrides and the Basic Logs tier for high-volume, low-value data instead of one workspace-wide setting.