MCP Log Analytics
by jometzg
README.md
# MCP Server for Azure Log Analytics
A Model Context Protocol (MCP) server that exposes Azure Log Analytics workspace data, with specific support for AuditLogs and AzureActivity tables.
## Features
- **Separate tools** for querying AuditLogs and AzureActivity tables
- **Custom KQL queries** with flexible filtering
- **Time range filters** with human-readable format (24h, 7d, 30d)
- **Pagination support** for large result sets
- **DefaultAzureCredential** authentication (CLI, Managed Identity, Service Principal)
- **Docker support** for containerized deployment
- **Comprehensive unit tests**
## Prerequisites
- Python 3.9+
- Azure Log Analytics workspace
- Azure CLI (for local development) or Managed Identity (for production)
## Installation
1. Clone the repository
2. Create a virtual environment:
```bash
python -m venv venv
```
3. Activate the virtual environment:
- **Windows (PowerShell)**: `venv\Scripts\Activate.ps1`
- **Windows (cmd)**: `venv\Scripts\activate.bat`
- **Linux/Mac**: `source venv/bin/activate`
4. Install dependencies:
```bash
pip install -r requirements.txt
```
## Configuration
Set the following environment variables:
- `AZURE_LOG_ANALYTICS_WORKSPACE_ID` (required): Your Log Analytics workspace ID
- `AZURE_TENANT_ID` (optional): Azure tenant ID for service principal
- `AZURE_CLIENT_ID` (optional): Service principal client ID
- `AZURE_CLIENT_SECRET` (optional): Service principal client secret
## Usage
The MCP server communicates via stdio and is designed to be used with MCP clients like VS Code (GitHub Copilot) or Claude Desktop.
### Quick Start with VS Code (GitHub Copilot)
1. Create or edit: `%APPDATA%\Code\User\globalStorage\github.copilot\mcp-settings.json`
```json
{
"mcpServers": {
"azure-log-analytics": {
"command": "C:\\dev\\sre-agent\\mcp-log-analytics\\venv\\Scripts\\python.exe",
"args": ["-m", "src.server"],
"cwd": "C:\\dev\\sre-agent\\mcp-log-analytics",
"env": {
"AZURE_LOG_ANALYTICS_WORKSPACE_ID": "your-workspace-id"
}
}
}
}
```
2. Restart VS Code
3. Use Copilot Chat to query your logs:
- `@azure-log-analytics Show me audit logs from the last 24 hours`
- `@azure-log-analytics Find failed operations in Azure Activity logs this week`
**For detailed VS Code setup and troubleshooting, see [VSCODE-USAGE.md](VSCODE-USAGE.md)**
## Development
Install development dependencies:
```bash
pip install -r requirements-dev.txt
```
Run tests:
```bash
pytest
```
## Docker
Build the image:
```bash
docker build -t mcp-log-analytics .
```
Run the container:
```bash
docker run -e AZURE_LOG_ANALYTICS_WORKSPACE_ID=<workspace-id> mcp-log-analytics
```
## Documentation
- **[VSCODE-USAGE.md](VSCODE-USAGE.md)** - Complete VS Code & GitHub Copilot setup guide
- [DESIGN.md](DESIGN.md) - Architecture and design documentation
- [CONTRIBUTING.md](CONTRIBUTING.md) - Development and contribution guidelines
## License
MIT
This server cannot be deployed
Maintenance
ActivityInactive
ResponsivenessNo issues