Skip to content

Latest commit

 

History

4 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

terraform-az-fk-log-analytics

This repository contains a reusable Terraform / OpenTofu module and progressive examples for deploying Azure Log Analytics as a shared observability layer for Azure services and infrastructure patterns.

It is part of the FoggyKitchen.com training ecosystem and is designed to work cleanly with reusable Azure infrastructure modules such as terraform-az-fk-aks, terraform-az-fk-compute, terraform-az-fk-vnet, and service-specific modules.

Support expectations are documented in SUPPORT.md.


Purpose

The goal of this module is to provide a clean, composable, and educational reference implementation for Azure Log Analytics:

  • Focused on Log Analytics Workspace creation
  • Suitable for AKS, Azure Firewall, App Service, Key Vault, Storage, ACR, Load Balancer, VM, and platform diagnostics patterns
  • Designed for hands-on learning, module composition, and multicloud comparisons with logging modules in other clouds

This is not a full observability platform. It is a learning-first, architecture-aware building-block module.


What the module does

The module creates:

  • Azure Log Analytics Workspace
  • Optional Log Analytics solutions, such as ContainerInsights
  • Optional Azure Monitor Diagnostic Settings for any Azure resource that supports diagnostic export

The module intentionally does not create:

  • AKS clusters, VMs, VNets, firewalls, storage accounts, or application workloads
  • alert rules or action groups
  • dashboards or workbooks
  • Data Collection Rules for Azure Monitor Agent
  • private networking for ingestion/query endpoints

Each of those concerns belongs in its own dedicated module or workflow layer.


Repository Structure

terraform-az-fk-log-analytics/
├── examples/
│   ├── 01_workspace/
│   ├── 02_aks_with_container_insights/
│   ├── 03_compute_vm_diagnostics/
│   ├── 04_postgresql_diagnostics/
│   ├── 05_storage_blob_diagnostics/
│   └── README.md
├── main.tf
├── inputs.tf
├── outputs.tf
├── versions.tf
├── SUPPORT.md
├── LICENSE
└── README.md

All examples demonstrate incremental Azure Log Analytics patterns, starting from a standalone workspace and progressing toward compute, database, and storage diagnostics.


Example Usage

Basic workspace

module "log_analytics" {
  source = "git::https://github.com/foggykitchen/terraform-az-fk-log-analytics.git?ref=v0.1.0"

  name                = "fk-law-dev"
  location            = "westeurope"
  resource_group_name = "fk-observability-rg"

  retention_in_days = 30

  tags = {
    project = "foggykitchen"
    env     = "dev"
  }
}

Compute VM metrics to Log Analytics

module "log_analytics" {
  source = "git::https://github.com/foggykitchen/terraform-az-fk-log-analytics.git?ref=v0.1.0"

  name                = "fk-compute-law"
  location            = azurerm_resource_group.this.location
  resource_group_name = azurerm_resource_group.this.name

  diagnostic_settings = {
    vm = {
      target_resource_id = module.compute_vm.vm_id
      metric_categories  = ["AllMetrics"]
    }
  }
}

For VM guest logs, use Azure Monitor Agent and Data Collection Rules. This module intentionally keeps that as a separate pattern and focuses on the shared workspace plus platform diagnostics.

PostgreSQL Flexible Server logs to Log Analytics

module "log_analytics" {
  source = "git::https://github.com/foggykitchen/terraform-az-fk-log-analytics.git?ref=v0.1.0"

  name                = "fk-pg-law"
  location            = azurerm_resource_group.this.location
  resource_group_name = azurerm_resource_group.this.name

  diagnostic_settings = {
    postgresql = {
      target_resource_id = module.postgresql.id
      log_categories     = ["PostgreSQLLogs"]
      metric_categories  = ["AllMetrics"]
    }
  }
}

Diagnostic categories are service-specific. Use az monitor diagnostic-settings categories list --resource <resource-id> to inspect the supported categories for a given Azure resource.

Storage Blob diagnostics to Log Analytics

module "log_analytics" {
  source = "git::https://github.com/foggykitchen/terraform-az-fk-log-analytics.git?ref=v0.1.0"

  name                = "fk-storage-law"
  location            = azurerm_resource_group.this.location
  resource_group_name = azurerm_resource_group.this.name

  diagnostic_settings = {
    storage_account = {
      target_resource_id = module.storage.storage_account_id
      metric_categories  = ["Transaction"]
    }

    blob_service = {
      target_resource_id = "${module.storage.storage_account_id}/blobServices/default"
      log_categories     = ["StorageRead", "StorageWrite", "StorageDelete"]
      metric_categories  = ["Transaction"]
    }
  }
}

Module Inputs

Core inputs

Variable Type Required Description
name string yes Name of the Log Analytics Workspace
location string yes Azure region, required when create_workspace = true
resource_group_name string yes Resource group name
create_workspace bool no Whether to create a new workspace or use an existing one
workspace_id string no Existing workspace resource ID when only adding diagnostics
sku string no Workspace SKU, default PerGB2018
retention_in_days number no Workspace retention in days, default 30
daily_quota_gb number no Daily ingestion quota in GB, default -1
internet_ingestion_enabled bool no Whether public ingestion is enabled
internet_query_enabled bool no Whether public query is enabled
reservation_capacity_in_gb_per_day number no Capacity reservation level when supported by the SKU
solutions map(object) no Optional Log Analytics solutions
diagnostic_settings map(object) no Optional Diagnostic Settings for Azure resources
tags map(string) no Common tags

solutions object schema

solutions = map(object({
  solution_name = string
  publisher     = optional(string, "Microsoft")
  product       = string
}))

diagnostic_settings object schema

diagnostic_settings = map(object({
  name                           = optional(string)
  target_resource_id             = string
  log_categories                 = optional(set(string), [])
  log_category_groups            = optional(set(string), [])
  metric_categories              = optional(set(string), [])
  log_analytics_destination_type = optional(string, "Dedicated")
}))

Diagnostic categories are service-specific. Use az monitor diagnostic-settings categories list --resource <resource-id> to inspect categories for a given Azure resource.


Module Outputs

Output Description
id Log Analytics Workspace resource ID
name Log Analytics Workspace name
workspace_id Workspace/customer ID used by Azure Monitor integrations
customer_id Alias for workspace_id
primary_shared_key Primary shared key, sensitive
secondary_shared_key Secondary shared key, sensitive
resource_group_name Resource group containing the workspace
retention_in_days Effective retention in days
solution_ids Map of Log Analytics solution IDs
diagnostic_setting_ids Map of Diagnostic Setting IDs

Service Scope And Design Notes

This initial release is intentionally focused on the shared Log Analytics layer and Azure Monitor Diagnostic Settings.

That makes it a natural fit for:

  • AKS control plane diagnostics and Container Insights composition
  • Azure Firewall diagnostic categories
  • Key Vault audit logs
  • Storage account blob/file/queue/table diagnostics
  • App Service and ACR diagnostic export
  • VM platform metrics
  • Storage account and Blob service logs and metrics

For VM guest logs, Azure Monitor Agent and Data Collection Rules are a distinct pattern and are not bundled into the first release.


Examples

Runnable examples are available in examples.

They show:

  • a standalone Log Analytics Workspace
  • AKS with Container Insights using terraform-az-fk-vnet and terraform-az-fk-aks
  • compute VM platform diagnostics using terraform-az-fk-vnet and terraform-az-fk-compute
  • PostgreSQL Flexible Server diagnostics using terraform-az-fk-pg
  • Storage Account and Blob service diagnostics using terraform-az-fk-vnet and terraform-az-fk-storage

Contributing

This project is open source. Contributions are welcome through pull requests.


License

Licensed under the Universal Permissive License (UPL), Version 1.0. See LICENSE for details.


© 2026 FoggyKitchen.com - Cloud. Code. Clarity.

About

Reusable Terraform / OpenTofu module and progressive examples for Azure Log Analytics Workspace and Azure Monitor Diagnostic Settings integration patterns.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages