Azure Monitor Log Integration via OTLP
This integration ships broker logs from your CloudAMQP cluster to Azure Monitor through its native OpenTelemetry Protocol (OTLP) ingestion endpoint. It is available on RabbitMQ and LavinMQ dedicated instances.
Prerequisites
Before setting up the integration, you need:
- An Azure subscription
- A Microsoft Entra app registration with a client secret
Set up native OTLP ingestion
Option A: Create a new Application Insights with OTLP support (recommended)
Create an Application Insights resource with OTLP support set to On. Azure provisions and connects the required resources. Follow Microsoft’s native OTLP ingestion guide for the current setup steps.
Option B: Enable OTLP support on an existing Application Insights resource
Enable OTLP support on an existing Application Insights resource. Azure creates an additional Data Collection Endpoint (DCE) and Data Collection Rule (DCR) for native OTLP ingestion. They do not replace the existing Application Insights resource or its Log Analytics Workspace, and existing ingestion can continue.
For either option, open the Application Insights Overview page and select OTLP Connection Info. Copy the Logs Endpoint to use in CloudAMQP and follow the DCR link to configure access.
Configure authentication
CloudAMQP authenticates with Microsoft Entra ID using the OAuth 2.0 client credentials flow. The integration uses the tenant ID, application (client) ID, and client secret to obtain access tokens for the Azure Monitor ingestion endpoint.
- From the Microsoft Entra app registration’s Overview page, record the Directory (tenant) ID and Application (client) ID.
- Under Certificates & secrets, create a client secret and record its value. The secret value is shown only once; do not use the secret ID.
- Follow the DCR link from OTLP Connection Info. Under Access control (IAM), assign the Monitoring Metrics Publisher role to the app registration’s service principal.
Setting up in the CloudAMQP console
In the CloudAMQP console, open Integrations → Add log integration → Azure Monitor and enter the following values:
- Directory (tenant) ID
- Found on the Microsoft Entra app registration’s Overview page.
- Application (client) ID
- Found on the app registration’s Overview page.
- Client secret
- The secret value created under Certificates & secrets, not its secret ID.
- Logs endpoint
- Copy the complete Logs Endpoint from Application Insights OTLP Connection Info.
Example:
https://example.eastus-1.ingest.monitor.azure.com/dataCollectionRules/dcr-123/streams/Microsoft-OTLP-Logs/otlp/v1/logs
Click Save to activate the integration. Logs will begin shipping within a few minutes.
Finding your logs
Azure stores logs received through native OTLP ingestion in the OTelLogs
table in the connected Log Analytics Workspace.
ServiceNameidentifies the CloudAMQP cluster.ServiceInstanceIdidentifies the individual server in the cluster.Bodycontains the broker log message.SeverityNumbercontains the OpenTelemetry severity.SeverityLevelis Azure’s simplified severity level derived fromSeverityNumber.Attributes.appnameidentifies the broker asrabbitmqorlavinmq.
Use this query to view the newest broker logs:
OTelLogs
| project TimeGenerated, ServiceName, ServiceInstanceId, SeverityLevel, Body, Attributes
| order by TimeGenerated desc
Migrating from the legacy Azure Monitor integration
The native OTLP integration writes to Azure’s fixed OTelLogs table instead of a customer-named
_CL table. Existing legacy ingestion can continue while you verify the new integration.
Settings from the legacy integration are not copied automatically. Configure the new integration with its native OTLP logs endpoint and Microsoft Entra credentials. Existing historical records remain in their original table.