workspaces
Creates, updates, deletes, gets or lists a workspaces resource.
Overview
| Name | workspaces |
| Type | Resource |
| Id | azure.log_analytics.workspaces |
Fields
The following fields are returned by SELECT queries:
- get_nsp
- get
- list_by_resource_group
- list
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
networkSecurityPerimeter | object | Information about a network security perimeter (NSP). |
profile | object | :vartype profile: ~azure.mgmt.loganalytics.models.NetworkSecurityProfile |
provisioningIssues | array | List of provisioning issues, if any. |
provisioningState | string | Known values are: "Succeeded", "Creating", "Updating", "Deleting", "Accepted", "Failed", and "Canceled". (Succeeded, Creating, Updating, Deleting, Accepted, Failed, Canceled) |
resourceAssociation | object | :vartype resource_association: ~azure.mgmt.loganalytics.models.ResourceAssociation |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
createdDate | string (date-time) | Workspace creation date. |
customerId | string | This is a read-only property. Represents the ID associated with the workspace. |
defaultDataCollectionRuleResourceId | string | The resource ID of the default Data Collection Rule to use for this workspace. Expected format is - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Insights/dataCollectionRules/{dcrName}. |
etag | string | The etag of the workspace. |
failover | object | workspace failover properties. |
features | object | Workspace features. |
forceCmkForQuery | boolean | Indicates whether customer managed storage is mandatory for query management. |
identity | object | The identity of the resource. |
location | string | The geo-location where the resource lives. Required. |
modifiedDate | string (date-time) | Workspace modification date. |
privateLinkScopedResources | array | List of linked private link scope resources. |
provisioningState | string | The provisioning state of the workspace. Known values are: "Creating", "Succeeded", "Failed", "Canceled", "Deleting", "ProvisioningAccount", and "Updating". (Creating, Succeeded, Failed, Canceled, Deleting, ProvisioningAccount, Updating) |
publicNetworkAccessForIngestion | string | The network access type for accessing Log Analytics ingestion. Known values are: "Enabled", "Disabled", and "SecuredByPerimeter". (Enabled, Disabled, SecuredByPerimeter) |
publicNetworkAccessForQuery | string | The network access type for accessing Log Analytics query. Known values are: "Enabled", "Disabled", and "SecuredByPerimeter". (Enabled, Disabled, SecuredByPerimeter) |
replication | object | workspace replication properties. |
retentionInDays | integer | The workspace data retention in days. Allowed values are per pricing plan. See pricing tiers documentation for details. |
sku | object | The SKU of the workspace. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
tags | object | Resource tags. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
workspaceCapping | object | The daily volume cap for ingestion. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
createdDate | string (date-time) | Workspace creation date. |
customerId | string | This is a read-only property. Represents the ID associated with the workspace. |
defaultDataCollectionRuleResourceId | string | The resource ID of the default Data Collection Rule to use for this workspace. Expected format is - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Insights/dataCollectionRules/{dcrName}. |
etag | string | The etag of the workspace. |
failover | object | workspace failover properties. |
features | object | Workspace features. |
forceCmkForQuery | boolean | Indicates whether customer managed storage is mandatory for query management. |
identity | object | The identity of the resource. |
location | string | The geo-location where the resource lives. Required. |
modifiedDate | string (date-time) | Workspace modification date. |
privateLinkScopedResources | array | List of linked private link scope resources. |
provisioningState | string | The provisioning state of the workspace. Known values are: "Creating", "Succeeded", "Failed", "Canceled", "Deleting", "ProvisioningAccount", and "Updating". (Creating, Succeeded, Failed, Canceled, Deleting, ProvisioningAccount, Updating) |
publicNetworkAccessForIngestion | string | The network access type for accessing Log Analytics ingestion. Known values are: "Enabled", "Disabled", and "SecuredByPerimeter". (Enabled, Disabled, SecuredByPerimeter) |
publicNetworkAccessForQuery | string | The network access type for accessing Log Analytics query. Known values are: "Enabled", "Disabled", and "SecuredByPerimeter". (Enabled, Disabled, SecuredByPerimeter) |
replication | object | workspace replication properties. |
retentionInDays | integer | The workspace data retention in days. Allowed values are per pricing plan. See pricing tiers documentation for details. |
sku | object | The SKU of the workspace. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
tags | object | Resource tags. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
workspaceCapping | object | The daily volume cap for ingestion. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
createdDate | string (date-time) | Workspace creation date. |
customerId | string | This is a read-only property. Represents the ID associated with the workspace. |
defaultDataCollectionRuleResourceId | string | The resource ID of the default Data Collection Rule to use for this workspace. Expected format is - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Insights/dataCollectionRules/{dcrName}. |
etag | string | The etag of the workspace. |
failover | object | workspace failover properties. |
features | object | Workspace features. |
forceCmkForQuery | boolean | Indicates whether customer managed storage is mandatory for query management. |
identity | object | The identity of the resource. |
location | string | The geo-location where the resource lives. Required. |
modifiedDate | string (date-time) | Workspace modification date. |
privateLinkScopedResources | array | List of linked private link scope resources. |
provisioningState | string | The provisioning state of the workspace. Known values are: "Creating", "Succeeded", "Failed", "Canceled", "Deleting", "ProvisioningAccount", and "Updating". (Creating, Succeeded, Failed, Canceled, Deleting, ProvisioningAccount, Updating) |
publicNetworkAccessForIngestion | string | The network access type for accessing Log Analytics ingestion. Known values are: "Enabled", "Disabled", and "SecuredByPerimeter". (Enabled, Disabled, SecuredByPerimeter) |
publicNetworkAccessForQuery | string | The network access type for accessing Log Analytics query. Known values are: "Enabled", "Disabled", and "SecuredByPerimeter". (Enabled, Disabled, SecuredByPerimeter) |
replication | object | workspace replication properties. |
retentionInDays | integer | The workspace data retention in days. Allowed values are per pricing plan. See pricing tiers documentation for details. |
sku | object | The SKU of the workspace. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
tags | object | Resource tags. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
workspaceCapping | object | The daily volume cap for ingestion. |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get_nsp | select | resource_group_name, workspace_name, network_security_perimeter_configuration_name, subscription_id | Gets a network security perimeter configuration. | |
get | select | resource_group_name, workspace_name, subscription_id | Gets a workspace instance. | |
list_by_resource_group | select | resource_group_name, subscription_id | Gets workspaces in a resource group. | |
list | select | subscription_id | Gets the workspaces in a subscription. | |
create_or_update | insert | resource_group_name, workspace_name, subscription_id, location | Create or update a workspace. | |
update | update | resource_group_name, workspace_name, subscription_id | Updates a workspace. | |
create_or_update | replace | resource_group_name, workspace_name, subscription_id, location | Create or update a workspace. | |
delete | delete | resource_group_name, workspace_name, subscription_id | force | Deletes a workspace resource. To recover the workspace, create it again with the same name, in the same subscription, resource group and location. The name is kept for 14 days and cannot be used for another workspace. To remove the workspace completely and release the name, use the force flag. |
list_nsp | exec | resource_group_name, workspace_name, subscription_id | Gets a list of NSP configurations for specified workspace. | |
failback | exec | resource_group_name, workspace_name, subscription_id | Deactivates failover for the specified workspace. The failback operation is asynchronous and can take up to 30 minutes to complete. The status of the operation can be checked using the operationId returned in the response. | |
reconcile_nsp | exec | resource_group_name, workspace_name, network_security_perimeter_configuration_name, subscription_id | Reconcile network security perimeter configuration for Workspace resource. | |
failover | exec | resource_group_name, location, workspace_name, subscription_id | Activates failover for the specified workspace. The specified replication location must match the location of the enabled replication for this workspace. The failover operation is asynchronous and can take up to 30 minutes to complete. The status of the operation can be checked using the operationId returned in the response. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
location | string | The location name. Required. |
network_security_perimeter_configuration_name | string | The name for a network security perimeter configuration. Required. |
resource_group_name | string | The name of the resource group. The name is case insensitive. Required. |
subscription_id | string | |
workspace_name | string | The name of the workspace. Required. |
force | boolean | Deletes the workspace without the recovery option. A workspace that was deleted with this flag cannot be recovered. Default value is None. |
SELECT examples
- get_nsp
- get
- list_by_resource_group
- list
Gets a network security perimeter configuration.
SELECT
id,
name,
networkSecurityPerimeter,
profile,
provisioningIssues,
provisioningState,
resourceAssociation,
systemData,
type
FROM azure.log_analytics.workspaces
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND workspace_name = '{{ workspace_name }}' -- required
AND network_security_perimeter_configuration_name = '{{ network_security_perimeter_configuration_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
;
Gets a workspace instance.
SELECT
id,
name,
createdDate,
customerId,
defaultDataCollectionRuleResourceId,
etag,
failover,
features,
forceCmkForQuery,
identity,
location,
modifiedDate,
privateLinkScopedResources,
provisioningState,
publicNetworkAccessForIngestion,
publicNetworkAccessForQuery,
replication,
retentionInDays,
sku,
systemData,
tags,
type,
workspaceCapping
FROM azure.log_analytics.workspaces
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND workspace_name = '{{ workspace_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
;
Gets workspaces in a resource group.
SELECT
id,
name,
createdDate,
customerId,
defaultDataCollectionRuleResourceId,
etag,
failover,
features,
forceCmkForQuery,
identity,
location,
modifiedDate,
privateLinkScopedResources,
provisioningState,
publicNetworkAccessForIngestion,
publicNetworkAccessForQuery,
replication,
retentionInDays,
sku,
systemData,
tags,
type,
workspaceCapping
FROM azure.log_analytics.workspaces
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
;
Gets the workspaces in a subscription.
SELECT
id,
name,
createdDate,
customerId,
defaultDataCollectionRuleResourceId,
etag,
failover,
features,
forceCmkForQuery,
identity,
location,
modifiedDate,
privateLinkScopedResources,
provisioningState,
publicNetworkAccessForIngestion,
publicNetworkAccessForQuery,
replication,
retentionInDays,
sku,
systemData,
tags,
type,
workspaceCapping
FROM azure.log_analytics.workspaces
WHERE subscription_id = '{{ subscription_id }}' -- required
;
INSERT examples
- create_or_update
- Manifest
Create or update a workspace.
INSERT INTO azure.log_analytics.workspaces (
tags,
location,
properties,
identity,
etag,
resource_group_name,
workspace_name,
subscription_id
)
SELECT
'{{ tags }}',
'{{ location }}' /* required */,
'{{ properties }}',
'{{ identity }}',
'{{ etag }}',
'{{ resource_group_name }}',
'{{ workspace_name }}',
'{{ subscription_id }}'
RETURNING
id,
name,
etag,
identity,
location,
properties,
systemData,
tags,
type
;
# Description fields are for documentation purposes
- name: workspaces
props:
- name: resource_group_name
value: "{{ resource_group_name }}"
description: Required parameter for the workspaces resource.
- name: workspace_name
value: "{{ workspace_name }}"
description: Required parameter for the workspaces resource.
- name: subscription_id
value: "{{ subscription_id }}"
description: Required parameter for the workspaces resource.
- name: tags
value: "{{ tags }}"
description: |
Resource tags.
- name: location
value: "{{ location }}"
description: |
The geo-location where the resource lives. Required.
- name: properties
description: |
Workspace properties.
value:
provisioningState: "{{ provisioningState }}"
customerId: "{{ customerId }}"
sku:
name: "{{ name }}"
capacityReservationLevel: {{ capacityReservationLevel }}
lastSkuUpdate: "{{ lastSkuUpdate }}"
retentionInDays: {{ retentionInDays }}
workspaceCapping:
dailyQuotaGb: {{ dailyQuotaGb }}
quotaNextResetTime: "{{ quotaNextResetTime }}"
dataIngestionStatus: "{{ dataIngestionStatus }}"
createdDate: "{{ createdDate }}"
modifiedDate: "{{ modifiedDate }}"
publicNetworkAccessForIngestion: "{{ publicNetworkAccessForIngestion }}"
publicNetworkAccessForQuery: "{{ publicNetworkAccessForQuery }}"
forceCmkForQuery: {{ forceCmkForQuery }}
privateLinkScopedResources:
- resourceId: "{{ resourceId }}"
scopeId: "{{ scopeId }}"
features:
enableDataExport: {{ enableDataExport }}
immediatePurgeDataOn30Days: {{ immediatePurgeDataOn30Days }}
enableLogAccessUsingOnlyResourcePermissions: {{ enableLogAccessUsingOnlyResourcePermissions }}
clusterResourceId: "{{ clusterResourceId }}"
disableLocalAuth: {{ disableLocalAuth }}
unifiedSentinelBillingOnly: {{ unifiedSentinelBillingOnly }}
associations:
- "{{ associations }}"
defaultDataCollectionRuleResourceId: "{{ defaultDataCollectionRuleResourceId }}"
replication:
location: "{{ location }}"
enabled: {{ enabled }}
provisioningState: "{{ provisioningState }}"
createdDate: "{{ createdDate }}"
lastModifiedDate: "{{ lastModifiedDate }}"
failover:
state: "{{ state }}"
lastModifiedDate: "{{ lastModifiedDate }}"
- name: identity
description: |
The identity of the resource.
value:
principalId: "{{ principalId }}"
tenantId: "{{ tenantId }}"
type: "{{ type }}"
userAssignedIdentities: "{{ userAssignedIdentities }}"
- name: etag
value: "{{ etag }}"
description: |
The etag of the workspace.
UPDATE examples
- update
Updates a workspace.
UPDATE azure.log_analytics.workspaces
SET
properties = '{{ properties }}',
identity = '{{ identity }}',
tags = '{{ tags }}'
WHERE
resource_group_name = '{{ resource_group_name }}' --required
AND workspace_name = '{{ workspace_name }}' --required
AND subscription_id = '{{ subscription_id }}' --required
RETURNING
id,
name,
etag,
identity,
location,
properties,
systemData,
tags,
type;
REPLACE examples
- create_or_update
Create or update a workspace.
REPLACE azure.log_analytics.workspaces
SET
tags = '{{ tags }}',
location = '{{ location }}',
properties = '{{ properties }}',
identity = '{{ identity }}',
etag = '{{ etag }}'
WHERE
resource_group_name = '{{ resource_group_name }}' --required
AND workspace_name = '{{ workspace_name }}' --required
AND subscription_id = '{{ subscription_id }}' --required
AND location = '{{ location }}' --required
RETURNING
id,
name,
etag,
identity,
location,
properties,
systemData,
tags,
type;
DELETE examples
- delete
Deletes a workspace resource. To recover the workspace, create it again with the same name, in the same subscription, resource group and location. The name is kept for 14 days and cannot be used for another workspace. To remove the workspace completely and release the name, use the force flag.
DELETE FROM azure.log_analytics.workspaces
WHERE resource_group_name = '{{ resource_group_name }}' --required
AND workspace_name = '{{ workspace_name }}' --required
AND subscription_id = '{{ subscription_id }}' --required
AND force = '{{ force }}'
;
Lifecycle Methods
- list_nsp
- failback
- reconcile_nsp
- failover
Gets a list of NSP configurations for specified workspace.
EXEC azure.log_analytics.workspaces.list_nsp
@resource_group_name='{{ resource_group_name }}' --required,
@workspace_name='{{ workspace_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
;
Deactivates failover for the specified workspace. The failback operation is asynchronous and can take up to 30 minutes to complete. The status of the operation can be checked using the operationId returned in the response.
EXEC azure.log_analytics.workspaces.failback
@resource_group_name='{{ resource_group_name }}' --required,
@workspace_name='{{ workspace_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
;
Reconcile network security perimeter configuration for Workspace resource.
EXEC azure.log_analytics.workspaces.reconcile_nsp
@resource_group_name='{{ resource_group_name }}' --required,
@workspace_name='{{ workspace_name }}' --required,
@network_security_perimeter_configuration_name='{{ network_security_perimeter_configuration_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
;
Activates failover for the specified workspace. The specified replication location must match the location of the enabled replication for this workspace. The failover operation is asynchronous and can take up to 30 minutes to complete. The status of the operation can be checked using the operationId returned in the response.
EXEC azure.log_analytics.workspaces.failover
@resource_group_name='{{ resource_group_name }}' --required,
@location='{{ location }}' --required,
@workspace_name='{{ workspace_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
;