---
title: "Send data to Azure Monitor and Sentinel"
url: "https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/azure-monitor/"
last_modified: "2026-08-05T15:08:09+02:00"
---

> For the complete documentation index, see [llms.txt](https://axoflow.com/docs/axosyslog-core/4.28/llms.txt).

# Send data to Azure Monitor and Sentinel

Starting with version 4.10.0, AxoSyslog can send data to [Azure Monitor](https://learn.microsoft.com/en-us/azure/azure-monitor/overview) using its [HTTP REST Logs ingestion API](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/logs-ingestion-api-overview#rest-api-call). Data sent to Azure Monitor’s Log Analytics is also available from [Microsoft Sentinel](https://learn.microsoft.com/en-us/azure/sentinel/data-transformation).

> **Note:**
>
> Version 4.10 introduced the `azure-monitor-builtin()` and `azure-monitor-custom()` destinations. These were deprecated and unified as `azure-monitor()` in version 4.11.
>
> Also, the `table-name()` option of the driver has been renamed to `stream-name()`.

## Prerequisites

- Install the `axosyslog-scl` package on [Debian/Ubuntu](https://axoflow.com/docs/axosyslog-core/4.28/install/debian-ubuntu/index.md). On [RHEL and compatible distributions](https://axoflow.com/docs/axosyslog-core/4.28/install/rhel-fedora-almalinux/index.md), the SCL files are part of the `axosyslog` base package.

  Your configuration must also contain `@include "scl.conf"`, which the default configuration file already does. If the SCL files are missing, AxoSyslog fails to start with an [`unexpected LL_IDENTIFIER` error](https://axoflow.com/docs/axosyslog-core/4.28/chapter-troubleshooting-syslog-ng/unexpected-ll-identifier/index.md).

  ```shell
  @include "scl.conf"
  ```

  The `azure-monitor()` driver is a reusable configuration snippet (SCL). For details on using or writing such configuration snippets, see [Reusing configuration blocks](https://axoflow.com/docs/axosyslog-core/4.28/chapter-configuration-file/large-configs/config-blocks/index.md). You can find its source in [scl/azure/azure-monitor.conf](https://github.com/axoflow/axosyslog/blob/main/scl/azure/azure-monitor.conf) on GitHub.
- This feature requires a separate module. Install the `axosyslog-mod-http` package on [Debian/Ubuntu](https://axoflow.com/docs/axosyslog-core/4.28/install/debian-ubuntu/index.md), or the `axosyslog-http` package on [RHEL and compatible distributions](https://axoflow.com/docs/axosyslog-core/4.28/install/rhel-fedora-almalinux/index.md). If the module isn’t installed, AxoSyslog fails to start with an [`unexpected LL_IDENTIFIER` error](https://axoflow.com/docs/axosyslog-core/4.28/chapter-troubleshooting-syslog-ng/unexpected-ll-identifier/index.md).
- This feature requires a separate module. Install the `axosyslog-mod-cloud-auth` package on [Debian/Ubuntu](https://axoflow.com/docs/axosyslog-core/4.28/install/debian-ubuntu/index.md), or the `axosyslog-cloud-auth` package on [RHEL and compatible distributions](https://axoflow.com/docs/axosyslog-core/4.28/install/rhel-fedora-almalinux/index.md). If the module isn’t installed, AxoSyslog fails to start with an [`unexpected LL_IDENTIFIER` error](https://axoflow.com/docs/axosyslog-core/4.28/chapter-troubleshooting-syslog-ng/unexpected-ll-identifier/index.md).
- An Azure subscription.
- A [Microsoft Entra application](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/tutorial-logs-ingestion-portal#create-azure-ad-application). You’ll need the Tenant ID, App ID, and App Secret of the application to configure the AxoSyslog destination.
- A [Data Collection Endpoint (DCE)](https://learn.microsoft.com/en-us/azure/azure-monitor/essentials/data-collection-endpoint-overview?tabs=portal)
- A [Data Collection Rule (DCR)](https://learn.microsoft.com/en-us/azure/azure-monitor/essentials/data-collection-rule-create-edit?tabs=portal)
- A [Log Analytics Workspace in Azure](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/log-analytics-workspace-overview).

For details, see the [Tutorial: Send data to Azure Monitor Logs with Logs ingestion API](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/tutorial-logs-ingestion-portal).

## Configuration

The `azure-monitor()` driver sends data to the built-in tables of Azure Monitor. The body of the message (`${MESSAGE}`) must be in JSON format. The keys in the JSON array must have the same names as the columns of the table (you can use [`format-json`](https://axoflow.com/docs/axosyslog-core/4.28/chapter-manipulating-messages/customizing-message-format/reference-template-functions/index.md#template-function-format-json) or [‘FilterX`](https://axoflow.com/docs/axosyslog-core/4.28/filterx/index.md)). If a field is empty, or Azure cannot parse it, it will be blank. The following example sends data to the [syslog table](https://learn.microsoft.com/en-us/azure/azure-monitor/reference/tables/syslog).

```sh
@include "scl.conf"
# ...

destination d_azure {
  azure-monitor(
    stream-name("syslog")
    dcr-id("my-dcr-id")
    dce-uri("https://dce-uri.ingest.monitor.azure.com")
    template("$MESSAGE")
    auth(tenant-id("my-tenant-id") app-id("my-app-id") app-secret("my-app-secret"))
  );
};
```

## Options

The following options are specific to the `azure-monitor()` destination. But since this destination is based on the `http()` destination, you can use the [options of the `http()` destination](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-http-nonjava/reference-destination-http-nonjava/index.md) as well if needed.

> Note: The `azure-monitor()` destination automatically configures some of these `http()` destination options as required by the Azure Monitor Logs ingestion API.

## auth()

Options for OAUTH2 authentication for Azure.

To authenticate, you need to register a [Microsoft Entra application](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/tutorial-logs-ingestion-portal#create-azure-ad-application). You’ll need the Tenant ID, App ID, and App Secret of this application to configure the AxoSyslog destination.

#### app-id()

|  |  |
| --- | --- |
| Type: | string |
| Default: |  |

*Description:* Application (client) ID of the Microsoft Entra application.

#### app-secret()

|  |  |
| --- | --- |
| Type: | string |
| Default: |  |

*Description:* The Client secret of the Microsoft Entra application.

#### tenant-id()

|  |  |
| --- | --- |
| Type: | string |
| Default: |  |

*Description:* Directory (tenant) ID of the Microsoft Entra application.

## dce-uri()

|  |  |
| --- | --- |
| Type: | string |
| Default: | - |

*Description:* The URI of your Data Collection Endpoint (DCE).

## dcr-id()

|  |  |
| --- | --- |
| Type: | string |
| Default: | - |

*Description:* The ID of the Azure Monitor Data Collection Rule (DCR) where AxoSyslog sends the data.

## table-name()

This option was available in version 4.10, but has been deprecated in 4.11. Use [`stream-name()`](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/azure-monitor/index.md#stream-name) instead.

## stream-name()

|  |  |
| --- | --- |
| Type: | string |
| Default: | - |

*Description:* The name of the table in the Log Analytics Workspace where AxoSyslog sends the data, for example, [syslog](https://learn.microsoft.com/en-us/azure/azure-monitor/reference/tables/syslog).

Last modified August 5, 2026: [Small fixes and deduplications (99cac43a)](https://github.com/axoflow/axosyslog-core-docs/commit/99cac43a517770299b97c7ed360eb87af9fef5ab)
