{"id":541,"date":"2018-08-12T00:22:20","date_gmt":"2018-08-12T00:22:20","guid":{"rendered":"http:\/\/www.ciraltos.com\/?p=541"},"modified":"2018-08-12T00:22:20","modified_gmt":"2018-08-12T00:22:20","slug":"azure-machine-learning-in-log-analytics","status":"publish","type":"post","link":"https:\/\/www.ciraltos.com\/staging2\/azure-machine-learning-in-log-analytics\/","title":{"rendered":"Azure Machine Learning in Log Analytics"},"content":{"rendered":"<h1><img decoding=\"async\" loading=\"lazy\" class=\" wp-image-462 alignleft\" src=\"\/wp-content\/uploads\/2018\/04\/OMS_Icon-300x158.png\" alt=\"\" width=\"290\" height=\"153\" srcset=\"https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2018\/04\/OMS_Icon-300x158.png 300w, https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2018\/04\/OMS_Icon.png 600w\" sizes=\"(max-width: 290px) 100vw, 290px\" \/>Machine Learning with Log Analytics<\/h1>\n<p>Machine Learning and Artificial Intelligence are all the rage and for good reason.\u00a0 While static grouping and sorting in Azure Log Analytics can help you break down data and find the source of issues, Machine Learning can point out issues or unusual relationships you may not even be aware of.\u00a0\u00a0 It does this by identifying patterns that are not obvious or by detecting differences in data sets.\u00a0 In this post I go over the basics of the Basket, Autocluster and Diffpatterns Machine Learning queries that can be use in Azure Log Analytics, Azure Application Insight or Azure Security Center.<!--more--><\/p>\n<p>I have to admit that I\u2019m not a data scientist.\u00a0 The full potential of Machine Learning in Log Analytics is beyond what I can blog about.\u00a0 However, by applying the information below I was able to find that 29% of all Event Logs in a production environment were coming from one server and source.\u00a0 The issue was identified and quickly fixed based off this information machine learning provided.\u00a0 My intention is to pass along what I have learned so others can take advantage of Machine Learning.<\/p>\n<h2>The Basket Command<\/h2>\n<p>The Basket command finds patterns in data and returns all patterns based on a given threshold.\u00a0 This command leverages the Market Basket Analysis algorithm used by retailers to find associations between items customers purchase.\u00a0 For example, given 1000 different shopping carts, or \u201cbaskets\u201d, what is the most frequent pattern of items purchased.<\/p>\n<p>Applied to Log Analytics, Basket finds associations between records in a set of results.\u00a0 This opens the door to discovering different combinations of events that may not have been found or event considered using static searches.\u00a0 In the example below, I walk through a Basket search on Security Events to find interesting relationships.<\/p>\n<p>First, I will run a quick search against the SecurityEvents table to identify the columns I want to analyze.<\/p>\n<pre>SecurityEvent\r\n| where TimeGenerated &gt;= ago(1h)<\/pre>\n<p>Out of the returned values, I project Account, Computer, Activity and logonTypeName.\u00a0 Projecting these values limits the data fields that will be evaluated.\u00a0 Once set, the results are piped to a command that evaluates the results with the basket command.\u00a0 I also change the evaluation time from one hour to one day.\u00a0 The complete command looks like this:<\/p>\n<pre>SecurityEvent\r\n| where TimeGenerated &gt;= ago(1d)\r\n| project Account\r\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0  , Computer\r\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 , Activity\r\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 , LogonTypeName\r\n| evaluate basket()<\/pre>\n<p>The results from the Log Analytics demo site are shown below.\u00a0 One item that stands out right away is the number of failed administrator account logins from the network indicated in SegmentId 2.<\/p>\n<p><a href=\"\/wp-content\/uploads\/2018\/08\/Image1.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter wp-image-557 size-full\" src=\"\/wp-content\/uploads\/2018\/08\/Image1.png\" alt=\"Machine Learning Azure Log Analytics\" width=\"1086\" height=\"572\" srcset=\"https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2018\/08\/Image1.png 1086w, https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2018\/08\/Image1-300x158.png 300w, https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2018\/08\/Image1-768x405.png 768w, https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2018\/08\/Image1-1024x539.png 1024w\" sizes=\"(max-width: 1086px) 100vw, 1086px\" \/><\/a><\/p>\n<p>The Basket command has a few optional arguments that can tweak the output of the command.\u00a0 One of them is the Threshold.\u00a0 Threshold sets the minimal ratio of rows considered as frequent.\u00a0 Essentially, the lower the number the more rows returned.\u00a0 The value is a double less than 1, with the default set to 0.05.\u00a0 For example, at default my example returns 24 rows, changing to 0.03 returns 45.\u00a0 More information on the different arguments can be found <a href=\"https:\/\/docs.loganalytics.io\/docs\/Language-Reference\/Machine-Learning-and-Time-Series-Analysis\/basket\" target=\"_blank\" rel=\"noopener\">here<\/a><\/p>\n<pre>SecurityEvent\r\n| where TimeGenerated &gt;= ago(1d)\r\n| project Account\r\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 , Computer\r\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 , Activity\r\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 , LogonTypeName\r\n| evaluate basket(0.03)<\/pre>\n<p><a href=\"\/wp-content\/uploads\/2018\/08\/Image2.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter wp-image-552 size-full\" src=\"\/wp-content\/uploads\/2018\/08\/Image2.png\" alt=\"Log Analytics Machine Learning\" width=\"966\" height=\"542\" srcset=\"https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2018\/08\/Image2.png 966w, https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2018\/08\/Image2-300x168.png 300w, https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2018\/08\/Image2-768x431.png 768w\" sizes=\"(max-width: 966px) 100vw, 966px\" \/><\/a><\/p>\n<h2>The Autocluster Command<\/h2>\n<p>While the Basket command finds all frequent patterns in data, Autocluster finds frequent patterns in the data and reduces the results to a smaller number of patterns.\u00a0 This works well for analyzing data like Event Logs to focus on more frequent patterns.\u00a0 In the example below, I run Autocluster against the Update table for the past 24 hours.\u00a0 Below is the output.<\/p>\n<pre>Update\r\n| where TimeGenerated &gt;= ago(1d)\r\n| project Computer\r\n        , UpdateState\r\n        , Product\r\n        , OSType\r\n| evaluate autocluster()<\/pre>\n<p><a href=\"\/wp-content\/uploads\/2018\/08\/Image3.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter wp-image-553 size-full\" src=\"\/wp-content\/uploads\/2018\/08\/Image3.png\" alt=\"Machine Learning Azure Log Analytics\" width=\"854\" height=\"425\" srcset=\"https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2018\/08\/Image3.png 854w, https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2018\/08\/Image3-300x149.png 300w, https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2018\/08\/Image3-768x382.png 768w\" sizes=\"(max-width: 854px) 100vw, 854px\" \/><\/a><\/p>\n<p>You can see that it only returned two rows.\u00a0 Like Threshold in the Basket command, Autocluster has a SizeWeight argument.\u00a0 SizeWeight adjusts the balance between generic results with a smaller number of rows returned and more refined results with a higher number of distinct patterns.\u00a0 The value is a double less than 1.\u00a0 You can get more details and the additional parameters <a href=\"https:\/\/docs.loganalytics.io\/docs\/Language-Reference\/Machine-Learning-and-Time-Series-Analysis\/autocluster\" target=\"_blank\" rel=\"noopener\">here<\/a>.<\/p>\n<p>In the example below, I run the same command, changing the sizeWeight from the default of 0.5 to 0.1.\u00a0 With that change 10 rows are returned with a more informative breakdown of the computers needing updates.<\/p>\n<p><a href=\"\/wp-content\/uploads\/2018\/08\/Image4.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter wp-image-554 size-full\" src=\"\/wp-content\/uploads\/2018\/08\/Image4.png\" alt=\"Machine Learning Azure Log Analytics\" width=\"824\" height=\"573\" srcset=\"https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2018\/08\/Image4.png 824w, https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2018\/08\/Image4-300x209.png 300w, https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2018\/08\/Image4-768x534.png 768w\" sizes=\"(max-width: 824px) 100vw, 824px\" \/><\/a><\/p>\n<h2>The Diffpatterns Command<\/h2>\n<p>Diffpatterns finds differences in data sets of the same structure.\u00a0 While the other commands try to find relationships, Diffpatterns finds differences in a dataset.\u00a0 Quite Honestly, I find this one is easier demonstrated than explained.<\/p>\n<p>I set out to view the difference between Errors and Warnings in the Event Log in this example.\u00a0 This is done by starting a query setting the time, filtering the EventLevelName to return two items, Error and Warning and projecting EventLevelName and Computer.<\/p>\n<p>Next comes the evaluate diffpatterns() command.\u00a0 This command requires three arguments.\u00a0 The first is SplitColumn, or the column with data to be compared.\u00a0 Next is SplitValueA, or the first value specified for comparison.\u00a0 The value is represented as a string and considered data set A.\u00a0 In this query, data set A represents Warning.<\/p>\n<p>The last required argument is SplitValueB.\u00a0 This is the second set of data compared and represents Error as data set B in the results.\u00a0 Below is the full query.<\/p>\n<pre>Event\r\n| where TimeGenerated &gt;= ago(7d)\r\nand EventLevelName == \"Warning\" or EventLevelName == \"Error\"\r\n| project EventLevelName\r\n        , Computer\r\n| evaluate diffpatterns(EventLevelName, \"Warning\", \"Error\")<\/pre>\n<p>The output gives the percent difference between Warning (PercentA) and Error (PercentB) as represented by computer under the PercentDiffAB column.<\/p>\n<p><a href=\"\/wp-content\/uploads\/2018\/08\/Image5.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter wp-image-555 size-full\" src=\"\/wp-content\/uploads\/2018\/08\/Image5.png\" alt=\"\" width=\"939\" height=\"426\" srcset=\"https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2018\/08\/Image5.png 939w, https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2018\/08\/Image5-300x136.png 300w, https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2018\/08\/Image5-768x348.png 768w\" sizes=\"(max-width: 939px) 100vw, 939px\" \/><\/a><\/p>\n<p>Here is another diffpatterns query for illustration.\u00a0 This time with the SecurtyEvent table.\u00a0 I am comparing Event number 4624 and 4625, Windows login success and failure.<\/p>\n<p>Two things stand out about this command.\u00a0 First, the event ID\u2019s are an integer, but have been evaluated as a string, surrounding them with quotes.\u00a0 This is because a string is required for the split data.<\/p>\n<p>Also, the first 3 arguments (SplitColumn, SplitValueA and SplitValueB) are required, but the command accepts additional optional arguments.\u00a0 These parameters are positional, use the \u201c~\u201d as a Null or Default value.\u00a0 In the example below, the 4<sup>th<\/sup> value is WeightColumn, I don\u2019t want to modify that value so I added a \u201c~\u201d.\u00a0 The fifth value is threshold (similar to threshold in the Basket command).\u00a0 Below, the value changed from the default of 0.05 to 0.02.<\/p>\n<pre>SecurityEvent\r\n| where TimeGenerated &gt;= ago(1d)\r\nand EventID == 4624 or EventID == 4625\r\n| project Account\r\n        , Computer\r\n        , EventID\r\n        , Activity\r\n| evaluate diffpatterns(EventID, \"4624\", \"4625\", \"~\", 0.02)<\/pre>\n<p>In this example we can see there was a 23.28% difference between success (PercentA) and failed (PercentB) logins for computer\u00a0ContosoSQLSrv1<\/p>\n<p><a href=\"\/wp-content\/uploads\/2018\/08\/Image6.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter wp-image-556 size-full\" src=\"\/wp-content\/uploads\/2018\/08\/Image6.png\" alt=\"Machine Learning Azure Log Analytics\" width=\"1387\" height=\"585\" srcset=\"https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2018\/08\/Image6.png 1387w, https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2018\/08\/Image6-300x127.png 300w, https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2018\/08\/Image6-768x324.png 768w, https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2018\/08\/Image6-1024x432.png 1024w\" sizes=\"(max-width: 1387px) 100vw, 1387px\" \/><\/a><\/p>\n<p>More information on the Difpatterns command and attributes are located <a href=\"https:\/\/docs.loganalytics.io\/docs\/Language-Reference\/Machine-Learning-and-Time-Series-Analysis\/diffpatterns\" target=\"_blank\" rel=\"noopener\">here<\/a>.<\/p>\n<p>If you would like to learn more about querying in Azure Log Analytics I recommend the Pluralsight course on the Kusto Query Language (KQL).\u00a0 Microsoft is offering the course for free at the time of writhing this post.<\/p>\n<p><a href=\"https:\/\/techcommunity.microsoft.com\/t5\/Azure-Log-Analytics\/ANNOUNCEMENT-free-query-language-course-now-available\/td-p\/207753\" target=\"_blank\" rel=\"noopener\">https:\/\/techcommunity.microsoft.com\/t5\/Azure-Log-Analytics\/ANNOUNCEMENT-free-query-language-course-now-available\/td-p\/207753<\/a><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Machine Learning with Log Analytics Machine Learning and Artificial Intelligence are all the rage and for good reason.\u00a0 While static grouping and sorting in Azure Log Analytics can help you break down data and find the source of issues, Machine Learning can point out issues or unusual relationships you may not even be aware of.\u00a0\u00a0 &hellip;<\/p>\n<p class=\"read-more\"> <a class=\"\" href=\"https:\/\/www.ciraltos.com\/staging2\/azure-machine-learning-in-log-analytics\/\"> <span class=\"screen-reader-text\">Azure Machine Learning in Log Analytics<\/span> Read More &raquo;<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"default","ast-global-header-display":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":""},"categories":[2],"tags":[250,247,251,9,202,249,248],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Azure Machine Learning in Log Analytics - ciraltos<\/title>\n<meta name=\"description\" content=\"In this post I go over the basics of the Basket, Autocluster and Diffpatterns Machine Learning queries that can be use in Azure Log Analytics, Azure Application Insight or Azure Security Center.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.ciraltos.com\/staging2\/azure-machine-learning-in-log-analytics\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Azure Machine Learning in Log Analytics - ciraltos\" \/>\n<meta property=\"og:description\" content=\"In this post I go over the basics of the Basket, Autocluster and Diffpatterns Machine Learning queries that can be use in Azure Log Analytics, Azure Application Insight or Azure Security Center.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.ciraltos.com\/staging2\/azure-machine-learning-in-log-analytics\/\" \/>\n<meta property=\"og:site_name\" content=\"ciraltos\" \/>\n<meta property=\"article:published_time\" content=\"2018-08-12T00:22:20+00:00\" \/>\n<meta name=\"author\" content=\"Travis Roberts\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@ciraltos\" \/>\n<meta name=\"twitter:site\" content=\"@ciraltos\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Travis Roberts\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.ciraltos.com\/staging2\/azure-machine-learning-in-log-analytics\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.ciraltos.com\/staging2\/azure-machine-learning-in-log-analytics\/\"},\"author\":{\"name\":\"Travis Roberts\",\"@id\":\"https:\/\/www.ciraltos.com\/staging2\/#\/schema\/person\/25391996d6cddfecd4d257162b7e373a\"},\"headline\":\"Azure Machine Learning in Log Analytics\",\"datePublished\":\"2018-08-12T00:22:20+00:00\",\"dateModified\":\"2018-08-12T00:22:20+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.ciraltos.com\/staging2\/azure-machine-learning-in-log-analytics\/\"},\"wordCount\":1038,\"commentCount\":1,\"publisher\":{\"@id\":\"https:\/\/www.ciraltos.com\/staging2\/#\/schema\/person\/25391996d6cddfecd4d257162b7e373a\"},\"keywords\":[\"ai\",\"application insight\",\"Artificial Intelligence\",\"Azure\",\"Log Analytics\",\"machine learning\",\"security center\"],\"articleSection\":[\"Azure\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.ciraltos.com\/staging2\/azure-machine-learning-in-log-analytics\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.ciraltos.com\/staging2\/azure-machine-learning-in-log-analytics\/\",\"url\":\"https:\/\/www.ciraltos.com\/staging2\/azure-machine-learning-in-log-analytics\/\",\"name\":\"Azure Machine Learning in Log Analytics - ciraltos\",\"isPartOf\":{\"@id\":\"https:\/\/www.ciraltos.com\/staging2\/#website\"},\"datePublished\":\"2018-08-12T00:22:20+00:00\",\"dateModified\":\"2018-08-12T00:22:20+00:00\",\"description\":\"In this post I go over the basics of the Basket, Autocluster and Diffpatterns Machine Learning queries that can be use in Azure Log Analytics, Azure Application Insight or Azure Security Center.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.ciraltos.com\/staging2\/azure-machine-learning-in-log-analytics\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.ciraltos.com\/staging2\/azure-machine-learning-in-log-analytics\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.ciraltos.com\/staging2\/azure-machine-learning-in-log-analytics\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.ciraltos.com\/staging2\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Azure Machine Learning in Log Analytics\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.ciraltos.com\/staging2\/#website\",\"url\":\"https:\/\/www.ciraltos.com\/staging2\/\",\"name\":\"ciraltos\",\"description\":\"cloud, technology and trends\",\"publisher\":{\"@id\":\"https:\/\/www.ciraltos.com\/staging2\/#\/schema\/person\/25391996d6cddfecd4d257162b7e373a\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.ciraltos.com\/staging2\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\/\/www.ciraltos.com\/staging2\/#\/schema\/person\/25391996d6cddfecd4d257162b7e373a\",\"name\":\"Travis Roberts\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.ciraltos.com\/staging2\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2023\/03\/Logo-1.png\",\"contentUrl\":\"https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2023\/03\/Logo-1.png\",\"width\":5657,\"height\":3563,\"caption\":\"Travis Roberts\"},\"logo\":{\"@id\":\"https:\/\/www.ciraltos.com\/staging2\/#\/schema\/person\/image\/\"},\"sameAs\":[\"http:\/\/www.ciraltos.com\",\"https:\/\/twitter.com\/ciraltos\"],\"url\":\"https:\/\/www.ciraltos.com\/staging2\/author\/admin\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Azure Machine Learning in Log Analytics - ciraltos","description":"In this post I go over the basics of the Basket, Autocluster and Diffpatterns Machine Learning queries that can be use in Azure Log Analytics, Azure Application Insight or Azure Security Center.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.ciraltos.com\/staging2\/azure-machine-learning-in-log-analytics\/","og_locale":"en_US","og_type":"article","og_title":"Azure Machine Learning in Log Analytics - ciraltos","og_description":"In this post I go over the basics of the Basket, Autocluster and Diffpatterns Machine Learning queries that can be use in Azure Log Analytics, Azure Application Insight or Azure Security Center.","og_url":"https:\/\/www.ciraltos.com\/staging2\/azure-machine-learning-in-log-analytics\/","og_site_name":"ciraltos","article_published_time":"2018-08-12T00:22:20+00:00","author":"Travis Roberts","twitter_card":"summary_large_image","twitter_creator":"@ciraltos","twitter_site":"@ciraltos","twitter_misc":{"Written by":"Travis Roberts","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.ciraltos.com\/staging2\/azure-machine-learning-in-log-analytics\/#article","isPartOf":{"@id":"https:\/\/www.ciraltos.com\/staging2\/azure-machine-learning-in-log-analytics\/"},"author":{"name":"Travis Roberts","@id":"https:\/\/www.ciraltos.com\/staging2\/#\/schema\/person\/25391996d6cddfecd4d257162b7e373a"},"headline":"Azure Machine Learning in Log Analytics","datePublished":"2018-08-12T00:22:20+00:00","dateModified":"2018-08-12T00:22:20+00:00","mainEntityOfPage":{"@id":"https:\/\/www.ciraltos.com\/staging2\/azure-machine-learning-in-log-analytics\/"},"wordCount":1038,"commentCount":1,"publisher":{"@id":"https:\/\/www.ciraltos.com\/staging2\/#\/schema\/person\/25391996d6cddfecd4d257162b7e373a"},"keywords":["ai","application insight","Artificial Intelligence","Azure","Log Analytics","machine learning","security center"],"articleSection":["Azure"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.ciraltos.com\/staging2\/azure-machine-learning-in-log-analytics\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.ciraltos.com\/staging2\/azure-machine-learning-in-log-analytics\/","url":"https:\/\/www.ciraltos.com\/staging2\/azure-machine-learning-in-log-analytics\/","name":"Azure Machine Learning in Log Analytics - ciraltos","isPartOf":{"@id":"https:\/\/www.ciraltos.com\/staging2\/#website"},"datePublished":"2018-08-12T00:22:20+00:00","dateModified":"2018-08-12T00:22:20+00:00","description":"In this post I go over the basics of the Basket, Autocluster and Diffpatterns Machine Learning queries that can be use in Azure Log Analytics, Azure Application Insight or Azure Security Center.","breadcrumb":{"@id":"https:\/\/www.ciraltos.com\/staging2\/azure-machine-learning-in-log-analytics\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.ciraltos.com\/staging2\/azure-machine-learning-in-log-analytics\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.ciraltos.com\/staging2\/azure-machine-learning-in-log-analytics\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.ciraltos.com\/staging2\/"},{"@type":"ListItem","position":2,"name":"Azure Machine Learning in Log Analytics"}]},{"@type":"WebSite","@id":"https:\/\/www.ciraltos.com\/staging2\/#website","url":"https:\/\/www.ciraltos.com\/staging2\/","name":"ciraltos","description":"cloud, technology and trends","publisher":{"@id":"https:\/\/www.ciraltos.com\/staging2\/#\/schema\/person\/25391996d6cddfecd4d257162b7e373a"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.ciraltos.com\/staging2\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/www.ciraltos.com\/staging2\/#\/schema\/person\/25391996d6cddfecd4d257162b7e373a","name":"Travis Roberts","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.ciraltos.com\/staging2\/#\/schema\/person\/image\/","url":"https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2023\/03\/Logo-1.png","contentUrl":"https:\/\/www.ciraltos.com\/staging2\/wp-content\/uploads\/2023\/03\/Logo-1.png","width":5657,"height":3563,"caption":"Travis Roberts"},"logo":{"@id":"https:\/\/www.ciraltos.com\/staging2\/#\/schema\/person\/image\/"},"sameAs":["http:\/\/www.ciraltos.com","https:\/\/twitter.com\/ciraltos"],"url":"https:\/\/www.ciraltos.com\/staging2\/author\/admin\/"}]}},"_links":{"self":[{"href":"https:\/\/www.ciraltos.com\/staging2\/wp-json\/wp\/v2\/posts\/541"}],"collection":[{"href":"https:\/\/www.ciraltos.com\/staging2\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ciraltos.com\/staging2\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ciraltos.com\/staging2\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ciraltos.com\/staging2\/wp-json\/wp\/v2\/comments?post=541"}],"version-history":[{"count":15,"href":"https:\/\/www.ciraltos.com\/staging2\/wp-json\/wp\/v2\/posts\/541\/revisions"}],"predecessor-version":[{"id":563,"href":"https:\/\/www.ciraltos.com\/staging2\/wp-json\/wp\/v2\/posts\/541\/revisions\/563"}],"wp:attachment":[{"href":"https:\/\/www.ciraltos.com\/staging2\/wp-json\/wp\/v2\/media?parent=541"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ciraltos.com\/staging2\/wp-json\/wp\/v2\/categories?post=541"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ciraltos.com\/staging2\/wp-json\/wp\/v2\/tags?post=541"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}