SQL Audit logs in Azure Log Analytics and Azure Event Hubs

First published on MSDN on Sep 13, 2018

We are pleased to announce that Azure SQL Database Audit logs can now be written directly to Azure Log Analytics or Azure Event Hubs. This ability, now available in public preview, provides SQL Database Auditing customers with an easy way to centrally manage all of their log data, along with a rich set of tools for consuming and analyzing database audit logs at scale.

Azure Log Analytics

plays a central role in monitoring and management of your Azure environment. It enables collecting telemetry and other data from a variety of sources across Azure, and provides a query language and analytics engine for deep analysis and insights on the operation of applications and resources. For more information on the Log Analytics platform, see

What is Azure Log Analytics


With native support for saving SQL audit logs directly to Log Analytics, log data from all of your database resources can be gathered and stored in a single central location. The logs can now be analyzed using the rich analysis tools provided by the platform, which can provide deeper visibility and advanced cross-resource analytics.

In addition, SQL Server audit logs (from on-premises SQL Servers or SQL Servers on a VM) can also be collected in Log Analytics via OMS agent integration, as described in

this article

. Thus, you can manage and analyze all of your database audit logs, whether from the cloud or on-premises, in a single central location using the power of Azure Log Analytics.

Writing audit logs to Azure Log Analytics is as easy as selecting Log Analytics as a target in the Auditing configuration blade, whether configuring Auditing for the database server or for an individual database.

You can choose to write logs to an existing OMS workspace or create a new one. Once this option is configured, logs will be written directly to the OMS workspace where you can analyze them using Log Analytics. Take a look at this

tutorial for viewing and analyzing data collected in Log Analytics

to help get you started.

Azure Event Hubs

is a big data streaming platform and event ingestion service, which can be used to stream events and process them in real time. Learn more about building a big data pipeline with Event Hubs in the

Azure Event Hubs documentation


With audit logs being written directly to an Event Hub, you can stream events to any data analytics service whether inside or outside Azure. This enables you to build a processing system for online analysis of logs, including anomaly detection or other real time alerting.

As with Log Analytics, you can configure writing logs to an Event Hub by choosing this option in the configuration blade.

You also have the flexibility to configure any combination of Azure Storage, Log Analytics and Event Hubs to store your SQL audit logs.

Please note

that using Event hubs or Log Analytics as targets for audit logs at the server level is currently not supported for secondary geo-replicated databases.

For more details on working with Auditing for Azure SQL Database, take a look at the

Auditing Getting Started documentation


Try it out and let us know what you think!

SQL Security team

Leave a Reply

Your email address will not be published. Required fields are marked *


This site uses Akismet to reduce spam. Learn how your comment data is processed.