Azure Data Explorer

Azure Data Explorer destination plugin

Azure Data Explorer (Kusto) is a cloud-based analytics service offered by Microsoft Azure. It's designed to help users analyze large amounts of data. Kusto uses a proprietary query language called KQL (Kusto Query Language) that enables users to perform complex data queries and visualizations. Kusto can be used for log and telemetry data analysis, as it is designed to handle large amounts of structured and unstructured data in real-time. Use the Azure Monitor Logs destination plugin to configure your Calyptia Core pipeline to send your logs and metrics data directly to Azure Data Explorer (Kusto).

Configuration parameters

The Azure Data Explorer (Kusto) destination plugin provides these configuration parameters.

General

KeyDescription
Tenant IDThe tenant/domain ID of the AAD registered application.
Client IDRequired - The client ID of the AAD registered application.
Ingestion EndpointThe clusters ingestion endpoint, usually in the form https://ingest-cluster\_name.region.kusto.windows.net.
Database NameThe database name.
Table NameThe table name.

Advanced

KeyDescription
Ingestion Mapping ReferenceThe name of a JSON ingestion mapping that will be used to map the ingested payload into the table columns.
Log KeyKey name of the log content.
Enable Tag KeyIf enabled, the tag is appended to output. The key name is used tag_key property.
Tag KeyOptional. Specify the key name where the tag is stored.
Enable Time KeyIf enabled, a timestamp is appended to output. The key name is used time_key property.
Time KeyOptional. Specify the key name where the timestamp is stored.

Security and TLS

KeyDescription
TLSEnable or disable TLS/SSL support.
TLS Certificate ValidationTurn TLS/SSL certificate validation on or off. TLS must be on for this setting to be enabled.
TLS Debug LevelSet TLS debug verbosity level. Accepts these values: 0 (No debug), 1 (Error), 2 (State change), 3 (Informational), 4 (Verbose).
CA Certificate File PathAbsolute path to CA certificate file.
Certificate File PathAbsolute path to certificate file.
Private key File PathAbsolute path to private key file.
Private Key Path PasswordOptional password for tls.key_file file.
TLS SNI Hostname ExtensionHostname to be used for TLS SNI extension.

The following are Advanced Networking configuration Parameters for Azure Data Explorer (Kusto) Destination Plugin.

KeyDescription
DNS ModeSelect the primary DNS connection type (TCP or UDP)
DNS ResolverSelect the primary DNS connection type (TCP or UDP)
Prefer IPv4Prioritize IPv4 DNS results when trying to establish a connection
KeepaliveEnable or disable Keepalive support
Keepalive Idle TimeoutSet maximum time allowed for an idle Keepalive connection
Max Connect TimeoutSet maximum time allowed to establish a connection, this time includes the TLS handshake
Max Connect Timeout Log ErrorOn connection timeout, specify if it should log an error. When disabled, the timeout is logged as a debug message
Max Keepalive RecycleSet maximum number of times a keepalive connection can be used before it is retired.
Source AddressSpecify network address to bind for data traffic