Skip to main content
Glama
jometzg

MCP Log Analytics

by jometzg

MCP Server for Azure Log Analytics

A Model Context Protocol (MCP) server that exposes Azure Log Analytics workspace data, with specific support for AuditLogs and AzureActivity tables.

Features

  • Separate tools for querying AuditLogs and AzureActivity tables

  • Custom KQL queries with flexible filtering

  • Time range filters with human-readable format (24h, 7d, 30d)

  • Pagination support for large result sets

  • DefaultAzureCredential authentication (CLI, Managed Identity, Service Principal)

  • Docker support for containerized deployment

  • Comprehensive unit tests

Related MCP server: Azure Logs MCP

Prerequisites

  • Python 3.9+

  • Azure Log Analytics workspace

  • Azure CLI (for local development) or Managed Identity (for production)

Installation

  1. Clone the repository

  2. Create a virtual environment:

    python -m venv venv
  3. Activate the virtual environment:

    • Windows (PowerShell): venv\Scripts\Activate.ps1

    • Windows (cmd): venv\Scripts\activate.bat

    • Linux/Mac: source venv/bin/activate

  4. Install dependencies:

    pip install -r requirements.txt

Configuration

Set the following environment variables:

  • AZURE_LOG_ANALYTICS_WORKSPACE_ID (required): Your Log Analytics workspace ID

  • AZURE_TENANT_ID (optional): Azure tenant ID for service principal

  • AZURE_CLIENT_ID (optional): Service principal client ID

  • AZURE_CLIENT_SECRET (optional): Service principal client secret

Usage

The MCP server communicates via stdio and is designed to be used with MCP clients like VS Code (GitHub Copilot) or Claude Desktop.

Quick Start with VS Code (GitHub Copilot)

  1. Create or edit: %APPDATA%\Code\User\globalStorage\github.copilot\mcp-settings.json

    {
      "mcpServers": {
        "azure-log-analytics": {
          "command": "C:\\dev\\sre-agent\\mcp-log-analytics\\venv\\Scripts\\python.exe",
          "args": ["-m", "src.server"],
          "cwd": "C:\\dev\\sre-agent\\mcp-log-analytics",
          "env": {
            "AZURE_LOG_ANALYTICS_WORKSPACE_ID": "your-workspace-id"
          }
        }
      }
    }
  2. Restart VS Code

  3. Use Copilot Chat to query your logs:

    • @azure-log-analytics Show me audit logs from the last 24 hours

    • @azure-log-analytics Find failed operations in Azure Activity logs this week

For detailed VS Code setup and troubleshooting, see VSCODE-USAGE.md

Development

Install development dependencies:

pip install -r requirements-dev.txt

Run tests:

pytest

Docker

Build the image:

docker build -t mcp-log-analytics .

Run the container:

docker run -e AZURE_LOG_ANALYTICS_WORKSPACE_ID=<workspace-id> mcp-log-analytics

Documentation

License

MIT

F
license - not found
-
quality - not tested
D
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • -
    license
    -
    quality
    -
    maintenance
    Provides secure access to Microsoft Entra ID (Azure AD) resources including users, devices, and applications through Microsoft Graph API. Enables querying organizational data with comprehensive audit logging to Azure Blob Storage.
  • A
    license
    B
    quality
    D
    maintenance
    Enables querying Azure Application Insights logs by order number through natural language. Provides secure access to Azure Monitor logs with comprehensive error handling and rate limiting.
    1
    1
    MIT
  • F
    license
    -
    quality
    D
    maintenance
    Enables querying and managing Azure Log Analytics workspaces using KQL (Kusto Query Language). Supports executing queries, managing saved queries, and exploring workspace tables and schemas with Service Principal authentication.
  • A
    license
    -
    quality
    D
    maintenance
    Enables AI assistants to query and analyze data in Azure Data Explorer, Log Analytics, and Microsoft Sentinel using Kusto Query Language (KQL) through tools, resources, and prompts.
    5
    MIT

View all related MCP servers

Related MCP Connectors

  • A paid remote MCP for AI SDK data query MCP, built to return verdicts, receipts, usage logs, and aud

  • Read-only access to Auralogs production logs: search logs, inspect errors, review AI analyses.

  • Query Churn Solution cancellation-flow metrics, revenue, and feedback analytics (read-only).

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/jometzg/mcp-log-analytics'

If you have feedback or need assistance with the MCP directory API, please join our Discord server