Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Log Analytics Security View shows empty graphs sometimes #724

Open
EvgeniaMartynova opened this issue Aug 20, 2019 · 2 comments
Open

Log Analytics Security View shows empty graphs sometimes #724

EvgeniaMartynova opened this issue Aug 20, 2019 · 2 comments
Assignees

Comments

@EvgeniaMartynova
Copy link

Title

Log Analytics Security View shows empty graphs sometimes

Description

Log Analytics Security View shows empty graphs sometimes though corresponding Kusto query for the view gives non-empty result set.

Steps to reproduce

Setup Log Analytics and CA for multiple automation accounts as described on the page:
https://github.com/azsk/DevOpsKit-docs/tree/master/04-Continous-Assurance

Expected behavior

'Security Monitoring using the AzSK' dashboards shows graphs and tables corresponding to the scan results

Actual behavior

'Security Monitoring using the AzSK' dashboards shows sometimes empty graphs.
empty_dashboards
However if I click on the "see all" link below it shows non empty result set:
non-empty-result-set

@SINIKI
Copy link
Contributor

SINIKI commented Aug 23, 2019

Hello @EvgeniaMartynova:

Please follow the below steps and let me know if this resolves your issue.

Step 1: Check if the log analytics workspace has been set correctly. To verify follow this FAQ.

Step 2: If you are certain that events are being sent to the Log Analytics workspace but you are seeing blank views/no query results, you may need to extend the duration applicable to the queries. (This can be done using the 'Time range' selector next to the 'Run' button at the top of the query window.). Read more about this here.

@SINIKI SINIKI self-assigned this Aug 23, 2019
@EvgeniaMartynova
Copy link
Author

Hi Siniki,

The duration is not a problem.
This happens sometimes. I can see the scan logs stored under AzSK resource group, blob storage accounts. The logs sometimes not loaded to LogAnalytics.

In the CA scan logs I see sometimes an error that AzSK resource group is not found, I don't know whether it is related to the scan results not shown for some subscriptions from time to time in the LogAnalytics workspace.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants