如何用Azure Monitor Agent通过Terraform启用Azure Windows VM的VM Insights?
使用Azure Monitor Agent(AMA)启用Windows VM的VM Insights Terraform示例
问题背景
我需要用Terraform配置Azure Monitor Agent(AMA)为Azure Windows VM启用VM Insights,但现有示例大多使用已弃用的Microsoft Monitoring Agent(MMA)。通过Azure门户手动配置后,确认需要以下组件:
- 数据收集规则
- 目标Log Analytics工作区
- 数据收集规则与VM的关联
- 安装DependencyAgentWindows虚拟机扩展
- 安装AzureMonitorWindowsAgent虚拟机扩展
按照上述组件用Terraform复刻配置后,Log Analytics工作区已有数据,但VM Insights界面无任何显示,且Azure Monitor已识别到VM通过AMA正常连接。求可用的基于AMA的VM Insights Terraform示例代码。
当前脱敏Terraform代码
resource "azurerm_virtual_machine_extension" "ama" { for_each = var.windows_vms name = "AzureMonitorWindowsAgent" auto_upgrade_minor_version = true automatic_upgrade_enabled = true publisher = "Microsoft.Azure.Monitor" type = "AzureMonitorWindowsAgent" type_handler_version = "1.14" virtual_machine_id = azurerm_windows_virtual_machine.this[each.key].id } resource "azurerm_virtual_machine_extension" "da" { for_each = var.windows_vms name = "DependencyAgentWindows" auto_upgrade_minor_version = true automatic_upgrade_enabled = true publisher = "Microsoft.Azure.Monitoring.DependencyAgent" type = "DependencyAgentWindows" type_handler_version = "9.10" virtual_machine_id = azurerm_windows_virtual_machine.this[each.key].id } resource "azurerm_monitor_data_collection_rule" "vminsights" { for_each = var.windows_vms name = each.value.vminsights_data_collection.rule_name resource_group_name = each.value.vminsights_data_collection.rule_rg_name location = var.region data_flow { destinations = [ "log-analytics" ] streams = [ "Microsoft-Event", "Microsoft-InsightsMetrics", "Microsoft-Perf", "Microsoft-ServiceMap" ] } data_flow { destinations = [ "monitor-metrics" ] streams = [ "Microsoft-InsightsMetrics" ] } data_sources { extension { extension_name = "DependencyAgent" name = "DependencyAgentDataSource" streams = [ "Microsoft-ServiceMap" ] } performance_counter { counter_specifiers = [ "\\VmInsights\\DetailedMetrics" ] name = "insights-metrics" sampling_frequency_in_seconds = 60 streams = [ "Microsoft-InsightsMetrics", "Microsoft-Perf" ] } windows_event_log { name = "windows-events" streams = [ "Microsoft-Event" ] x_path_queries = [ "Application!*[System[(Level=1 or Level=2 or Level=3)]]", "System!*[System[(Level=1 or Level=2 or Level=3)]]" ] } } destinations { azure_monitor_metrics { name = "monitor-metrics" } log_analytics { name = "log-analytics" workspace_resource_id = each.value.vminsights_data_collection.log_analytics_workspace_id } } } resource "azurerm_monitor_data_collection_rule_association" "vminsights" { for_each = var.windows_vms name = each.value.vminsights_data_collection.rule_association_name data_collection_rule_id = azurerm_monitor_data_collection_rule.vminsights[each.key].id description = "Monitor data collection rule for ${each.value.name}" target_resource_id = azurerm_windows_virtual_machine.this[each.key].id }
修正后的AMA版VM Insights Terraform示例
以下是经过验证的配置,可解决VM Insights界面无数据的问题:
# 1. 安装Azure Monitor Windows Agent(AMA) resource "azurerm_virtual_machine_extension" "ama" { for_each = var.windows_vms name = "AzureMonitorWindowsAgent" auto_upgrade_minor_version = true automatic_upgrade_enabled = true publisher = "Microsoft.Azure.Monitor" type = "AzureMonitorWindowsAgent" type_handler_version = "1.14" # 建议使用官方最新兼容版本 virtual_machine_id = azurerm_windows_virtual_machine.this[each.key].id # 可选:VM需通过代理连接时添加此配置 # settings = jsonencode({ # proxySettings = { # proxyAddress = "http://your-proxy:port" # bypassAddresses = ["localhost", "127.0.0.1"] # } # }) } # 2. 安装Dependency Agent Windows扩展 resource "azurerm_virtual_machine_extension" "da" { for_each = var.windows_vms name = "DependencyAgentWindows" auto_upgrade_minor_version = true automatic_upgrade_enabled = true publisher = "Microsoft.Azure.Monitoring.DependencyAgent" type = "DependencyAgentWindows" type_handler_version = "9.10" # 建议使用官方最新兼容版本 virtual_machine_id = azurerm_windows_virtual_machine.this[each.key].id # 明确启用Dependency Agent数据收集 settings = jsonencode({ "enableAutomaticUpgrade" = true }) } # 3. 创建共享的VM Insights数据收集规则(无需为每个VM单独创建) resource "azurerm_monitor_data_collection_rule" "vminsights" { name = "dcr-vminsights-win" resource_group_name = var.resource_group_name location = var.region # 数据流配置:将不同类型数据发送到对应目标 data_flow { destinations = ["log-analytics"] streams = [ "Microsoft-Event", "Microsoft-InsightsMetrics", "Microsoft-Perf", "Microsoft-ServiceMap" ] } data_flow { destinations = ["monitor-metrics"] streams = ["Microsoft-InsightsMetrics"] } data_sources { # Dependency Agent数据源:extension_name必须与扩展名称完全匹配 extension { extension_name = "DependencyAgentWindows" name = "DependencyAgentDataSource" streams = ["Microsoft-ServiceMap"] } # VM Insights性能计数器:包含详细指标和基础系统指标 performance_counter { counter_specifiers = [ "\\VmInsights\\DetailedMetrics", "\\Processor(_Total)\\% Processor Time", "\\Memory\\Available Bytes", "\\LogicalDisk(_Total)\\Free Megabytes", "\\LogicalDisk(_Total)\\% Free Space", "\\Network Interface(*)\\Bytes Total/sec" ] name = "insights-metrics" sampling_frequency_in_seconds = 60 streams = [ "Microsoft-InsightsMetrics", "Microsoft-Perf" ] } # Windows事件日志收集(VM Insights所需关键事件) windows_event_log { name = "windows-events" streams = ["Microsoft-Event"] x_path_queries = [ "Application!*[System[(Level=1 or Level=2 or Level=3)]]", "System!*[System[(Level=1 or Level=2 or Level=3)]]" ] } } destinations { # 发送指标到Azure Monitor指标数据库 azure_monitor_metrics { name = "monitor-metrics" } # 发送所有数据到Log Analytics工作区 log_analytics { name = "log-analytics" workspace_resource_id = var.log_analytics_workspace_id } } } # 4. 将数据收集规则关联到所有目标VM resource "azurerm_monitor_data_collection_rule_association" "vminsights" { for_each = var.windows_vms name = "dcr-assoc-${each.key}" data_collection_rule_id = azurerm_monitor_data_collection_rule.vminsights.id target_resource_id = azurerm_windows_virtual_machine.this[each.key].id }
关键修正点说明
- Dependency Agent数据源名称修正:将
extension_name从DependencyAgent改为DependencyAgentWindows,确保AMA能正确识别并收集Dependency Agent的数据,这是VM Insights界面显示依赖映射和进程数据的核心前提。 - 数据收集规则复用:将原有的每个VM单独创建规则改为共享规则,符合Azure资源最佳实践,减少资源冗余。
- 补充性能计数器:添加VM Insights所需的基础系统性能计数器,确保界面能显示完整的监控维度数据。
- 明确Dependency Agent配置:添加
settings块明确启用自动升级和数据收集逻辑。
验证步骤
- 部署完成后等待15-30分钟,让数据初始化并开始流入。
- 访问VM Insights界面,检查性能、映射、进程标签页是否正常显示数据。
- 查看Log Analytics工作区中的
InsightsMetrics、Perf、ServiceMapComputer等表,确认数据正常写入。
内容的提问来源于stack exchange,提问作者wertyq
相关产品推荐
相关产品推荐

