Skip to main content

Overview

This guide walks through how to create an Azure Log Analytics connection and the permissions it requires to be used in Blink’s Automated Case Management, primarily for Enrichment workflows (running KQL queries against a Log Analytics workspace for user and host enrichment).
Like the general Azure connection, Log Analytics authorizes through Azure role-based access control (Azure RBAC) rather than Microsoft Graph API scopes. You assign a role to a service principal on the target workspace. For this reason, there is no Microsoft Graph connection option for Log Analytics. See Required Permissions.

Creating a Connection

Azure Log Analytics Connection Guide

Follow this guide to create an Azure Log Analytics connection
Log Analytics authenticates using a Microsoft Entra app registration and its service principal, which is then granted a role on the target workspace
Assign the role at the workspace scope (rather than subscription-wide) and prefer read-only access, so Blink can query only the logs it needs.

Required Permissions

Log Analytics access is granted by assigning an Azure RBAC role to the connection’s service principal on the workspace.
For Blink’s KQL-based enrichment, Log Analytics Reader at the workspace scope is sufficient. For tighter least-privilege setups, Log Analytics Data Reader grants only query and metadata access. Log Analytics queries may incur usage-based (pay-as-you-go) costs depending on your Azure plan.