Summarize Data for DNS Essentials Solution using Log Ingestion API

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


This playbook summarizes data for DNS Essentials Solution and ingests into custom tables.

Attribute Value
Type Playbook
Solution DNS Essentials
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
DNS_Summarized_Logs_ipV1_CL 🔶 ? ✓ ?
DNS_Summarized_Logs_sourceInfoV1_CL 🔶 ? ✓ ?

Logic App Connectors

This playbook uses 2 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azuremonitorlogs Managed 1 2
http Built-in 0 2
Action parameters (URLs, paths, function IDs)

azuremonitorlogs (Managed)

Action Method Endpoint Other
Run_query_and_list_results_-_IP post /queryData —
Run_query_and_list_results_-_SourceInfo post /queryData —

http (Built-in)

Action Method Endpoint Other
Send_Data_-_IP POST @parameters('IPIngestionEndpoint') —
Send_Data POST @parameters('SourceInfoIngestionEndpoint') —

Additional Documentation

📄 Source: SummarizeData_DNSEssentials_Logingestionapi/readme.md

DNS Essentials Summarization Capability

This Logic App ingests summarized DNS data into custom Log Analytics tables by using the Logs Ingestion API. Enabling this playbook incurs additional cost.

Summary

The playbook improves DNS Essentials solution performance by creating two tables containing analytics based on the ASIM DNS schema:

The V1 table names avoid conflicts with existing classic tables. The playbook uses a data collection endpoint (DCE), data collection rule (DCR), and its managed identity to ingest summarized data.

Deployment Instructions

  1. Deploy the playbook by selecting the applicable button:

Deploy to Azure Deploy to Azure Gov

  1. Deploy the playbook to a resource group in the same Azure region as the Log Analytics workspace.
  2. Provide the required parameters:
    • Playbook Name: The default is SummarizeDNSData_DNS_logingestion.
    • Log Analytics Name: The Log Analytics workspace that contains the DNS data.
    • Resource Group Name and Subscription ID: The workspace resource group and subscription.

The deployment creates the DCE, DCR, V1 custom tables, and grants the playbook managed identity the Monitoring Metrics Publisher role on the DCR.

Post-Deployment Instructions

Authorize the Azure Monitor Logs API connection if prompted:

  1. Open the Azure Monitor Logs API connection.
  2. Select Edit API connection.
  3. Select Authorize, sign in, and then save the connection.

The Logs Ingestion API uses the playbook's managed identity. No Azure Log Analytics Data Collector connection or workspace key is required.


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Playbooks · Back to DNS Essentials