Azure Operations Management Suite Explained – Part 2

By Bala Murugesan, Microsoft Cloud Specialist, Data#3

In my previous blog post, I covered Azure Operations Management Suite (OMS) Log Analytics, which included the OMS overview, Architecture, and the list of solution packs and their functionalities. In this blog post, I will be covering how to setup OMS and also how to analyse and report on events through the Azure OMS Portal.

How to Setup OMS

OMS is incredibly easy to configure if there is an existing Azure tenancy although, be careful to select the right settings in the new Portal (ARM) and not the classic items from the old ASM portal.

Below are the required steps to setup OMS

Create an OMS Workspace

1. Login to the Azure Management Portal and Search for “Log Analytics (OMS)”.  Azure Operations Management Suite
2. Provide the appropriate details, including subscription, pay level and then create a workspace.  Azure Operations Management Suite

Connect Azure Storage to OMS Log Analytics

Before on-boarding an Azure storage account to OMS, the diagnostic logs need to be enabled on the VM so that the logs are stored on the allocated blob storage. Follow this article for more information on how to configure this but the general settings are below:

1. Browse to the OMS workspace on Azure portal. Click on the workspace – Settings – Storage and logs to point the OMS to the Storage locations where the VM diagnostics logs are stored. Azure Operations Management Suite
2. Choose a previously created Azure storage account.  Azure Operations Management Suite
3. Choose the logs that you want to analyse and the source table will get selected based on the type of data that you wish to analyse.  Azure Operations Management Suite
4. Click ok to save the settings.

Connect Azure Virtual Machine to OMS Log Analytics

To perform additional analysis, including configuration change tracking, SQL assessment and update assessment against VM’s, then head to the OMS dashboard and click on the Virtual machines blade.

1. This will query the list of virtual machines present in the tenancy where the OMS is created.  Azure Operations Management Suite
2. Click on the Virtual machine that you want to connect to  Azure Operations Management Suite
3. Click the connect button to connect the VM to OMS which will install an agent on the VM and the flow of analytics will start to OMS.  Azure Operations Management Suite
4. It may take a couple of minutes to connect but once it is connected you are good to go.
Now browse to OMS Portal and start searching and analysing the logs to your heart’s content.
 Azure Operations Management Suite

Lastly, it is worth mentioning the following dashboard that is part of the free OMS and shows the number of failed logins. Personally, I have configured an alert for this event every 15 minutes which works well and will let me know if anyone is trying to get into my tenant. This is not an instant alert though, considering the OMS logs needs to read the information from storage logs and report to the dashboard and then notify myself via email. It’s not instantaneous, but for a free package, it has plenty of potential and I would recommend setting this up wherever it is appropriate to give Azure administrators more visibility of their tenant.

Azure Operations Management Suite

That’s all for now. I hope you found my blog series useful. Feel free to reach out to me on LinkedIn if you would like to discuss any points mentioned.

Tags: Microsoft



Webinar: Data#3 Licensing Update and Microsoft 365 A5 Deep Dive
Data#3 Licensing Update and Microsoft 365 A5 Deep Dive

During the recent ISQ IT Managers forum, many schools expressed strong interest in a follow-up session on Microsoft 365…

Choose your own path to modern endpoint management

Accelerate your journey to modern endpoint management with Data#3 Through our interactive workshop and pilot program, Endpoint Management Launchpad…

Managing device fleets in a hybrid ecosystem

HP Device Services, delivered by Data#3, provide best-in-class endpoint management services to optimise today’s evolving workplace. Your organisation is…

Smart Space Technology is Leading the Fightback Against Rising Energy Costs

Just as the country hit winter, and even Queenslanders were spotted wearing long sleeves, the prospect of power…

Data#3 appoints John Tan to CCO
Data#3 appoints John Tan to newly created Chief Customer Officer position

July 13, 2022; Brisbane, Australia: Leading Australian technology services and solutions provider, Data#3, is delighted to announce that it has…

Meraki smart spaces
Smart Spaces: Changing Work for the Better

There’s a certain strangeness to heading back into the workplace after a lengthy spell working from home during lockdowns. Workers…

Customer Story: ElectraNet

ElectraNet cuts costs and increases visibility with technology intelligence solution Download Customer Story…

Customer Story: Victoria State Emergency Services

Decommissioning Legacy Server Environment Cuts Risk for Victoria State Emergency Service Download Customer Story…