OMS InsightAnalytics L300
OMS InsightAnalytics L300
Any cloud
Analytics
Deep Dive
Any platform
L300
Operational excellence
with Insight & Analytics
Fast
Simple and Gain
troubleshoot
unified immediate
and auto
experience insight
remediate
Simple and unified experience
Challenges
Individual
monitoring
Platform and
Application
monitoring tool
Network
monitoring tool Individual
monitoring
Security
analysis tool
Individual
monitoring
On premises Application data
datacenter
Platform data
Network data
Security data
Individual Hosters
monitoring
Simple and unified experience
Solution
Individual
monitoring
Platform and
Platform and
Application
monitoring tool Application IT
monitoring Operational
Network excellence
monitoring tool Individual
monitoring
Security
analysis tool
Individual
Application data Security Network monitoring
Security data
Individual Hosters
monitoring
Simple and unified experience UNIFIED
EXPERIENCE
Expand your enterprise management with a consistent experience
• Single pane of control • Integrate with existing systems • Control from anywhere
• Unified experience • Connect with isolated resources • Consistent user interface
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Windows agents
• Log Analytics
SCOM
• Automation
• Site Recovery
Linux / FluentD • Backup
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Windows agents
Connect to Windows computers in your on-premises infrastructure directly to OMS workspaces by using a
customized version of the Microsoft Monitoring Agent (MMA).
https://azure.microsoft.com/en-us/documentation/articles/log-analytics-windows-agents/
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
SCOM
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Linux / FluentD
Collect and act on data generated from Linux computers. Adding data collected from Linux to OMS allows you to
manage Linux systems and container solutions like Docker regardless of where your computers are located—virtually
anywhere.
Upload data
(HTTPS)
syslog
Firewall/proxy
Nagios
OMS Service
Zabbix
Providers
Docker
Pull configuration
(https)
Linux Computer
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Linux / FluentD
5.x 32/64-bit
2013.09 – 2015.09 6.x 32/64-bit
7.x 64-bit
12.x 32/64-bit alpha
14.x 32/64-bit beta
15.x 32/64-bit stable
16.x 32/64-bit
10.x 32/64-bit
5.x 32/64-bit
11.x 32/64-bit
6.x 32/64-bit
12.x 64-bit
7.x 64-bit
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Leverage REST collection API to ingest custom data to Operations Management Suite
API
Log Search API
Ensure json is flattened and not nested • Create, manage and run searches
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Leverage existing
management platform
Do not rip and replace by Operations Management Suite
leveraging your management Gateway to connect with isolated
platform such as System Center, environment
Zabbix or Nagios
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
1. On the Operations
Management Suite
Onboarding Wizard:
associate with your OMS
subscription
https://azure.microsoft.com/en-us/documentation/articles/log-analytics-om-agents/
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
2. Modify the
omsagent.confconfiguration file
(/etc/opt/microsoft/omsagent/conf
/omsagent.conf).
https://azure.microsoft.com/en-us/documentation/articles/log-analytics-linux-agents/
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Business
Platform and owners?
Application
monitoring
Application
owners?
Security Network
analysis monitoring
Infrastructure
owners?
Gain immediate insight
Solution
Business
owners
Application
owners
Infrastructure
owners
Intelligence
Engine
Gain immediate insight UNIFIED
on trusted sources.
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Quick data
collection
Automatic end point data selection Custom log collection including
and collection Windows and Linux
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
https://azure.microsoft.com/en-us/documentation/articles/log-analytics-data-sources/
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
https://azure.microsoft.com/en-us/documentation/articles/log-analytics-data-sources-custom-logs/
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
https://blogs.technet.microsoft.com/msoms/2016/08/24/announcing-public-preview-oms-container-solution-for-linux/
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Two types of installation methods to support different operating system types, such as CoreOS.
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Experienced
sources of insight
Single source of truth, gathering Correlate and analyze through
data from public cloud, private Knowledge obtained by the trusted
cloud, traditional datacenters source such as product team, support
team, MSIT, Digital Crime Unit
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Solutions
Log Analytics solutions are a collection of logic, visualization and data acquisition rules that provide
metrics pivoted around a particular problem area.
https://azure.microsoft.com/en-us/documentation/articles/log-analytics-add-solutions/
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Solutions
Data collection details for OMS features and solutions
Alerts (Operations
Windows 3 minutes
Manager)
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Solutions
Data collection details for OMS features and solutions
SCOM agent data sent
Data type Platform Direct Agent SCOM agent Azure Storage SCOM required? Collection frequency
via management group
Network Application
Windows 10 minutes
Gateways
Network Security
Windows 10 minutes
Groups
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
SCSI/Disk
VM ESXi ESXi …
Status and
Activities Events Failure
Error
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Solutions
Example of JSON for Solution document
{
"name":“MySolution",
"location":"eastus",
"properties": {
"sourceLink": {
"contentUrl":"http://mystorageaccount.blob.core.windows.net/templates/SolutionTemplate.json",
"solutionVersion":"1.0.0."
} "managedResources":[{
"key":"Microsoft.Automation/AutomationAccount",
"resourceGroupName":"rg1",
"templateLink": {
"uri": "http://mystorageaccount.blob.core.windows.net/templates/template.json",
"contentVersion": "1.0.0.0"
}, }, {
…
}], "referencedResources":[ {
"id":”resourceGroups/{rgName}/providers/Microsoft.Automation/automationAccount/{accountName}/
credentials/{credName}”,
}, { } }
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
C# binding
PS binding
Ingestion
AWS CW API OMS
API
Python binding
Ruby binding
JS
AWS
OMS
AWS I/P transfor
O/P
plugin m
plugin
plugin Java
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Ingestio
AWS CW API OMS
n API
CW Azure Integration
Function Service
CW Azure
Automation
CW Lambda
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Ingestio
AWS CW API OMS
n API
CW Integration
Web Service Service
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Analyze petabytes of
data from the cloud
Infrastructure free, On the fly metrics PowerBI integration
management as a aggregation
service
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
View designer
Create visual tiles based on searches
Assemble tiles on a dashboard
View Designer editing Overview Tile to show custom service’s front-end custom events and performance data
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
View designer
Create visual tiles based on searches
Assemble tiles on a dashboard
Complete with metrics visualized in line charts, distributions of event levels for my service, and the amount of data getting
for both types of events. Each visualization can drill down into OMS Log search.
Simple and Gain Fast
unified immediate troubleshoot
experience insight and auto
remediate
Fast troubleshoot and auto remediate
Challenges
Platform and
Application
monitoring
Security Network
analysis monitoring
Platform and
Application
monitoring
Filter alerts Professional knowledge
Automated
Problem
process
solved
Fast troubleshoot and auto remediate UNIFIED
Solve issues as quickly as possible in an automated fashion to improve EXPERIENCE
your SLA
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Alert management
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Alert management
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Alert management
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Alert management
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Alert management
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Alert management
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Community based
automation
Leverage PowerShell community for automating via PowerShell based runbooks
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Auto remediate
Leverage automation Connect existing alerts
from the cloud to auto remediate
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Fast
Simple and Gain
troubleshoot
unified immediate
and auto
experience insight
remediate