Official agent skill

Azure Monitor Query Py

by microsoft in microsoft/skills

Azure Monitor Query SDK for Python. An agent skill from microsoft/skills.

OfficialMITAuto-check passedDevOps & Cloud

Install Azure Monitor Query Py

skills CLI
$ npx skills add microsoft/skills --skill azure-monitor-query-py -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/skills azure-monitor-query-py --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/plugins/azure-sdk-python/skills/azure-monitor-query-py .claude/skills/azure-monitor-query-py && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-monitor-query-py
GitHub stars
3.1k
Token cost
~2.1k tokens
SKILL.md length
350 words
Files
3 (incl. references)
Skills in repo
150
Repo updated
First seen
Licence
MIT

At a glance

Azure Monitor Query SDK for Python. An agent skill from microsoft/skills.

  • Works in 10 steps: Pick sync OR async and stay consistent.… → Always use context managers for clients… → Use DefaultAzureCredential for portable… → …
  • Querying Log Analytics workspaces and Azure Monitor metrics
  • SKILL.md covers Installation, Environment Variables, Authentication & Lifecycle and Logs Query Client, plus 6 more sections
  • Calls pip; reaches learn.microsoft.com; needs AZURE_TOKEN_CREDENTIALS

What it does

Azure Monitor Query Py is an agent skill from microsoft/skills, published by the product's own GitHub organization. Azure Monitor Query SDK for Python. Use for querying Log Analytics workspaces and Azure Monitor metrics. Triggers: "azure-monitor-query", "LogsQueryClient", "MetricsQueryClient", "Log Analytics", "Kusto queries", "Azure metrics".

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/capabilities.md` and `references/non-hero-scenarios.md`).

It sits in DevOps & Cloud. It works with Azure Monitor, Microsoft Azure, Python and Visual Studio Code. The repository describes itself as: Skills, MCP servers, Custom Agents, Agents.md for SDKs to ground Coding Agents. The licence is MIT.

When your agent uses it

  • Querying Log Analytics workspaces and Azure Monitor metrics

Example prompts

  • “azure-monitor-query”
  • “LogsQueryClient”
  • “MetricsQueryClient”
  • “/azure-monitor-query-py”

Requirements

  • Python 3

Workflow steps

10 steps, taken from the first numbered list in SKILL.md.

  1. Pick sync OR async and stay consistent. Do not mix azure.xxx sync clients with azure.xxx.aio async clients in the same call path. Choose…
  2. Always use context managers for clients and async credentials. Wrap every client in with Client(...) as client: (sync) or async with…
  3. Use DefaultAzureCredential for portable auth across local dev and Azure (avoid connection strings / API keys when possible).
  4. Use timedelta for relative time ranges
  5. Handle partial results for large queries
  6. Use batch queries when running multiple queries
  7. Set appropriate granularity for metrics to reduce data points
  8. Convert to DataFrame for easier data analysis
  9. Use aggregations to summarize metric data
  10. Filter by dimensions to narrow metric results

What it can do on your machine

Read from SKILL.md and the folder at commit d5741a1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • AZURE_TOKEN_CREDENTIALS

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure Monitor Query Py loads about 2.1k tokens when it runs, and up to ~2.5k if it reads all its reference files. Until then it costs about 63 tokens; SKILL.md has 350 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~63
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/skills at commit d5741a1, republished under its MIT licence (© microsoft). 350 words, ~2,142 tokens.

Download SKILL.mdSave it as .claude/skills/azure-monitor-query-py/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
azure-monitor-query-py
description
Azure Monitor Query SDK for Python. Use for querying Log Analytics workspaces and Azure Monitor metrics. Triggers: "azure-monitor-query", "LogsQueryClient", "MetricsQueryClient", "Log Analytics", "Kusto queries", "Azure metrics".
license
MIT
metadata.author
Microsoft
metadata.version
1.0.0
metadata.package
azure-monitor-query

Azure Monitor Query SDK for Python

Query logs and metrics from Azure Monitor and Log Analytics workspaces.

Installation

bash
pip install azure-monitor-query

Environment Variables

bash
# Log Analytics
AZURE_LOG_ANALYTICS_WORKSPACE_ID=<workspace-id>  # Required for log queries

# Metrics
AZURE_METRICS_RESOURCE_URI=/subscriptions/<sub>/resourceGroups/<rg>/providers/<provider>/<type>/<name>  # Required for metric queries
AZURE_TOKEN_CREDENTIALS=prod # Required only if DefaultAzureCredential is used in production

Authentication & Lifecycle

🔑 Two rules apply to every code sample below:

  1. Prefer DefaultAzureCredential. It works locally (Azure CLI / VS Code / Developer CLI) and in Azure (managed identity, workload identity) with no code change. Avoid connection strings, account/API keys — they bypass Entra audit and rotation.
    • Local dev: DefaultAzureCredential works as-is.
    • Production: set AZURE_TOKEN_CREDENTIALS=prod (or AZURE_TOKEN_CREDENTIALS=<specific_credential>) to constrain the credential chain to production-safe credentials.
  2. Wrap every client in a context manager so HTTP transports, sockets, and token caches are released deterministically:
    • Sync: with <Client>(...) as client:
    • Async: async with <Client>(...) as client: and async with DefaultAzureCredential() as credential: (from azure.identity.aio)

Snippets may abbreviate this setup, but production code should always follow both rules.

python
from azure.identity import DefaultAzureCredential, ManagedIdentityCredential

# Local dev: DefaultAzureCredential. Production: set AZURE_TOKEN_CREDENTIALS=prod or AZURE_TOKEN_CREDENTIALS=<specific_credential>
credential = DefaultAzureCredential(require_envvar=True)
# Or use a specific credential directly in production:
# See https://learn.microsoft.com/python/api/overview/azure/identity-readme?view=azure-python#credential-classes
# credential = ManagedIdentityCredential()

Logs Query Client

Basic Query
python
from azure.monitor.query import LogsQueryClient
from datetime import timedelta

query = """
AppRequests
| where TimeGenerated > ago(1h)
| summarize count() by bin(TimeGenerated, 5m), ResultCode
| order by TimeGenerated desc
"""

with LogsQueryClient(credential) as client:
    response = client.query_workspace(
        workspace_id=os.environ["AZURE_LOG_ANALYTICS_WORKSPACE_ID"],
        query=query,
        timespan=timedelta(hours=1)
    )

    for table in response.tables:
        for row in table.rows:
            print(row)
Query with Time Range
python
from datetime import datetime, timezone

response = client.query_workspace(
    workspace_id=workspace_id,
    query="AppRequests | take 10",
    timespan=(
        datetime(2024, 1, 1, tzinfo=timezone.utc),
        datetime(2024, 1, 2, tzinfo=timezone.utc)
    )
)
Convert to DataFrame
python
import pandas as pd

response = client.query_workspace(workspace_id, query, timespan=timedelta(hours=1))

if response.tables:
    table = response.tables[0]
    df = pd.DataFrame(data=table.rows, columns=[col.name for col in table.columns])
    print(df.head())
Batch Query
python
from azure.monitor.query import LogsBatchQuery

queries = [
    LogsBatchQuery(workspace_id=workspace_id, query="AppRequests | take 5", timespan=timedelta(hours=1)),
    LogsBatchQuery(workspace_id=workspace_id, query="AppExceptions | take 5", timespan=timedelta(hours=1))
]

responses = client.query_batch(queries)

for response in responses:
    if response.tables:
        print(f"Rows: {len(response.tables[0].rows)}")
Handle Partial Results
python
from azure.monitor.query import LogsQueryStatus

response = client.query_workspace(workspace_id, query, timespan=timedelta(hours=24))

if response.status == LogsQueryStatus.PARTIAL:
    print(f"Partial results: {response.partial_error}")
elif response.status == LogsQueryStatus.FAILURE:
    print(f"Query failed: {response.partial_error}")

Metrics Query Client

Query Resource Metrics
python
from azure.monitor.query import MetricsQueryClient
from datetime import timedelta

with MetricsQueryClient(credential) as metrics_client:
    response = metrics_client.query_resource(
        resource_uri=os.environ["AZURE_METRICS_RESOURCE_URI"],
        metric_names=["Percentage CPU", "Network In Total"],
        timespan=timedelta(hours=1),
        granularity=timedelta(minutes=5)
    )

    for metric in response.metrics:
        print(f"{metric.name}:")
        for time_series in metric.timeseries:
            for data in time_series.data:
                print(f"  {data.timestamp}: {data.average}")
Aggregations
python
from azure.monitor.query import MetricAggregationType

response = metrics_client.query_resource(
    resource_uri=resource_uri,
    metric_names=["Requests"],
    timespan=timedelta(hours=1),
    aggregations=[
        MetricAggregationType.AVERAGE,
        MetricAggregationType.MAXIMUM,
        MetricAggregationType.MINIMUM,
        MetricAggregationType.COUNT
    ]
)
Filter by Dimension
python
response = metrics_client.query_resource(
    resource_uri=resource_uri,
    metric_names=["Requests"],
    timespan=timedelta(hours=1),
    filter="ApiName eq 'GetBlob'"
)
List Metric Definitions
python
definitions = metrics_client.list_metric_definitions(resource_uri)
for definition in definitions:
    print(f"{definition.name}: {definition.unit}")
List Metric Namespaces
python
namespaces = metrics_client.list_metric_namespaces(resource_uri)
for ns in namespaces:
    print(ns.fully_qualified_namespace)

Async Clients

python
from azure.monitor.query.aio import LogsQueryClient, MetricsQueryClient
from azure.identity.aio import DefaultAzureCredential

async def query_logs():
    async with DefaultAzureCredential() as credential:
        async with LogsQueryClient(credential) as client:
            response = await client.query_workspace(
                workspace_id=workspace_id,
                query="AppRequests | take 10",
                timespan=timedelta(hours=1)
            )
            return response

Common Kusto Queries

kusto
// Requests by status code
AppRequests
| summarize count() by ResultCode
| order by count_ desc

// Exceptions over time
AppExceptions
| summarize count() by bin(TimeGenerated, 1h)

// Slow requests
AppRequests
| where DurationMs > 1000
| project TimeGenerated, Name, DurationMs
| order by DurationMs desc

// Top errors
AppExceptions
| summarize count() by ExceptionType
| top 10 by count_

Client Types

ClientPurpose
LogsQueryClientQuery Log Analytics workspaces
MetricsQueryClientQuery Azure Monitor metrics
Show full SKILL.md (166 more words)Show less

Best Practices

  1. Pick sync OR async and stay consistent. Do not mix azure.xxx sync clients with azure.xxx.aio async clients in the same call path. Choose one mode per module.
  2. Always use context managers for clients and async credentials. Wrap every client in with Client(...) as client: (sync) or async with Client(...) as client: (async). For async DefaultAzureCredential from azure.identity.aio, also use async with credential: so tokens and transports are cleaned up.
  3. Use DefaultAzureCredential for portable auth across local dev and Azure (avoid connection strings / API keys when possible).
  4. Use timedelta for relative time ranges
  5. Handle partial results for large queries
  6. Use batch queries when running multiple queries
  7. Set appropriate granularity for metrics to reduce data points
  8. Convert to DataFrame for easier data analysis
  9. Use aggregations to summarize metric data
  10. Filter by dimensions to narrow metric results

Reference Files

FileContents
references/capabilities.mdAdditional non-hero capabilities, operation-group coverage, and production checklists.
references/non-hero-scenarios.mdDedicated non-hero examples for secondary/advanced scenarios.

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .github/plugins/azure-sdk-python/skills/azure-monitor-query-py of microsoft/skills.

  • SKILL.md
  • references/capabilities.md
  • references/non-hero-scenarios.md

Open the folder on GitHubat commit d5741a1

Compare with similar skills

Azure Monitor Query Py next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Monitor Query Py compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Monitor Query Py this skillmicrosoft/skills3.1k—~2.1kAutomated safety check: PassMIT
Azure Carbon OptimizationMicrosoftDocs/Agent-Skills776—~837Automated safety check: PassCC-BY-4.0
Azure Architecture Autopilotgithub/awesome-copilot40k1 repos~1.9kAutomated safety check: PassMIT
Terraform Azurerm Set Diff Analyzergithub/awesome-copilot40k1 repos~547Automated safety check: PassMIT
Osmo Lerobot Trainingmicrosoft/physical-ai-toolchain126—~3.8kAutomated safety check: NotesMIT
Azure AI Deploytimothywarner-org/claude-code224—~731Automated safety check: NotesMIT

Similar skills

  • Azure Carbon Optimization

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure Carbon Optimization development including troubleshooting, security, and integrations & coding patterns.

    776 GitHub stars~837 tokensUpdated 5 days ago
    Backend & APIsAuto-check passed
  • Azure Architecture Autopilot

    github/awesome-copilot

    Official

    Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.

    40k GitHub starsUsed in 1 repo~1.9k tokens
    DevOps & CloudAuto-check passed
  • Official

    Analyze Terraform plan JSON output for AzureRM Provider to distinguish between false-positive diffs (order-only changes in Set-type attributes) and actual resource changes.

    40k GitHub starsUsed in 1 repo~547 tokens
    DevOps & CloudAuto-check passed
  • Osmo Lerobot Training

    microsoft/physical-ai-toolchain

    Official

    Submit, monitor, analyze, and evaluate LeRobot imitation learning training jobs on OSMO with Azure ML MLflow integration and inference evaluation - Brought to you by microsoft/physical-ai-toolchain

    126 GitHub stars~3.8k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Azure AI Deploy

    timothywarner-org/claude-code

    Ship a Python generative-AI app to Azure the keyless way, using DefaultAzureCredential and azd.

    224 GitHub stars~731 tokensUpdated 2 mo ago
    DevOps & CloudAuto-check: notes
  • Apex Azure Bicep Patterns

    jonathan-vella/apex

    UTILITY SKILL — Reusable Azure Bicep patterns: hub-spoke, private endpoints, diagnostics, AVM composition.

    217 GitHub stars~2.5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from microsoft/skills

All 150 skills in this repo
  • Official

    Covers producer, consumer, and checkpoint-store setup for Azure Event Hubs streaming in Python, with Entra ID auth and partition targeting.

    3.1k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Official

    Builds podcast-style audio narration from text with Azure OpenAI's GPT Realtime Mini over WebSocket, from a Python FastAPI backend to a React player.

    3.1k GitHub starsUsed in 1 repo~947 tokens
    Auto-check passed
  • Frontend UI Dark TS

    microsoft/skills

    Official

    Build dark-themed React applications using Tailwind CSS with custom theming, glassmorphism effects, and Framer Motion animations.

    3.1k GitHub starsUsed in 5 repos~3.6k tokens
    Auto-check passed
  • Pydantic Models Py

    microsoft/skills

    Official

    Create Pydantic models following the multi-model pattern with Base, Create, Update, Response, and InDB variants.

    3.1k GitHub starsUsed in 5 repos~496 tokens
    Auto-check passed
  • Official

    Reference for building on Microsoft Foundry with the azure-ai-projects Python SDK: project clients, versioned agents, evaluations, connections, datasets and indexes.

    3.1k GitHub stars~2.8k tokensUpdated yesterday
    Auto-check passed
  • Skill Creator

    microsoft/skills

    Official

    Guide for creating effective skills for AI coding agents working with Azure SDKs and Microsoft Foundry services.

    3.1k GitHub starsUsed in 5 repos~17k tokens
    Auto-check passed

Categories

Questions about Azure Monitor Query Py

What does Azure Monitor Query Py do?

Azure Monitor Query SDK for Python. An agent skill from microsoft/skills. Azure Monitor Query Py is an agent skill from microsoft/skills, published by the product's own GitHub organization. Azure Monitor Query SDK for Python.

When should I use Azure Monitor Query Py?

Azure Monitor Query Py fits situations like: querying Log Analytics workspaces and Azure Monitor metrics.

How do I install Azure Monitor Query Py in Claude Code?

Run `npx skills add microsoft/skills --skill azure-monitor-query-py -a claude-code`. Or copy the skill folder (.github/plugins/azure-sdk-python/skills/azure-monitor-query-py in microsoft/skills) into .claude/skills/azure-monitor-query-py in your project. Claude Code loads it when a task matches its description.

How do I install Azure Monitor Query Py in Codex?

Run `npx skills add microsoft/skills --skill azure-monitor-query-py -a codex`. Or copy the skill folder (.github/plugins/azure-sdk-python/skills/azure-monitor-query-py in microsoft/skills) into .agents/skills/azure-monitor-query-py in your project. Codex loads it when a task matches its description.

Can I use Azure Monitor Query Py in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/skills --skill azure-monitor-query-py -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-monitor-query-py, .gemini/skills/azure-monitor-query-py, .github/skills/azure-monitor-query-py and .opencode/skills/azure-monitor-query-py in your project.

What does Azure Monitor Query Py need to run?

Going by SKILL.md and its folder, Azure Monitor Query Py needs the command-line tools its instructions call (pip) and credentials named AZURE_TOKEN_CREDENTIALS. Our summary lists: Python 3.

Does Azure Monitor Query Py access the network?

SKILL.md names 1 domain. In commands or code: learn.microsoft.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Azure Monitor Query Py safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure Monitor Query Py use?

Azure Monitor Query Py is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Monitor Query Py use?

About 2.1k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 370 tokens, read only when the agent opens those files.

What are the alternatives to Azure Monitor Query Py?

Skills that share tags, products or a category with Azure Monitor Query Py: Azure Carbon Optimization (MicrosoftDocs/Agent-Skills, 776 stars), Azure Architecture Autopilot (github/awesome-copilot, 40k stars), Terraform Azurerm Set Diff Analyzer (github/awesome-copilot, 40k stars) and Osmo Lerobot Training (microsoft/physical-ai-toolchain, 126 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Monitor Query Py?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/skills, which has 3,097 GitHub stars. The repository holds 150 skills in this directory. The repository was last updated on October 9, 2026.

Source: microsoft/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.