This repository contains a reusable Terraform / OpenTofu module and progressive examples for deploying Azure Log Analytics as a shared observability layer for Azure services and infrastructure patterns.
It is part of the FoggyKitchen.com training ecosystem and is designed to work cleanly with reusable Azure infrastructure modules such as terraform-az-fk-aks, terraform-az-fk-compute, terraform-az-fk-vnet, and service-specific modules.
Support expectations are documented in SUPPORT.md.
The goal of this module is to provide a clean, composable, and educational reference implementation for Azure Log Analytics:
- Focused on Log Analytics Workspace creation
- Suitable for AKS, Azure Firewall, App Service, Key Vault, Storage, ACR, Load Balancer, VM, and platform diagnostics patterns
- Designed for hands-on learning, module composition, and multicloud comparisons with logging modules in other clouds
This is not a full observability platform. It is a learning-first, architecture-aware building-block module.
The module creates:
- Azure Log Analytics Workspace
- Optional Log Analytics solutions, such as
ContainerInsights - Optional Azure Monitor Diagnostic Settings for any Azure resource that supports diagnostic export
The module intentionally does not create:
- AKS clusters, VMs, VNets, firewalls, storage accounts, or application workloads
- alert rules or action groups
- dashboards or workbooks
- Data Collection Rules for Azure Monitor Agent
- private networking for ingestion/query endpoints
Each of those concerns belongs in its own dedicated module or workflow layer.
terraform-az-fk-log-analytics/
├── examples/
│ ├── 01_workspace/
│ ├── 02_aks_with_container_insights/
│ ├── 03_compute_vm_diagnostics/
│ ├── 04_postgresql_diagnostics/
│ ├── 05_storage_blob_diagnostics/
│ └── README.md
├── main.tf
├── inputs.tf
├── outputs.tf
├── versions.tf
├── SUPPORT.md
├── LICENSE
└── README.mdAll examples demonstrate incremental Azure Log Analytics patterns, starting from a standalone workspace and progressing toward compute, database, and storage diagnostics.
module "log_analytics" {
source = "git::https://github.com/foggykitchen/terraform-az-fk-log-analytics.git?ref=v0.1.0"
name = "fk-law-dev"
location = "westeurope"
resource_group_name = "fk-observability-rg"
retention_in_days = 30
tags = {
project = "foggykitchen"
env = "dev"
}
}module "log_analytics" {
source = "git::https://github.com/foggykitchen/terraform-az-fk-log-analytics.git?ref=v0.1.0"
name = "fk-compute-law"
location = azurerm_resource_group.this.location
resource_group_name = azurerm_resource_group.this.name
diagnostic_settings = {
vm = {
target_resource_id = module.compute_vm.vm_id
metric_categories = ["AllMetrics"]
}
}
}For VM guest logs, use Azure Monitor Agent and Data Collection Rules. This module intentionally keeps that as a separate pattern and focuses on the shared workspace plus platform diagnostics.
module "log_analytics" {
source = "git::https://github.com/foggykitchen/terraform-az-fk-log-analytics.git?ref=v0.1.0"
name = "fk-pg-law"
location = azurerm_resource_group.this.location
resource_group_name = azurerm_resource_group.this.name
diagnostic_settings = {
postgresql = {
target_resource_id = module.postgresql.id
log_categories = ["PostgreSQLLogs"]
metric_categories = ["AllMetrics"]
}
}
}Diagnostic categories are service-specific. Use az monitor diagnostic-settings categories list --resource <resource-id> to inspect the supported categories for a given Azure resource.
module "log_analytics" {
source = "git::https://github.com/foggykitchen/terraform-az-fk-log-analytics.git?ref=v0.1.0"
name = "fk-storage-law"
location = azurerm_resource_group.this.location
resource_group_name = azurerm_resource_group.this.name
diagnostic_settings = {
storage_account = {
target_resource_id = module.storage.storage_account_id
metric_categories = ["Transaction"]
}
blob_service = {
target_resource_id = "${module.storage.storage_account_id}/blobServices/default"
log_categories = ["StorageRead", "StorageWrite", "StorageDelete"]
metric_categories = ["Transaction"]
}
}
}| Variable | Type | Required | Description |
|---|---|---|---|
name |
string |
yes | Name of the Log Analytics Workspace |
location |
string |
yes | Azure region, required when create_workspace = true |
resource_group_name |
string |
yes | Resource group name |
create_workspace |
bool |
no | Whether to create a new workspace or use an existing one |
workspace_id |
string |
no | Existing workspace resource ID when only adding diagnostics |
sku |
string |
no | Workspace SKU, default PerGB2018 |
retention_in_days |
number |
no | Workspace retention in days, default 30 |
daily_quota_gb |
number |
no | Daily ingestion quota in GB, default -1 |
internet_ingestion_enabled |
bool |
no | Whether public ingestion is enabled |
internet_query_enabled |
bool |
no | Whether public query is enabled |
reservation_capacity_in_gb_per_day |
number |
no | Capacity reservation level when supported by the SKU |
solutions |
map(object) |
no | Optional Log Analytics solutions |
diagnostic_settings |
map(object) |
no | Optional Diagnostic Settings for Azure resources |
tags |
map(string) |
no | Common tags |
solutions = map(object({
solution_name = string
publisher = optional(string, "Microsoft")
product = string
}))diagnostic_settings = map(object({
name = optional(string)
target_resource_id = string
log_categories = optional(set(string), [])
log_category_groups = optional(set(string), [])
metric_categories = optional(set(string), [])
log_analytics_destination_type = optional(string, "Dedicated")
}))Diagnostic categories are service-specific. Use az monitor diagnostic-settings categories list --resource <resource-id> to inspect categories for a given Azure resource.
| Output | Description |
|---|---|
id |
Log Analytics Workspace resource ID |
name |
Log Analytics Workspace name |
workspace_id |
Workspace/customer ID used by Azure Monitor integrations |
customer_id |
Alias for workspace_id |
primary_shared_key |
Primary shared key, sensitive |
secondary_shared_key |
Secondary shared key, sensitive |
resource_group_name |
Resource group containing the workspace |
retention_in_days |
Effective retention in days |
solution_ids |
Map of Log Analytics solution IDs |
diagnostic_setting_ids |
Map of Diagnostic Setting IDs |
This initial release is intentionally focused on the shared Log Analytics layer and Azure Monitor Diagnostic Settings.
That makes it a natural fit for:
- AKS control plane diagnostics and Container Insights composition
- Azure Firewall diagnostic categories
- Key Vault audit logs
- Storage account blob/file/queue/table diagnostics
- App Service and ACR diagnostic export
- VM platform metrics
- Storage account and Blob service logs and metrics
For VM guest logs, Azure Monitor Agent and Data Collection Rules are a distinct pattern and are not bundled into the first release.
Runnable examples are available in examples.
They show:
- a standalone Log Analytics Workspace
- AKS with Container Insights using
terraform-az-fk-vnetandterraform-az-fk-aks - compute VM platform diagnostics using
terraform-az-fk-vnetandterraform-az-fk-compute - PostgreSQL Flexible Server diagnostics using
terraform-az-fk-pg - Storage Account and Blob service diagnostics using
terraform-az-fk-vnetandterraform-az-fk-storage
This project is open source. Contributions are welcome through pull requests.
Licensed under the Universal Permissive License (UPL), Version 1.0. See LICENSE for details.
© 2026 FoggyKitchen.com - Cloud. Code. Clarity.