You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Azure Monitor-Log Analytics-Performance Counters采集本地机器运行进程日志并获取进程详情?

Hey there! Great to hear you've already got Azure Monitor tracking process CPU usage—let's get you the rest of the data you need (process owner username and memory metrics) and cover those low-cost non-SCOM alternatives too.

1. Fetching Process Username & Memory Data in Azure Monitor Log Analytics

1.1 Memory Usage Metrics

Since you're already using performance counters, you can just add the relevant ones to capture the same memory stats you see in Task Manager:

  • Head to your Log Analytics workspace's Data Collection Rules, find the Windows performance counters section, and add these counters:
    • Process(*)\Working Set (matches "Memory (Working Set)" in Task Manager)
    • Process(*)\Private Bytes (matches "Private Bytes")
    • Process(*)\Virtual Bytes (matches "Virtual Memory")

Once data starts flowing into the Perf table, use this KQL query to visualize or analyze it:

Perf
| where ObjectName == "Process" and CounterName in ("Working Set", "Private Bytes")
| where Computer == "YOUR_LOCAL_MACHINE_NAME"
| summarize avg(CounterValue) by InstanceName, CounterName, bin(TimeGenerated, 5m)
| render timechart

1.2 Process Owner Username

Performance counters don't include user ownership data, so you'll need to collect Windows process creation events or use the Process Inventory solution:

Option 1: Use Security Event Logs (Event ID 4688)

  • In your Data Collection Rules, add the Windows Security log and filter for Event ID 4688 (process creation).
  • Use this KQL query to join process creation events (with usernames) to your memory data:
// Grab recent process creation events with owner info
let processCreates = SecurityEvent
| where EventID == 4688
| where Computer == "YOUR_LOCAL_MACHINE_NAME"
| parse EventData with * '<Data Name="NewProcessId">'NewProcessId'</Data>' * '<Data Name="SubjectUserName">'UserName'</Data>' * '<Data Name="NewProcessName">'ProcessName'</Data>' *
| extend ProcessId = tostring(tolong(NewProcessId)/1000) // Convert hex process ID to decimal
| project TimeGenerated, ProcessName, UserName, ProcessId;

// Join with memory usage data
Perf
| where ObjectName == "Process" and CounterName == "Working Set"
| where Computer == "YOUR_LOCAL_MACHINE_NAME"
| extend ProcessId = tostring(InstanceIndex) // InstanceIndex maps to process ID
| join kind=inner (processCreates) on ProcessId
| project TimeGenerated, ProcessName, UserName, CounterValue, Computer
| order by TimeGenerated desc

Option 2: Use the Process Inventory Solution

  • Enable the Process Inventory solution in your Log Analytics workspace (it's free for basic usage).
  • It automatically collects process owner, memory, and other metadata into the ProcessInventory table—query it with:
ProcessInventory
| where Computer == "YOUR_LOCAL_MACHINE_NAME"
| project TimeGenerated, ProcessName, UserName, WorkingSet, PrivateBytes
| order by TimeGenerated desc

2. Low-Cost Non-SCOM Alternatives

2.1 Azure Monitor (Your Current Setup)

Don't overlook this! For small-scale local machine monitoring, the Log Analytics free tier (5GB daily data) is more than enough, and paid tiers are cost-effective for larger environments. It's already integrated if you're using it for CPU tracking.

2.2 Prometheus + Grafana (Open Source, Free)

  • Use windows_exporter (formerly wmi_exporter) to scrape Windows process metrics (CPU, memory, owner) via WMI.
  • Configure Prometheus to pull the exporter data, then build custom dashboards in Grafana for visualization. Perfect if you want full control and don't mind setting up open-source tools.

2.3 ELK Stack (Elasticsearch + Logstash + Kibana)

  • Use Filebeat to collect Windows performance counters and process events, ship them to Logstash for parsing, then store in Elasticsearch. Kibana lets you build interactive dashboards. Great if you already have an ELK environment or prefer Elastic's ecosystem.

2.4 Nagios Core

A tried-and-true open-source monitoring tool. Use the NSClient++ plugin to collect Windows process data, and write simple scripts to fetch process owner usernames. It's free, highly customizable, and works well for small to medium environments.

2.5 Datadog Free Tier

If you want a managed solution without the setup hassle, Datadog's free tier supports up to 5 hosts. It has built-in Windows process monitoring, pre-built dashboards, and alerting—super easy to get started with.

内容的提问来源于stack exchange,提问作者daviesdoesit

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.29 13:42:43