Skip to content

Triagic + Azure Monitor: ticket investigations over your cloud account, read-only

Query Log Analytics and Application Insights with KQL, and read metrics and the activity log. Triagic connects to Azure Monitor from the desktop app on each member's machine, with a credential you configure, and shows every call it makes while it investigates a ticket. Nothing is copied out of Azure Monitor.

What you can ask

  • In Azure Monitor, find the log lines for the Lambda that handles webhook retries between 10:00 and 10:20
  • Did the error rate in Azure Monitor for the API gateway change in the last six hours?
  • Which alarms in Azure Monitor fired this week, and which are still in alarm?
  • Show me the Azure Monitor deployment that was live when ticket 4819 was filed
  • What is the dead-letter queue depth in Azure Monitor right now?

What the agent can do

Triagic exposes every tool the Azure Monitor server annotates as read-only, and nothing else. The official Azure server narrowed to the monitor namespace and started with --read-only.

Connect in three steps

  1. 1

    Mint a read-only credential in Azure Monitor

    Create a dedicated user or token that can only read. The official Azure server narrowed to the monitor namespace and started with --read-only.

  2. 2

    Add it in the Triagic portal

    Integrations, then Add shared data source, then Azure Monitor.

    • Tenant ID: Entra ID → App registrations → your app → Directory (tenant) ID.
    • Client ID: The same app registration's Application (client) ID.
    • Client secret: Certificates & secrets → New client secret. These expire. Note the date.
    • Client certificate path: The certificate you uploaded under Certificates & secrets → Certificates. PEM or PFX; a PEM must contain the private key as well as the certificate. Only a PEM can be pasted. A PFX is binary, so give it as a path. Path on each machine running Triagic, or paste the file itself.
    • Subscription ID: The subscription to query. Grant the service principal Monitoring Reader on it, and Log Analytics Reader on the workspaces.
  3. 3

    Let a desktop pick it up

    Saving validates the shape of what you typed. The first desktop app to sync starts Azure Monitor locally and reports running or degraded with the error text.

Field-by-field setup, TLS options and the error table: Azure Monitor in the docs.

Read-only, by construction

The official Azure server narrowed to the monitor namespace and started with --read-only.

FAQ

Can Triagic change anything in Azure Monitor?
No. The official Azure server narrowed to the monitor namespace and started with --read-only. Give it a read-only credential as well, so the guarantee does not rest on one layer.
What do I need to connect Azure Monitor?
Tenant ID, Client ID, Client secret, Client certificate path, Subscription ID. The desktop app on a member's machine starts the connection; the portal never holds a live process.
Does Azure Monitor cost extra?
No. Every connector is included in the seat price. Start a 14-day trial without a card.

Related integrations

Try it on your own Azure Monitor

No card. Install the desktop app, connect Azure Monitor read-only, and triage a real ticket this afternoon.