MCP Log Analytics
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@MCP Log AnalyticsShow me audit logs from the last 24 hours"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
MCP Server for Azure Log Analytics
A Model Context Protocol (MCP) server that exposes Azure Log Analytics workspace data, with specific support for AuditLogs and AzureActivity tables.
Features
Separate tools for querying AuditLogs and AzureActivity tables
Custom KQL queries with flexible filtering
Time range filters with human-readable format (24h, 7d, 30d)
Pagination support for large result sets
DefaultAzureCredential authentication (CLI, Managed Identity, Service Principal)
Docker support for containerized deployment
Comprehensive unit tests
Related MCP server: Azure Logs MCP
Prerequisites
Python 3.9+
Azure Log Analytics workspace
Azure CLI (for local development) or Managed Identity (for production)
Installation
Clone the repository
Create a virtual environment:
python -m venv venvActivate the virtual environment:
Windows (PowerShell):
venv\Scripts\Activate.ps1Windows (cmd):
venv\Scripts\activate.batLinux/Mac:
source venv/bin/activate
Install dependencies:
pip install -r requirements.txt
Configuration
Set the following environment variables:
AZURE_LOG_ANALYTICS_WORKSPACE_ID(required): Your Log Analytics workspace IDAZURE_TENANT_ID(optional): Azure tenant ID for service principalAZURE_CLIENT_ID(optional): Service principal client IDAZURE_CLIENT_SECRET(optional): Service principal client secret
Usage
The MCP server communicates via stdio and is designed to be used with MCP clients like VS Code (GitHub Copilot) or Claude Desktop.
Quick Start with VS Code (GitHub Copilot)
Create or edit:
%APPDATA%\Code\User\globalStorage\github.copilot\mcp-settings.json{ "mcpServers": { "azure-log-analytics": { "command": "C:\\dev\\sre-agent\\mcp-log-analytics\\venv\\Scripts\\python.exe", "args": ["-m", "src.server"], "cwd": "C:\\dev\\sre-agent\\mcp-log-analytics", "env": { "AZURE_LOG_ANALYTICS_WORKSPACE_ID": "your-workspace-id" } } } }Restart VS Code
Use Copilot Chat to query your logs:
@azure-log-analytics Show me audit logs from the last 24 hours@azure-log-analytics Find failed operations in Azure Activity logs this week
For detailed VS Code setup and troubleshooting, see VSCODE-USAGE.md
Development
Install development dependencies:
pip install -r requirements-dev.txtRun tests:
pytestDocker
Build the image:
docker build -t mcp-log-analytics .Run the container:
docker run -e AZURE_LOG_ANALYTICS_WORKSPACE_ID=<workspace-id> mcp-log-analyticsDocumentation
VSCODE-USAGE.md - Complete VS Code & GitHub Copilot setup guide
DESIGN.md - Architecture and design documentation
CONTRIBUTING.md - Development and contribution guidelines
License
MIT
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- -license-quality-maintenanceProvides secure access to Microsoft Entra ID (Azure AD) resources including users, devices, and applications through Microsoft Graph API. Enables querying organizational data with comprehensive audit logging to Azure Blob Storage.
- AlicenseBqualityDmaintenanceEnables querying Azure Application Insights logs by order number through natural language. Provides secure access to Azure Monitor logs with comprehensive error handling and rate limiting.11MIT
- Flicense-qualityDmaintenanceEnables querying and managing Azure Log Analytics workspaces using KQL (Kusto Query Language). Supports executing queries, managing saved queries, and exploring workspace tables and schemas with Service Principal authentication.
- Alicense-qualityDmaintenanceEnables AI assistants to query and analyze data in Azure Data Explorer, Log Analytics, and Microsoft Sentinel using Kusto Query Language (KQL) through tools, resources, and prompts.5MIT
Related MCP Connectors
A paid remote MCP for AI SDK data query MCP, built to return verdicts, receipts, usage logs, and aud
Read-only access to Auralogs production logs: search logs, inspect errors, review AI analyses.
Query Churn Solution cancellation-flow metrics, revenue, and feedback analytics (read-only).
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/jometzg/mcp-log-analytics'
If you have feedback or need assistance with the MCP directory API, please join our Discord server