> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blinkops.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Microsoft Azure Log Analytics

## Overview

This guide walks through how to create an Azure Log Analytics connection and the permissions it requires to be used in Blink's Automated Case Management, primarily for **Enrichment** workflows (running KQL queries against a Log Analytics workspace for user and host enrichment).

<Note>
  Like the general Azure connection, Log Analytics authorizes through **Azure role-based access control (Azure RBAC)** rather than Microsoft Graph API scopes. You assign a role to a service principal on the target workspace. For this reason, there is no Microsoft Graph connection option for Log Analytics. See [Required Permissions](#required-permissions).
</Note>

***

## Creating a Connection

<Card title="Azure Log Analytics Connection Guide" icon="arrow-up-right-from-square" href="https://docs.blinkops.com/docs/integrations/microsoft-azure-log-analytics">
  Follow this guide to create an Azure Log Analytics connection

  <Note>Log Analytics authenticates using a **Microsoft Entra app registration** and its **service principal**, which is then granted a role on the target workspace</Note>

  <Warning>
    Assign the role at the workspace scope (rather than subscription-wide) and prefer read-only access, so Blink can query only the logs it needs.
  </Warning>
</Card>

***

## Required Permissions

Log Analytics access is granted by assigning an **Azure RBAC role** to the connection's service principal on the workspace.

| Role | Access | Needed for |
| - | - | - |
| `Log Analytics Reader` | View and search all monitoring data and settings in the workspace | Running KQL enrichment queries (recommended default) |
| `Log Analytics Data Reader` | Query and read log data with the minimum necessary permissions | Least-privilege alternative when broader read access isn't wanted |
| `Log Analytics Contributor` | Read data and edit monitoring settings | Only if Blink must modify workspace settings |

<Info>
  For Blink's KQL-based enrichment, **Log Analytics Reader** at the workspace scope is sufficient. For tighter least-privilege setups, **Log Analytics Data Reader** grants only query and metadata access. Log Analytics queries may incur usage-based (pay-as-you-go) costs depending on your Azure plan.
</Info>

<AccordionGroup>
  <Accordion title="Which stage of Alert Processing need this connection?" icon="table">
    | Source | Requires this connection? | Notes |
    | - | - | - |
    | Ingestion | ✗ No | Not applicable |
    | Enrichment | ✓ Yes | KQL user/host enrichment queries (`Log Analytics Reader`) |
    | Response | ✗ No | Not applicable |
  </Accordion>
</AccordionGroup>

***


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.