Overview
This guide walks through how to create an Azure Log Analytics connection and the permissions it requires to be used in Blink’s Automated Case Management, primarily for Enrichment workflows (running KQL queries against a Log Analytics workspace for user and host enrichment).Like the general Azure connection, Log Analytics authorizes through Azure role-based access control (Azure RBAC) rather than Microsoft Graph API scopes. You assign a role to a service principal on the target workspace. For this reason, there is no Microsoft Graph connection option for Log Analytics. See Required Permissions.
Creating a Connection
Azure Log Analytics Connection Guide
Follow this guide to create an Azure Log Analytics connection
Log Analytics authenticates using a Microsoft Entra app registration and its service principal, which is then granted a role on the target workspace
Required Permissions
Log Analytics access is granted by assigning an Azure RBAC role to the connection’s service principal on the workspace.For Blink’s KQL-based enrichment, Log Analytics Reader at the workspace scope is sufficient. For tighter least-privilege setups, Log Analytics Data Reader grants only query and metadata access. Log Analytics queries may incur usage-based (pay-as-you-go) costs depending on your Azure plan.
Which stage of Alert Processing need this connection?
Which stage of Alert Processing need this connection?