Very low footprint Loganalytics provider for logspout
1.9K
This repository provides an Azure IoT Edge module that can be used to send container logs from other modules on the edge device, including the edge runtime, securely to Azure Log Analytics in the cloud. With minimal changes to the edge deployment, logs from multiple edge devices can be directed to a single log analytics workspace. This allows you to get a consolidated view of logs from all your edge devices which can be analyzed using a powerful search mechanism to discern operational patterns or debug failures.
This module leverages gliderlabs/logspout project, for which it provides a custom loganalytics adapter that sends container logs obtained by logspout to Azure Log Analytics service. Log analytics credential and logging options can be specified in the module configuration from IoT hub.

You'll need to create a log analytics workspace, configure the log module in IoT hub with required settings and you should be good to go!
Follow the Log Analytics documentation to create a workspace and obtain the workspace ID and key. Take note of the workspace ID and key as they are required in the next step.
Next, we'll deploy an IoT edge module for logging.
Here are the values and steps for logging module creation:
logspoutkbeaugrand/logspout-loganalytics for platforms listed above.{
"Env": [
"BACKLOG=false",
"LOGSPOUT=ignore",
"LOGANALYTICS_WORKSPACE_ID=<replace-with-loganalytics-workspace-id>",
"LOGANALYTICS_WORKSPACE_SECRET=<replace-with-workspace-key>"
],
"Cmd": [
"loganalytics://"
],
"HostConfig": {
"Binds": [
"/var/run/docker.sock:/var/run/docker.sock"
]
}
}
Thats it! You don't have to change any configuration for other modules or install any services or agents on the edge device to start pushing module logs to the cloud. The logspout-loganalytics module is self-contained.
Logs emitted on the device usually show up in log analytics portal in 5 minutes.
Navigate to the Log search / Advanced analytics portal to search or query logs from your edge devices. Advanced analytics portal is more user friendly.
Enter the following search query to view logs from all devices sorted by time generated.
search *
| project TimeGenerated, Level, msg_s, moduleName_s, iothubdeviceid_s, hostname_s, iothubname_s
| sort by TimeGenerated desc nulls last
Here is a sample screenshot of the output:

Checkout the sample queries page.
See the FAQ page.
If the time on the edge device is out of sync it fails to establish a secure TLS connection with Log analytics endpoint. Consider using NTP daemon to keep the time on the device synchronized (especially when testing in a VM).
The Advanced analytics portal only works when opened from the Log search pane inside the Azure Portal. If it times out, close the Advanced analytics portal and re-open from Log search pane. Sometimes this shows a 403 Forbidden error code. Clicking the Try Again link helps fix the issue (sometimes).

Content type
Image
Digest
Size
5.9 MB
Last updated
over 6 years ago
docker pull kbeaugrand/logspout-loganalytics