{"_id":"@dkhalife/azure-log-analytics-mcp","_rev":"3-53ff708a99161440609bac859f19afca","name":"@dkhalife/azure-log-analytics-mcp","dist-tags":{"latest":"1.0.2"},"versions":{"1.0.0":{"name":"@dkhalife/azure-log-analytics-mcp","version":"1.0.0","keywords":["mcp","azure","log-analytics","kql","application-insights","kusto"],"author":{"name":"dkhalife"},"license":"MIT","_id":"@dkhalife/azure-log-analytics-mcp@1.0.0","maintainers":[{"name":"dkhalife","email":"npm@dkhalife.com"}],"homepage":"https://github.com/dkhalife/azure-log-analytics-mcp#readme","bugs":{"url":"https://github.com/dkhalife/azure-log-analytics-mcp/issues"},"bin":{"azure-log-analytics-mcp":"dist/index.js"},"dist":{"shasum":"039554b9448bf66d7d1f3fe02a881491d113edc1","tarball":"https://registry.npmjs.org/@dkhalife/azure-log-analytics-mcp/-/azure-log-analytics-mcp-1.0.0.tgz","fileCount":5,"integrity":"sha512-nTB+VAomXD/mtTV+F+2jN/eZ+kwrwwS3+AAuU5KkolMNtbmdo6WgbQTKNadjmR8WlFmBXV1SFjHxFW5MSEITJQ==","signatures":[{"sig":"MEQCIFQVfjc/DPWDQWKSKqP4fpHwBR4hXMAVvPzdZW9Jxoi5AiBzJpPCglULksxnJ3xa3A8nIgUWIqvfrN1D7Mwj+Eqo8Q==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":13938},"main":"dist/index.js","types":"./dist/index.d.ts","gitHead":"313d8771b1249681c05a0b996c948e1ba08da573","scripts":{"build":"tsc","start":"node dist/index.js","prepublishOnly":"npm run build"},"_npmUser":{"name":"dkhalife","email":"npm@dkhalife.com"},"repository":{"url":"git+https://github.com/dkhalife/azure-log-analytics-mcp.git","type":"git"},"_npmVersion":"11.7.0","description":"MCP server for querying Azure Log Analytics workspaces","directories":{},"_nodeVersion":"22.21.1","dependencies":{"@azure/identity":"^4.6.0","@azure/monitor-query":"^1.3.0","@modelcontextprotocol/sdk":"^1.11.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/azure-log-analytics-mcp_1.0.0_1771691972840_0.08082261569969917","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@dkhalife/azure-log-analytics-mcp","version":"1.0.1","keywords":["mcp","azure","log-analytics","kql","application-insights","kusto"],"author":{"name":"dkhalife"},"license":"MIT","_id":"@dkhalife/azure-log-analytics-mcp@1.0.1","maintainers":[{"name":"dkhalife","email":"npm@dkhalife.com"}],"homepage":"https://github.com/dkhalife/azure-log-analytics-mcp#readme","bugs":{"url":"https://github.com/dkhalife/azure-log-analytics-mcp/issues"},"bin":{"azure-log-analytics-mcp":"dist/index.js"},"dist":{"shasum":"29751c5707e2c785d2aa654fd7083000c57de0ad","tarball":"https://registry.npmjs.org/@dkhalife/azure-log-analytics-mcp/-/azure-log-analytics-mcp-1.0.1.tgz","fileCount":5,"integrity":"sha512-DTE+bK9i2X2ukxObOYfu+cmh2iBYSOUTKydGsucTwbW1MwsDu9weltTQxz9uu6xVWeKDGUtJQ/Y74Aapa3qRvg==","signatures":[{"sig":"MEQCIB12CZ+v7D98dYhmNAleKt+KnDuJ4IB3MAEct7U9EHYlAiBrfgf0QBxOtTWnvXYXq661WolPO2mV1KQqKTb810YMqQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@dkhalife%2fazure-log-analytics-mcp@1.0.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":13906},"main":"dist/index.js","types":"./dist/index.d.ts","gitHead":"e219f14051cde0ecd7b5b62af7b106556edc1804","scripts":{"build":"tsc","start":"node dist/index.js","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:12c9dc76-6db8-4c96-b85f-a39177c36f67"}},"repository":{"url":"git+https://github.com/dkhalife/azure-log-analytics-mcp.git","type":"git"},"_npmVersion":"11.6.2","description":"MCP server for querying Azure Log Analytics workspaces","directories":{},"_nodeVersion":"24.13.0","dependencies":{"@azure/identity":"^4.6.0","@azure/monitor-query":"^1.3.0","@modelcontextprotocol/sdk":"^1.11.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/azure-log-analytics-mcp_1.0.1_1771694158504_0.6141868849426346","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@dkhalife/azure-log-analytics-mcp","version":"1.0.2","description":"MCP server for querying Azure Log Analytics workspaces","main":"dist/index.js","bin":{"azure-log-analytics-mcp":"dist/index.js"},"scripts":{"build":"tsc","start":"node dist/index.js","prepublishOnly":"npm run build"},"keywords":["mcp","azure","log-analytics","kql","application-insights","kusto"],"license":"MIT","author":{"name":"dkhalife"},"repository":{"type":"git","url":"git+https://github.com/dkhalife/azure-log-analytics-mcp.git"},"bugs":{"url":"https://github.com/dkhalife/azure-log-analytics-mcp/issues"},"homepage":"https://github.com/dkhalife/azure-log-analytics-mcp#readme","publishConfig":{"access":"public"},"dependencies":{"@azure/identity":"^4.6.0","@azure/monitor-query-logs":"^1.0.0","@modelcontextprotocol/sdk":"^1.11.0"},"devDependencies":{"@types/node":"^22.0.0","typescript":"^5.7.0"},"gitHead":"18299d26afc173dc019b2703f2610de8652c9de5","types":"./dist/index.d.ts","_id":"@dkhalife/azure-log-analytics-mcp@1.0.2","_nodeVersion":"24.13.0","_npmVersion":"11.6.2","dist":{"integrity":"sha512-tgHTfqLxqFxD5zGybqvmG355HSyDZ6CkohQDN6NyD3QDbJHfF5x75aaC7O4oq3+TlowGPOkrm2ydobIL3yBY3Q==","shasum":"b237feedf86d43f9b2e25fd5abacdccdc4f47e07","tarball":"https://registry.npmjs.org/@dkhalife/azure-log-analytics-mcp/-/azure-log-analytics-mcp-1.0.2.tgz","fileCount":5,"unpackedSize":13936,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@dkhalife%2fazure-log-analytics-mcp@1.0.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCPNrYsdf/cQIBvBrZMx8KlCYdqqr/DAQg+16iuJn5HBQIhAP8QRbMeuWCHBF45sHVQggPeIwrnWPyvqX2/1xgFP1yD"}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:12c9dc76-6db8-4c96-b85f-a39177c36f67"}},"directories":{},"maintainers":[{"name":"dkhalife","email":"npm@dkhalife.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/azure-log-analytics-mcp_1.0.2_1771694429036_0.9596547799170951"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-21T16:39:32.761Z","modified":"2026-02-21T17:20:29.477Z","1.0.0":"2026-02-21T16:39:32.968Z","1.0.1":"2026-02-21T17:15:58.649Z","1.0.2":"2026-02-21T17:20:29.196Z"},"bugs":{"url":"https://github.com/dkhalife/azure-log-analytics-mcp/issues"},"author":{"name":"dkhalife"},"license":"MIT","homepage":"https://github.com/dkhalife/azure-log-analytics-mcp#readme","keywords":["mcp","azure","log-analytics","kql","application-insights","kusto"],"repository":{"type":"git","url":"git+https://github.com/dkhalife/azure-log-analytics-mcp.git"},"description":"MCP server for querying Azure Log Analytics workspaces","maintainers":[{"name":"dkhalife","email":"npm@dkhalife.com"}],"readme":"# Azure Log Analytics MCP\n\n**Query Azure Log Analytics workspaces from any MCP client**\n\nAzure Log Analytics MCP is a lightweight [Model Context Protocol (MCP)](https://modelcontextprotocol.io) server that lets AI assistants query your Azure Log Analytics workspaces. It runs locally via stdio and authenticates using your existing Azure credentials.\n\n> **Tip:** If your Application Insights resource is workspace-based (the default since February 2024), you can use this server to query App Insights data too. See [App Insights vs Log Analytics tables](#app-insights-vs-log-analytics-tables) for details.\n\n## 🎯 What it does\n\nThis MCP server gives AI assistants read-only access to your Log Analytics telemetry data through two simple tools:\n\n* **Discover** what tables are available in your workspace\n* **Query** your telemetry using [KQL (Kusto Query Language)](https://learn.microsoft.com/en-us/azure/data-explorer/kusto/query/)\n\nAll operations are strictly read-only — KQL is a query language, not a mutation language.\n\n## ✨ Tools\n\n| Tool | Description | Parameters |\n|------|-------------|------------|\n| `list_tables` | Discovers available tables in the workspace by scanning recent data | `timespan` (optional) — ISO 8601 duration, defaults to `P1D` |\n| `query` | Runs a KQL query and returns results as JSON | `query` (required) — KQL query string; `timespan` (optional) — ISO 8601 duration, defaults to `P1D` |\n\n## 🚀 Installation\n\n### Prerequisites\n\n* [Node.js](https://nodejs.org) 18+\n* An Azure account with access to a Log Analytics workspace\n* Azure CLI logged in (`az login`) or another credential source supported by [DefaultAzureCredential](https://learn.microsoft.com/en-us/javascript/api/@azure/identity/defaultazurecredential)\n\n### Setup\n\nNo build step required for end users. Just use `npx`:\n\n```bash\nAPP_INSIGHTS_WORKSPACE_ID=<your-workspace-id> npx @dkhalife/azure-log-analytics-mcp@latest\n```\n\nFor development:\n\n```bash\ngit clone https://github.com/dkhalife/azure-log-analytics-mcp.git\ncd azure-log-analytics-mcp\nnpm install\nnpm run build\n```\n\n## ⚙️ Configuration\n\nThe server is configured via a single environment variable:\n\n| Variable | Required | Description |\n|----------|----------|-------------|\n| `APP_INSIGHTS_WORKSPACE_ID` | ✅ | The Log Analytics workspace ID (GUID) |\n\n### Finding your Workspace ID\n\n**Azure Portal:**\n1. Go to your **Log Analytics workspace** → **Overview**\n2. Copy the **Workspace ID** (a GUID)\n\n**Azure CLI:**\n```bash\naz monitor log-analytics workspace show \\\n  --workspace-name <workspace-name> \\\n  -g <resource-group> \\\n  --query \"customerId\" -o tsv\n```\n\n### Authentication\n\nThe server uses [DefaultAzureCredential](https://learn.microsoft.com/en-us/javascript/api/@azure/identity/defaultazurecredential) which automatically picks up credentials from (in order):\n\n1. Environment variables (`AZURE_CLIENT_ID`, `AZURE_TENANT_ID`, `AZURE_CLIENT_SECRET`)\n2. Azure CLI (`az login`)\n3. Azure PowerShell\n4. Managed Identity (when running in Azure)\n\nFor local development, `az login` is the simplest option.\n\n## 📋 Usage Examples\n\n### VS Code\n\nAdd to your VS Code `settings.json` under MCP servers:\n\n```json\n{\n  \"mcp\": {\n    \"servers\": {\n      \"log-analytics\": {\n        \"command\": \"npx\",\n        \"args\": [\"@dkhalife/azure-log-analytics-mcp@latest\"],\n        \"env\": {\n          \"APP_INSIGHTS_WORKSPACE_ID\": \"<your-workspace-id>\"\n        }\n      }\n    }\n  }\n}\n```\n\n### Claude Desktop\n\nAdd to your `claude_desktop_config.json`:\n\n```json\n{\n  \"mcpServers\": {\n    \"log-analytics\": {\n      \"command\": \"npx\",\n      \"args\": [\"@dkhalife/azure-log-analytics-mcp@latest\"],\n      \"env\": {\n        \"APP_INSIGHTS_WORKSPACE_ID\": \"<your-workspace-id>\"\n      }\n    }\n  }\n}\n```\n\n### Example Prompts\n\nOnce connected, you can ask your AI assistant things like:\n\n* *\"List all available tables in the workspace\"*\n* *\"Show me recent security events from the last hour\"*\n* *\"Query heartbeat data for the last 7 days grouped by computer\"*\n* *\"What are the top error events in the last 24 hours?\"*\n\n### Example KQL Queries\n\n```kusto\n// Recent heartbeats by computer\nHeartbeat\n| summarize LastHeartbeat = max(TimeGenerated) by Computer\n| order by LastHeartbeat desc\n\n// Security events by type\nSecurityEvent\n| summarize count() by Activity\n| top 10 by count_\n\n// Performance counters — average CPU usage\nPerf\n| where CounterName == \"% Processor Time\"\n| summarize avg(CounterValue) by Computer, bin(TimeGenerated, 1h)\n| order by TimeGenerated desc\n\n// Syslog errors\nSyslog\n| where SeverityLevel == \"err\"\n| summarize count() by Facility, bin(TimeGenerated, 1h)\n| order by TimeGenerated desc\n```\n\n## 📊 App Insights vs Log Analytics Tables\n\nIf your Application Insights resource is linked to a Log Analytics workspace, you can query App Insights data through this server. However, the table names differ between the two:\n\n| Log Analytics Table | Application Insights Table | Description |\n|---------------------|---------------------------|-------------|\n| `AppRequests` | `requests` | Incoming HTTP requests |\n| `AppDependencies` | `dependencies` | Outbound dependency calls |\n| `AppExceptions` | `exceptions` | Application exceptions |\n| `AppTraces` | `traces` | Log traces |\n| `AppEvents` | `customEvents` | Custom events |\n| `AppMetrics` | `customMetrics` | Custom metrics |\n| `AppPageViews` | `pageViews` | Page view telemetry |\n| `AppBrowserTimings` | `browserTimings` | Browser performance |\n| `AppAvailabilityResults` | `availabilityResults` | Availability tests |\n| `AppPerformanceCounters` | `performanceCounters` | Performance counters |\n\nWhen querying through this MCP server (which connects to the Log Analytics workspace), use the **Log Analytics table names** (left column).\n\n## ❓ FAQ\n\n**Q: Does it work with Application Insights?**\nYes, if your Application Insights resource is workspace-based (the default since February 2024). The App Insights data appears in the Log Analytics workspace under table names like `AppRequests`, `AppExceptions`, etc. See [App Insights vs Log Analytics Tables](#app-insights-vs-log-analytics-tables).\n\n**Q: What authentication methods are supported?**\nAny method supported by Azure's [DefaultAzureCredential](https://learn.microsoft.com/en-us/javascript/api/@azure/identity/defaultazurecredential) — Azure CLI, environment variables, managed identity, and more. For local use, `az login` is the easiest.\n\n**Q: What is the `timespan` parameter?**\nAn ISO 8601 duration string that limits how far back the query looks. Examples: `PT1H` (1 hour), `P1D` (1 day), `P7D` (7 days), `P30D` (30 days). Defaults to `P1D` (24 hours) if not specified.\n\n**Q: Can I query multiple workspaces?**\nNot currently. The server queries the single workspace specified by `APP_INSIGHTS_WORKSPACE_ID`.\n\n**Q: Why do I get \"The requested path does not exist\"?**\nYour `APP_INSIGHTS_WORKSPACE_ID` is incorrect. Make sure you're using the **Workspace ID** (a GUID like `xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx`), not the workspace name or ARM resource ID. See [Finding your Workspace ID](#finding-your-workspace-id).\n\n## 🤝 Contributing\n\nContributions are welcome! Feel free to fork the repo and submit pull requests.\nIf you have ideas but aren't familiar with code, you can also [open issues](https://github.com/dkhalife/azure-log-analytics-mcp/issues).\n\n## 🔒 License\n\nThis project is licensed under the MIT License. See the [LICENSE](LICENSE) file for details.\r\n","readmeFilename":"README.md"}