MCP Log Analytics
Exposes Azure Log Analytics workspace data with tools for querying AuditLogs and AzureActivity tables, supporting custom KQL queries, time range filters, and pagination.
README
MCP Server for Azure Log Analytics
A Model Context Protocol (MCP) server that exposes Azure Log Analytics workspace data, with specific support for AuditLogs and AzureActivity tables.
Features
- Separate tools for querying AuditLogs and AzureActivity tables
- Custom KQL queries with flexible filtering
- Time range filters with human-readable format (24h, 7d, 30d)
- Pagination support for large result sets
- DefaultAzureCredential authentication (CLI, Managed Identity, Service Principal)
- Docker support for containerized deployment
- Comprehensive unit tests
Prerequisites
- Python 3.9+
- Azure Log Analytics workspace
- Azure CLI (for local development) or Managed Identity (for production)
Installation
- Clone the repository
- Create a virtual environment:
python -m venv venv - Activate the virtual environment:
- Windows (PowerShell):
venv\Scripts\Activate.ps1 - Windows (cmd):
venv\Scripts\activate.bat - Linux/Mac:
source venv/bin/activate
- Windows (PowerShell):
- Install dependencies:
pip install -r requirements.txt
Configuration
Set the following environment variables:
AZURE_LOG_ANALYTICS_WORKSPACE_ID(required): Your Log Analytics workspace IDAZURE_TENANT_ID(optional): Azure tenant ID for service principalAZURE_CLIENT_ID(optional): Service principal client IDAZURE_CLIENT_SECRET(optional): Service principal client secret
Usage
The MCP server communicates via stdio and is designed to be used with MCP clients like VS Code (GitHub Copilot) or Claude Desktop.
Quick Start with VS Code (GitHub Copilot)
-
Create or edit:
%APPDATA%\Code\User\globalStorage\github.copilot\mcp-settings.json{ "mcpServers": { "azure-log-analytics": { "command": "C:\\dev\\sre-agent\\mcp-log-analytics\\venv\\Scripts\\python.exe", "args": ["-m", "src.server"], "cwd": "C:\\dev\\sre-agent\\mcp-log-analytics", "env": { "AZURE_LOG_ANALYTICS_WORKSPACE_ID": "your-workspace-id" } } } } -
Restart VS Code
-
Use Copilot Chat to query your logs:
@azure-log-analytics Show me audit logs from the last 24 hours@azure-log-analytics Find failed operations in Azure Activity logs this week
For detailed VS Code setup and troubleshooting, see VSCODE-USAGE.md
Development
Install development dependencies:
pip install -r requirements-dev.txt
Run tests:
pytest
Docker
Build the image:
docker build -t mcp-log-analytics .
Run the container:
docker run -e AZURE_LOG_ANALYTICS_WORKSPACE_ID=<workspace-id> mcp-log-analytics
Documentation
- VSCODE-USAGE.md - Complete VS Code & GitHub Copilot setup guide
- DESIGN.md - Architecture and design documentation
- CONTRIBUTING.md - Development and contribution guidelines
License
MIT
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.