Azure Monitor Log Integration via OTLP

This integration ships broker logs from your CloudAMQP cluster to Azure Monitor through its native OpenTelemetry Protocol (OTLP) ingestion endpoint. It is available on RabbitMQ and LavinMQ dedicated instances.

Prerequisites

Before setting up the integration, you need:

  • An Azure subscription
  • A Microsoft Entra app registration with a client secret

Set up native OTLP ingestion

Option A: Create a new Application Insights with OTLP support (recommended)

Create an Application Insights resource with OTLP support set to On. Azure provisions and connects the required resources. Follow Microsoft's native OTLP ingestion guide for the current setup steps.

Option B: Enable OTLP support on an existing Application Insights resource

Enable OTLP support on an existing Application Insights resource. Azure creates an additional Data Collection Endpoint (DCE) and Data Collection Rule (DCR) for native OTLP ingestion. They do not replace the existing Application Insights resource or its Log Analytics Workspace, and existing ingestion can continue.

For either option, open the Application Insights Overview page and select OTLP Connection Info. Copy the Logs Endpoint to use in CloudAMQP and follow the DCR link to configure access.

Configure authentication

CloudAMQP authenticates with Microsoft Entra ID using the OAuth 2.0 client credentials flow. The integration uses the tenant ID, application (client) ID, and client secret to obtain access tokens for the Azure Monitor ingestion endpoint.

  1. From the Microsoft Entra app registration's Overview page, record the Directory (tenant) ID and Application (client) ID.
  2. Under Certificates & secrets, create a client secret and record its value. The secret value is shown only once; do not use the secret ID.
  3. Follow the DCR link from OTLP Connection Info. Under Access control (IAM), assign the Monitoring Metrics Publisher role to the app registration's service principal.

Setting up in the CloudAMQP console

In the CloudAMQP console, open Integrations → Add log integration → Azure Monitor and enter the following values:

Directory (tenant) ID
Found on the Microsoft Entra app registration's Overview page.
Application (client) ID
Found on the app registration's Overview page.
Client secret
The secret value created under Certificates & secrets, not its secret ID.
Logs endpoint
Copy the complete Logs Endpoint from Application Insights OTLP Connection Info.

Example:

https://example.eastus-1.ingest.monitor.azure.com/dataCollectionRules/dcr-123/streams/Microsoft-OTLP-Logs/otlp/v1/logs

Click Save to activate the integration. Logs will begin shipping within a few minutes.

Finding your logs

Azure stores logs received through native OTLP ingestion in the OTelLogs table in the connected Log Analytics Workspace.

  • ServiceName identifies the CloudAMQP cluster.
  • ServiceInstanceId identifies the individual server in the cluster.
  • Body contains the broker log message.
  • SeverityNumber contains the OpenTelemetry severity.
  • SeverityLevel is Azure's simplified severity level derived from SeverityNumber.
  • Attributes.appname identifies the broker as rabbitmq or lavinmq.

Use this query to view the newest broker logs:

OTelLogs
| project TimeGenerated, ServiceName, ServiceInstanceId, SeverityLevel, Body, Attributes
| order by TimeGenerated desc

Migrating from the legacy Azure Monitor integration

The native OTLP integration writes to Azure's fixed OTelLogs table instead of a customer-named _CL table. Existing legacy ingestion can continue while you verify the new integration.

Settings from the legacy integration are not copied automatically. Configure the new integration with its native OTLP logs endpoint and Microsoft Entra credentials. Existing historical records remain in their original table.

← Back to Log Integrations

↑ Back to top