Skip to main content
Glama
jometzg

MCP Log Analytics

by jometzg

MCP Server for Azure Log Analytics

A Model Context Protocol (MCP) server that exposes Azure Log Analytics workspace data, with specific support for AuditLogs and AzureActivity tables.

Features

  • Separate tools for querying AuditLogs and AzureActivity tables

  • Custom KQL queries with flexible filtering

  • Time range filters with human-readable format (24h, 7d, 30d)

  • Pagination support for large result sets

  • DefaultAzureCredential authentication (CLI, Managed Identity, Service Principal)

  • Docker support for containerized deployment

  • Comprehensive unit tests

Related MCP server: Azure Log Analytics MCP Server

Prerequisites

  • Python 3.9+

  • Azure Log Analytics workspace

  • Azure CLI (for local development) or Managed Identity (for production)

Installation

  1. Clone the repository

  2. Create a virtual environment:

    python -m venv venv
  3. Activate the virtual environment:

    • Windows (PowerShell): venv\Scripts\Activate.ps1

    • Windows (cmd): venv\Scripts\activate.bat

    • Linux/Mac: source venv/bin/activate

  4. Install dependencies:

    pip install -r requirements.txt

Configuration

Set the following environment variables:

  • AZURE_LOG_ANALYTICS_WORKSPACE_ID (required): Your Log Analytics workspace ID

  • AZURE_TENANT_ID (optional): Azure tenant ID for service principal

  • AZURE_CLIENT_ID (optional): Service principal client ID

  • AZURE_CLIENT_SECRET (optional): Service principal client secret

Usage

The MCP server communicates via stdio and is designed to be used with MCP clients like VS Code (GitHub Copilot) or Claude Desktop.

Quick Start with VS Code (GitHub Copilot)

  1. Create or edit: %APPDATA%\Code\User\globalStorage\github.copilot\mcp-settings.json

    {
      "mcpServers": {
        "azure-log-analytics": {
          "command": "C:\\dev\\sre-agent\\mcp-log-analytics\\venv\\Scripts\\python.exe",
          "args": ["-m", "src.server"],
          "cwd": "C:\\dev\\sre-agent\\mcp-log-analytics",
          "env": {
            "AZURE_LOG_ANALYTICS_WORKSPACE_ID": "your-workspace-id"
          }
        }
      }
    }
  2. Restart VS Code

  3. Use Copilot Chat to query your logs:

    • @azure-log-analytics Show me audit logs from the last 24 hours

    • @azure-log-analytics Find failed operations in Azure Activity logs this week

For detailed VS Code setup and troubleshooting, see VSCODE-USAGE.md

Development

Install development dependencies:

pip install -r requirements-dev.txt

Run tests:

pytest

Docker

Build the image:

docker build -t mcp-log-analytics .

Run the container:

docker run -e AZURE_LOG_ANALYTICS_WORKSPACE_ID=<workspace-id> mcp-log-analytics

Documentation

License

MIT

Related MCP Connectors

Related MCP Servers

  • -
    license
    Not graded
    quality
    Not graded
    maintenance
    Provides secure access to Microsoft Entra ID (Azure AD) resources including users, devices, and applications through Microsoft Graph API. Enables querying organizational data with comprehensive audit logging to Azure Blob Storage.
    -
  • F
    license
    Not graded
    quality
    D
    maintenance
    Enables querying and managing Azure Log Analytics workspaces using KQL (Kusto Query Language). Supports executing queries, managing saved queries, and exploring workspace tables and schemas with Service Principal authentication.
    -
  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables AI assistants to query and analyze data in Azure Data Explorer, Log Analytics, and Microsoft Sentinel using Kusto Query Language (KQL) through tools, resources, and prompts.
    5
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Enables read-only querying of Azure Log Analytics and Azure Resource Graph through MCP, supporting KQL queries, workspace discovery, and resource inventory exploration with Azure RBAC authentication.
    5
    2
    MIT