New to Claude Skills? Learn how to install them →

sickn33 on GitHub

Azure Monitor Ingestion SDK

Free

Effortlessly send logs to Azure Monitor.

Get this skill

Free · Opens the source repo

What Azure Monitor Ingestion SDK does

The Azure Monitor Ingestion SDK for Python simplifies the process of sending custom logs to your Azure Monitor Log Analytics workspace using the Logs Ingestion API. This SDK is designed for developers and data engineers who need to integrate log data from their applications into Azure Monitor for analysis and monitoring. By leveraging this SDK, users can programmatically upload logs, ensuring that they are properly formatted and routed to the correct destination within Azure's ecosystem.

To get started, users must set up a Log Analytics workspace, define a Data Collection Rule (DCR), and establish a Data Collection Endpoint (DCE). The SDK supports both synchronous and asynchronous operations, allowing for flexibility in how logs are uploaded. Users can easily authenticate using the DefaultAzureCredential, which streamlines the authentication process by automatically handling various Azure authentication methods.

The SDK provides robust error handling features, enabling developers to manage partial failures effectively. Users can implement callbacks to handle errors gracefully or choose to ignore them if necessary. Additionally, the SDK automatically manages log batching, splitting large log sets into manageable chunks and compressing them for efficient transmission. This feature is particularly useful for applications generating high volumes of log data.

Overall, this SDK is a valuable tool for any developer looking to enhance their application's observability by integrating with Azure Monitor. Its straightforward setup and powerful features make it a practical choice for projects requiring log ingestion into Azure's analytics platform.

When to use it

Use this SDK when you need to send logs from your application to Azure Monitor for analysis and monitoring.

When not to use it

Avoid using this SDK if your logging requirements do not involve Azure Monitor or if you need extensive customization beyond what the SDK provides.

What you can build with it

Integrating Application Logs

Use the SDK to send logs from a web application to Azure Monitor for real-time monitoring and analysis.

Batch Uploading Logs

Leverage the SDK's automatic batching feature to efficiently upload large sets of logs generated by your application.

Handling Log Ingestion Errors

Implement custom error handling to manage failed log uploads without interrupting your application's operation.

How to install Azure Monitor Ingestion SDK

View source

1. Install with the skills CLI

npx skills add sickn33/agentic-awesome-skills/azure-monitor-ingestion-py --agent claude-code

2. Or install it manually

Download the skill folder and drop it into ~/.claude/skills/ for all projects, or .claude/skills/ to scope it to one repo. Restart Claude Code so it picks up the new skill.

Anthropic's agentic coding CLI, and the reference implementation of Agent Skills. Drop a skill folder into ~/.claude/skills and Claude Code loads it automatically whenever a task matches the skill's description. Claude Code docs

Inside SKILL.md

Written by sickn33

Azure Monitor Ingestion SDK for Python

Send custom logs to Azure Monitor Log Analytics workspace using the Logs Ingestion API.

Installation

pip install azure-monitor-ingestion
pip install azure-identity

Environment Variables

# Data Collection Endpoint (DCE)
AZURE_DCE_ENDPOINT=https://<dce-name>.<region>.ingest.monitor.azure.com

# Data Collection Rule (DCR) immutable ID
AZURE_DCR_RULE_ID=dcr-xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

# Stream name from DCR
AZURE_DCR_STREAM_NAME=Custom-MyTable_CL

Prerequisites

Before using this SDK, you need:

  1. Log Analytics Workspace — Target for your logs
  2. Data Collection Endpoint (DCE) — Ingestion endpoint
  3. Data Collection Rule (DCR) — Defines schema and destination
  4. Custom Table — In Log Analytics (created via DCR or manually)

Authentication

from azure.monitor.ingestion import LogsIngestionClient
from azure.identity import DefaultAzureCredential
import os

client = LogsIngestionClient(
    endpoint=os.environ["AZURE_DCE_ENDPOINT"],
    credential=DefaultAzureCredential()
)

Upload Custom Logs

from azure.monitor.ingestion import LogsIngestionClient
from azure.identity import DefaultAzureCredential
import os

client = LogsIngestionClient(
    endpoint=os.environ["AZURE_DCE_ENDPOINT"],
    credential=DefaultAzureCredential()
)

rule_id = os.environ["AZURE_DCR_RULE_ID"]
stream_name = os.environ["AZURE_DCR_STREAM_NAME"]

logs = [
    {"TimeGenerated": "2024-01-15T10:00:00Z", "Computer": "server1", "Message": "Application started"},
    {"TimeGenerated": "2024-01-15T10:01:00Z", "Computer": "server1", "Message": "Processing request"},
    {"TimeGenerated": "2024-01-15T10:02:00Z", "Computer": "server2", "Message": "Connection established"}
]

client.upload(rule_id=rule_id, stream_name=stream_name, logs=logs)

Upload from JSON File

import json

with open("logs.json", "r") as f:
    logs = json.load(f)

client.upload(rule_id=rule_id, stream_name=stream_name, logs=logs)

Custom Error Handling

Handle partial failures with a callback:

failed_logs = []

def on_error(error):
    print(f"Upload failed: {error.error}")
    failed_logs.extend(error.failed_logs)

client.upload(
    rule_id=rule_id,
    stream_name=stream_name,
    logs=logs,
    on_error=on_error
)

# Retry failed logs
if failed_logs:
    print(f"Retrying {len(failed_logs)} failed logs...")
    client.upload(rule_id=rule_id, stream_name=stream_name, logs=failed_logs)

Ignore Errors

def ignore_errors(error):
    pass  # Silently ignore upload failures

client.upload(
    rule_id=rule_id,
    stream_name=stream_name,
    logs=logs,
    on_error=ignore_errors
)

Async Client

import asyncio
from azure.monitor.ingestion.aio import LogsIngestionClient
from azure.identity.aio import DefaultAzureCredential

async def upload_logs():
    async with LogsIngestionClient(
        endpoint=endpoint,
        credential=DefaultAzureCredential()
    ) as client:
        await client.upload(
            rule_id=rule_id,
            stream_name=stream_name,
            logs=logs
        )

asyncio.run(upload_logs())

Sovereign Clouds

from azure.identity import AzureAuthorityHosts, DefaultAzureCredential
from azure.monitor.ingestion import LogsIngestionClient

# Azure Government
credential = DefaultAzureCredential(authority=AzureAuthorityHosts.AZURE_GOVERNMENT)
client = LogsIngestionClient(
    endpoint="https://example.ingest.monitor.azure.us",
    credential=credential,
    credential_scopes=["https://monitor.azure.us/.default"]
)

Batching Behavior

The SDK automatically:

  • Splits logs into chunks of 1MB or less
  • Compresses each chunk with gzip
  • Uploads chunks in parallel

No manual batching needed for large log sets.

Client Types

ClientPurpose
LogsIngestionClientSync client for uploading logs
LogsIngestionClient (aio)Async client for uploading logs

Key Concepts

ConceptDescription
DCEData Collection Endpoint — ingestion URL
DCRData Collection Rule — defines schema, transformations, destination
StreamNamed data flow within a DCR
Custom TableTarget table in Log Analytics (ends with _CL)

DCR Stream Name Format

Stream names follow patterns:

  • Custom-<TableName>_CL — For custom tables
  • Microsoft-<TableName> — For built-in tables

Best Practices

  1. Use DefaultAzureCredential for authentication
  2. Handle errors gracefully — use on_error callback for partial failures
  3. Include TimeGenerated — Required field for all logs
  4. Match DCR schema — Log fields must match DCR column definitions
  5. Use async client for high-throughput scenarios
  6. Batch uploads — SDK handles batching, but send reasonable chunks
  7. Monitor ingestion — Check Log Analytics for ingestion status
  8. Use context manager — Ensures proper client cleanup

When to Use

This skill is applicable to execute the workflow or actions described in the overview.

Limitations

  • Use this skill only when the task clearly matches the scope described above.
  • Do not treat the output as a substitute for environment-specific validation, testing, or expert review.
  • Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.

Frequently asked questions about Azure Monitor Ingestion SDK

Similar skills