<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Log Analytics on sekureco42</title><link>https://sekureco42.ch/tags/log-analytics/</link><description>Recent content in Log Analytics on sekureco42</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>&amp;copy; 2025 rOger Eisenecher</copyright><lastBuildDate>Fri, 22 Nov 2024 16:34:12 +0100</lastBuildDate><atom:link href="https://sekureco42.ch/tags/log-analytics/index.xml" rel="self" type="application/rss+xml"/><item><title>Split log streams into Analytics and Auxiliary Table</title><link>https://sekureco42.ch/posts/auxiliary-logs/split-log-streams-into-analytics-and-auxiliary-table/</link><pubDate>Fri, 22 Nov 2024 16:34:12 +0100</pubDate><guid>https://sekureco42.ch/posts/auxiliary-logs/split-log-streams-into-analytics-and-auxiliary-table/</guid><description>&lt;p>In the last article we found out that KQL transformation at ingestion time is not available for Auxiliary Logs. But in real cases you want to have the ability to send selective log lines to Analytics while sending the rest to Auxiliary. In this article we will discover the possibilities.&lt;/p></description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://sekureco42.ch/posts/auxiliary-logs/split-log-streams-into-analytics-and-auxiliary-table/featured.png"/></item><item><title>Remap column names in Data Collection Rules (DCR)</title><link>https://sekureco42.ch/posts/auxiliary-logs/remap-column-names-in-data-collection-rule/</link><pubDate>Thu, 21 Nov 2024 07:46:12 +0100</pubDate><guid>https://sekureco42.ch/posts/auxiliary-logs/remap-column-names-in-data-collection-rule/</guid><description>&lt;p>In real world scenarios you have a data source with field names which are not identical to those in your table. Beside of renaming the fields in your agent which sending logs also Data Collection Rules provide the ability to map fields with &lt;code>transformkql&lt;/code>.&lt;/p></description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://sekureco42.ch/posts/auxiliary-logs/remap-column-names-in-data-collection-rule/featured.png"/></item><item><title>Auxiliary Logs in Azure Log Analytics</title><link>https://sekureco42.ch/posts/auxiliary-logs/azure-log-analytics-with-auxiliary-log-tables/</link><pubDate>Wed, 13 Nov 2024 17:29:12 +0100</pubDate><guid>https://sekureco42.ch/posts/auxiliary-logs/azure-log-analytics-with-auxiliary-log-tables/</guid><description>&lt;p>Microsoft provides a new type of Log Analytics tables called Auxiliary Logs. Currently this is in Public Preview and I did some lab testing which I documented in this blog post.&lt;/p></description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://sekureco42.ch/posts/auxiliary-logs/azure-log-analytics-with-auxiliary-log-tables/featured.png"/></item></channel></rss>