Service Azure Monitor utilisé pour collecter, analyser et exploiter les données de télémétrie des environnements Azure et locaux.
Hello Dijoux-Brezot Thibaut,
It sounds like you're issue with the Azure Monitor Agent (AMA) on your Windows VM. Since you've got two identical VMs and only one is successfully sending logs to your Log Analytics Workspace, there are a few things we can check to troubleshoot the issue further.
Given your detailed diagnostics, here are some steps you can take to investigate what's happening with the silent VM:
- Check Extension Status: Ensure that the Azure Monitor Agent extension is properly installed and provisioned on the VM. You can do this from the Azure portal by navigating to your VM and checking in the Extensions + applications section. If it's not listed or shows provisioning errors, you may need to reinstall it.
- Validate Network Connectivity: Since you have already confirmed connectivity with
Test-NetConnection, make sure that your firewall settings are not blocking any required endpoints. Specifically, ensure that the following endpoints are whitelisted:-
*.ods.opinsights.azure.com -
*.oms.opinsights.azure.com -
*.blob.core.windows.net -
*.azure-automation.net
-
- Configuration of Data Collection Rule (DCR): Verify that the Data Collection Rule associated with both VMs is configured correctly. Sometimes, a slight misconfiguration or a missing setting can cause one VM to not send data.
- Check Heartbeat Data: Run a query in your Log Analytics Workspace to check if the silent VM is indeed sending heartbeat data. You can use the following Kusto query:
ReplaceHeartbeat | where Computer contains "<VM_NAME>" | where TimeGenerated > ago(1d)<VM_NAME>with the name of your silent VM. If you don't see any results, there might be an issue with the agent's ability to connect and report. - Examine Agent Logs: Beyond the Event Viewer, you can check the specific agent log files located at:
-
C:\ProgramData\Microsoft\Azure\AzureMonitor\Logs\
MonAgentCore.exeis failing to transmit data. -
- Review Managed Identity Configuration: Even though you confirmed that the Managed Identity is enabled and an Access Token can be retrieved, double-check if there are any specific IAM roles that the silent VM might be missing that are necessary for logging.
If you've gone through these troubleshooting steps and the issue persists, it might be helpful to gather the following additional information to provide a more tailored solution:
- Can you confirm that both VMs have the same version of the Azure Monitor Agent installed?
- Are there any specific errors or warnings logged in the agent log files that you've checked?
- Have you tried any additional testing, such as temporarily disabling any security features (like antivirus or additional firewalls) to see if that changes anything?
References:
Hope this helps! Let me know if you need any more information or if you have other questions. Thanks