Official agent skill

Azure Monitor Ingestion Py

by microsoft in microsoft/skills

Azure Monitor Ingestion SDK for Python. An agent skill from microsoft/skills.

OfficialMITAuto-check passedDevOps & Cloud

Install Azure Monitor Ingestion Py

skills CLI
$ npx skills add microsoft/skills --skill azure-monitor-ingestion-py -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/skills azure-monitor-ingestion-py --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/plugins/azure-sdk-python/skills/azure-monitor-ingestion-py .claude/skills/azure-monitor-ingestion-py && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-monitor-ingestion-py
GitHub stars
3.1k
Token cost
~2k tokens
SKILL.md length
468 words
Files
3 (incl. references)
Skills in repo
150
Repo updated
First seen
Licence
MIT

At a glance

Azure Monitor Ingestion SDK for Python. An agent skill from microsoft/skills.

  • Works in 4 steps: Log Analytics Workspace — Target for… → Data Collection Endpoint (DCE) —… → Data Collection Rule (DCR) — Defines… → …
  • Sending custom logs to Log Analytics workspace via Logs Ingestion API
  • SKILL.md covers Installation, Environment Variables, Prerequisites and Authentication & Lifecycle, plus 12 more sections
  • Calls pip; reaches learn.microsoft.com and monitor.azure.us; needs AZURE_TOKEN_CREDENTIALS

What it does

Azure Monitor Ingestion Py is an agent skill from microsoft/skills, published by the product's own GitHub organization. Azure Monitor Ingestion SDK for Python. Use for sending custom logs to Log Analytics workspace via Logs Ingestion API. Triggers: "azure-monitor-ingestion", "LogsIngestionClient", "custom logs", "DCR", "data collection rule", "Log Analytics".

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/capabilities.md` and `references/non-hero-scenarios.md`).

It sits in DevOps & Cloud. It works with Azure Monitor, Python, Microsoft Azure and Visual Studio Code. The repository describes itself as: Skills, MCP servers, Custom Agents, Agents.md for SDKs to ground Coding Agents. The licence is MIT.

When your agent uses it

  • Sending custom logs to Log Analytics workspace via Logs Ingestion API

Example prompts

  • “azure-monitor-ingestion”
  • “LogsIngestionClient”
  • “custom logs”
  • “/azure-monitor-ingestion-py”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Log Analytics Workspace — Target for your logs
  2. Data Collection Endpoint (DCE) — Ingestion endpoint
  3. Data Collection Rule (DCR) — Defines schema and destination
  4. Custom Table — In Log Analytics (created via DCR or manually)

What it can do on your machine

Read from SKILL.md and the folder at commit d5741a1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • learn.microsoft.com
    • monitor.azure.us

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • AZURE_TOKEN_CREDENTIALS

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure Monitor Ingestion Py loads about 2k tokens when it runs, and up to ~3k if it reads all its reference files. Until then it costs about 67 tokens; SKILL.md has 468 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/skills at commit d5741a1, republished under its MIT licence (© microsoft). 468 words, ~2,004 tokens.

Download SKILL.mdSave it as .claude/skills/azure-monitor-ingestion-py/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
azure-monitor-ingestion-py
description
Azure Monitor Ingestion SDK for Python. Use for sending custom logs to Log Analytics workspace via Logs Ingestion API. Triggers: "azure-monitor-ingestion", "LogsIngestionClient", "custom logs", "DCR", "data collection rule", "Log Analytics".
license
MIT
metadata.author
Microsoft
metadata.version
1.0.0
metadata.package
azure-monitor-ingestion

Azure Monitor Ingestion SDK for Python

Send custom logs to Azure Monitor Log Analytics workspace using the Logs Ingestion API.

Installation

bash
pip install azure-monitor-ingestion
pip install azure-identity

Environment Variables

bash
# Data Collection Endpoint (DCE)
AZURE_DCE_ENDPOINT=https://<dce-name>.<region>.ingest.monitor.azure.com  # Required for all auth methods

# Data Collection Rule (DCR) immutable ID
AZURE_DCR_RULE_ID=dcr-xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx  # Required for all auth methods

# Stream name from DCR
AZURE_DCR_STREAM_NAME=Custom-MyTable_CL  # Required for all auth methods
AZURE_TOKEN_CREDENTIALS=prod # Required only if DefaultAzureCredential is used in production

Prerequisites

Before using this SDK, you need:

  1. Log Analytics Workspace — Target for your logs
  2. Data Collection Endpoint (DCE) — Ingestion endpoint
  3. Data Collection Rule (DCR) — Defines schema and destination
  4. Custom Table — In Log Analytics (created via DCR or manually)

Authentication & Lifecycle

🔑 Two rules apply to every code sample below:

  1. Prefer DefaultAzureCredential. It works locally (Azure CLI / VS Code / Developer CLI) and in Azure (managed identity, workload identity) with no code change. Avoid connection strings, account/API keys — they bypass Entra audit and rotation.
    • Local dev: DefaultAzureCredential works as-is.
    • Production: set AZURE_TOKEN_CREDENTIALS=prod (or AZURE_TOKEN_CREDENTIALS=<specific_credential>) to constrain the credential chain to production-safe credentials.
  2. Wrap every client in a context manager so HTTP transports, sockets, and token caches are released deterministically:
    • Sync: with <Client>(...) as client:
    • Async: async with <Client>(...) as client: and async with DefaultAzureCredential() as credential: (from azure.identity.aio)

Snippets may abbreviate this setup, but production code should always follow both rules.

python
from azure.monitor.ingestion import LogsIngestionClient
from azure.identity import DefaultAzureCredential, ManagedIdentityCredential
import os

# Local dev: DefaultAzureCredential. Production: set AZURE_TOKEN_CREDENTIALS=prod or AZURE_TOKEN_CREDENTIALS=<specific_credential>
credential = DefaultAzureCredential(require_envvar=True)
# Or use a specific credential directly in production:
# See https://learn.microsoft.com/python/api/overview/azure/identity-readme?view=azure-python#credential-classes
# credential = ManagedIdentityCredential()

with LogsIngestionClient(
    endpoint=os.environ["AZURE_DCE_ENDPOINT"],
    credential=credential
) as client:
    # Use `client.upload(...)` for all subsequent operations (see examples below)
    ...

Upload Custom Logs

python
from azure.monitor.ingestion import LogsIngestionClient
from azure.identity import DefaultAzureCredential
import os

rule_id = os.environ["AZURE_DCR_RULE_ID"]
stream_name = os.environ["AZURE_DCR_STREAM_NAME"]

logs = [
    {"TimeGenerated": "2024-01-15T10:00:00Z", "Computer": "server1", "Message": "Application started"},
    {"TimeGenerated": "2024-01-15T10:01:00Z", "Computer": "server1", "Message": "Processing request"},
    {"TimeGenerated": "2024-01-15T10:02:00Z", "Computer": "server2", "Message": "Connection established"}
]

with LogsIngestionClient(
    endpoint=os.environ["AZURE_DCE_ENDPOINT"],
    credential=DefaultAzureCredential()
) as client:
    client.upload(rule_id=rule_id, stream_name=stream_name, logs=logs)

Upload from JSON File

python
import json

with open("logs.json", "r") as f:
    logs = json.load(f)

client.upload(rule_id=rule_id, stream_name=stream_name, logs=logs)

Custom Error Handling

Handle partial failures with a callback:

python
failed_logs = []

def on_error(error):
    print(f"Upload failed: {error.error}")
    failed_logs.extend(error.failed_logs)

client.upload(
    rule_id=rule_id,
    stream_name=stream_name,
    logs=logs,
    on_error=on_error
)

# Retry failed logs
if failed_logs:
    print(f"Retrying {len(failed_logs)} failed logs...")
    client.upload(rule_id=rule_id, stream_name=stream_name, logs=failed_logs)

Ignore Errors

python
def ignore_errors(error):
    pass  # Silently ignore upload failures

client.upload(
    rule_id=rule_id,
    stream_name=stream_name,
    logs=logs,
    on_error=ignore_errors
)

Async Client

python
import asyncio
from azure.monitor.ingestion.aio import LogsIngestionClient
from azure.identity.aio import DefaultAzureCredential

async def upload_logs():
    async with LogsIngestionClient(
        endpoint=endpoint,
        credential=DefaultAzureCredential()
    ) as client:
        await client.upload(
            rule_id=rule_id,
            stream_name=stream_name,
            logs=logs
        )

asyncio.run(upload_logs())

Sovereign Clouds

python
from azure.identity import AzureAuthorityHosts, DefaultAzureCredential
from azure.monitor.ingestion import LogsIngestionClient

# Azure Government
credential = DefaultAzureCredential(authority=AzureAuthorityHosts.AZURE_GOVERNMENT)
with LogsIngestionClient(
    endpoint="https://example.ingest.monitor.azure.us",
    credential=credential,
    credential_scopes=["https://monitor.azure.us/.default"]
) as client:
    # client.upload(...)
    ...

Batching Behavior

The SDK automatically:

  • Splits logs into chunks of 1MB or less
  • Compresses each chunk with gzip
  • Uploads chunks in parallel

No manual batching needed for large log sets.

Client Types

ClientPurpose
LogsIngestionClientSync client for uploading logs
LogsIngestionClient (aio)Async client for uploading logs

Key Concepts

ConceptDescription
DCEData Collection Endpoint — ingestion URL
DCRData Collection Rule — defines schema, transformations, destination
StreamNamed data flow within a DCR
Custom TableTarget table in Log Analytics (ends with _CL)
Show full SKILL.md (187 more words)Show less

DCR Stream Name Format

Stream names follow patterns:

  • Custom-<TableName>_CL — For custom tables
  • Microsoft-<TableName> — For built-in tables

Best Practices

  1. Pick sync OR async and stay consistent. Do not mix azure.xxx sync clients with azure.xxx.aio async clients in the same call path. Choose one mode per module.
  2. Always use context managers for clients and async credentials. Wrap every client in with Client(...) as client: (sync) or async with Client(...) as client: (async) to ensure proper cleanup. For async DefaultAzureCredential from azure.identity.aio, also use async with credential: so tokens and transports are cleaned up.
  3. Use DefaultAzureCredential for code that runs locally. Use a specific token credential for code that runs in Azure.
  4. Handle errors gracefully — use on_error callback for partial failures
  5. Include TimeGenerated — Required field for all logs
  6. Match DCR schema — Log fields must match DCR column definitions
  7. Use async client for high-throughput scenarios
  8. Batch uploads — SDK handles batching, but send reasonable chunks
  9. Monitor ingestion — Check Log Analytics for ingestion status

Reference Files

FileContents
references/capabilities.mdAdditional non-hero capabilities, operation-group coverage, and production checklists.
references/non-hero-scenarios.mdDedicated non-hero examples for secondary/advanced scenarios.

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .github/plugins/azure-sdk-python/skills/azure-monitor-ingestion-py of microsoft/skills.

  • SKILL.md
  • references/capabilities.md
  • references/non-hero-scenarios.md

Open the folder on GitHubat commit d5741a1

Compare with similar skills

Azure Monitor Ingestion Py next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Monitor Ingestion Py compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Monitor Ingestion Py this skillmicrosoft/skills3.1k—~2kAutomated safety check: PassMIT
Azure Carbon OptimizationMicrosoftDocs/Agent-Skills776—~837Automated safety check: PassCC-BY-4.0
Azure Architecture Autopilotgithub/awesome-copilot40k1 repos~1.9kAutomated safety check: PassMIT
Terraform Azurerm Set Diff Analyzergithub/awesome-copilot40k1 repos~547Automated safety check: PassMIT
Osmo Lerobot Trainingmicrosoft/physical-ai-toolchain126—~3.8kAutomated safety check: NotesMIT
Azure AI Deploytimothywarner-org/claude-code224—~731Automated safety check: NotesMIT

Similar skills

  • Azure Carbon Optimization

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure Carbon Optimization development including troubleshooting, security, and integrations & coding patterns.

    776 GitHub stars~837 tokensUpdated 5 days ago
    Backend & APIsAuto-check passed
  • Azure Architecture Autopilot

    github/awesome-copilot

    Official

    Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.

    40k GitHub starsUsed in 1 repo~1.9k tokens
    DevOps & CloudAuto-check passed
  • Official

    Analyze Terraform plan JSON output for AzureRM Provider to distinguish between false-positive diffs (order-only changes in Set-type attributes) and actual resource changes.

    40k GitHub starsUsed in 1 repo~547 tokens
    DevOps & CloudAuto-check passed
  • Osmo Lerobot Training

    microsoft/physical-ai-toolchain

    Official

    Submit, monitor, analyze, and evaluate LeRobot imitation learning training jobs on OSMO with Azure ML MLflow integration and inference evaluation - Brought to you by microsoft/physical-ai-toolchain

    126 GitHub stars~3.8k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Azure AI Deploy

    timothywarner-org/claude-code

    Ship a Python generative-AI app to Azure the keyless way, using DefaultAzureCredential and azd.

    224 GitHub stars~731 tokensUpdated 2 mo ago
    DevOps & CloudAuto-check: notes
  • Apex Azure Bicep Patterns

    jonathan-vella/apex

    UTILITY SKILL — Reusable Azure Bicep patterns: hub-spoke, private endpoints, diagnostics, AVM composition.

    217 GitHub stars~2.5k tokensUpdated today
    DevOps & CloudAuto-check passed

More from microsoft/skills

All 150 skills in this repo
  • Official

    Covers producer, consumer, and checkpoint-store setup for Azure Event Hubs streaming in Python, with Entra ID auth and partition targeting.

    3.1k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Official

    Builds podcast-style audio narration from text with Azure OpenAI's GPT Realtime Mini over WebSocket, from a Python FastAPI backend to a React player.

    3.1k GitHub starsUsed in 1 repo~947 tokens
    Auto-check passed
  • Frontend UI Dark TS

    microsoft/skills

    Official

    Build dark-themed React applications using Tailwind CSS with custom theming, glassmorphism effects, and Framer Motion animations.

    3.1k GitHub starsUsed in 5 repos~3.6k tokens
    Auto-check passed
  • Pydantic Models Py

    microsoft/skills

    Official

    Create Pydantic models following the multi-model pattern with Base, Create, Update, Response, and InDB variants.

    3.1k GitHub starsUsed in 5 repos~496 tokens
    Auto-check passed
  • Official

    Reference for building on Microsoft Foundry with the azure-ai-projects Python SDK: project clients, versioned agents, evaluations, connections, datasets and indexes.

    3.1k GitHub stars~2.8k tokensUpdated yesterday
    Auto-check passed
  • Skill Creator

    microsoft/skills

    Official

    Guide for creating effective skills for AI coding agents working with Azure SDKs and Microsoft Foundry services.

    3.1k GitHub starsUsed in 5 repos~17k tokens
    Auto-check passed

Categories

Questions about Azure Monitor Ingestion Py

What does Azure Monitor Ingestion Py do?

Azure Monitor Ingestion SDK for Python. An agent skill from microsoft/skills. Azure Monitor Ingestion Py is an agent skill from microsoft/skills, published by the product's own GitHub organization. Azure Monitor Ingestion SDK for Python.

When should I use Azure Monitor Ingestion Py?

Azure Monitor Ingestion Py fits situations like: sending custom logs to Log Analytics workspace via Logs Ingestion API.

How do I install Azure Monitor Ingestion Py in Claude Code?

Run `npx skills add microsoft/skills --skill azure-monitor-ingestion-py -a claude-code`. Or copy the skill folder (.github/plugins/azure-sdk-python/skills/azure-monitor-ingestion-py in microsoft/skills) into .claude/skills/azure-monitor-ingestion-py in your project. Claude Code loads it when a task matches its description.

How do I install Azure Monitor Ingestion Py in Codex?

Run `npx skills add microsoft/skills --skill azure-monitor-ingestion-py -a codex`. Or copy the skill folder (.github/plugins/azure-sdk-python/skills/azure-monitor-ingestion-py in microsoft/skills) into .agents/skills/azure-monitor-ingestion-py in your project. Codex loads it when a task matches its description.

Can I use Azure Monitor Ingestion Py in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/skills --skill azure-monitor-ingestion-py -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-monitor-ingestion-py, .gemini/skills/azure-monitor-ingestion-py, .github/skills/azure-monitor-ingestion-py and .opencode/skills/azure-monitor-ingestion-py in your project.

What does Azure Monitor Ingestion Py need to run?

Going by SKILL.md and its folder, Azure Monitor Ingestion Py needs the command-line tools its instructions call (pip) and credentials named AZURE_TOKEN_CREDENTIALS. Our summary lists: Python 3.

Does Azure Monitor Ingestion Py access the network?

SKILL.md names 2 domains. In commands or code: learn.microsoft.com and monitor.azure.us; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Azure Monitor Ingestion Py safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure Monitor Ingestion Py use?

Azure Monitor Ingestion Py is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Monitor Ingestion Py use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 988 tokens, read only when the agent opens those files.

What are the alternatives to Azure Monitor Ingestion Py?

Skills that share tags, products or a category with Azure Monitor Ingestion Py: Azure Carbon Optimization (MicrosoftDocs/Agent-Skills, 776 stars), Azure Architecture Autopilot (github/awesome-copilot, 40k stars), Terraform Azurerm Set Diff Analyzer (github/awesome-copilot, 40k stars) and Osmo Lerobot Training (microsoft/physical-ai-toolchain, 126 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Monitor Ingestion Py?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/skills, which has 3,097 GitHub stars. The repository holds 150 skills in this directory. The repository was last updated on October 9, 2026.

Source: microsoft/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.