For the complete documentation index, see llms.txt. This page is also available as Markdown.

Azure Resources

Cortex connects to many third-party vendors whose system interfaces frequently change. As a result, integration behavior or configuration steps may shift without notice. If you encounter unexpected issues, check with your system administrator or refer to the vendor's documentation for the most current information. Additionally, integration sync times vary and are subject to scheduling overrides and timing variance.

Azure Resources provides on-demand cloud computing platforms and APIs. Cortex uses the Azure Resource API to pull in resource details and import entities such as SQL servers, virtual machines, virtual networks, load balancers, and others.

Integrating Azure Resources with Cortex allows you to:

Cortex conducts a background sync of Azure Resources every day at 00:00 a.m. UTC and an ownership sync every day at 6 a.m. UTC.

How to configure Azure Resources with Cortex

Prerequisites

Before getting started, you will need the following information. These can be found in the Enterprise applications section of Azure:

  • Azure tenant ID

  • Azure client ID and client secret

  • Azure subscription ID

    • Ensure that the service principal for the subscription ID has a Reader role.

Configure the integration in Cortex

  1. In Cortex, navigate to the Azure Resources settings page.

    • Click Integrations from the main nav. Search for and select Azure Resources.

  2. Click Add configuration.

  3. Configure the Azure Resources integration form:

    • Account alias: Enter your Azure account alias. Account aliases are used to tie service registrations to different configuration accounts.

    • Azure tenant ID: Enter your Azure tenant ID.

    • Client ID and Client secret: Enter your Azure client ID and secret.

    • Subscription ID: Enter your Azure subscription ID.

  4. Click Save.

    • You will be redirected to the Azure Resources Settings page in Cortex, where you can optionally choose to include only specified Azure resource types for this integration. You can also enable automatic import for any discovered entities of known types.

After saving your configuration, you are redirected to the integration settings page in Cortex. In the upper right corner of the page, click Test configuration to ensure Azure Resources was configured properly.

How to connect Cortex Entities to Azure Resources

For Azure Resources, Cortex replaces non-alphanumeric characters in entity names with a space. For example, resource_1 would become resource 1.

For the Cortex tag, Cortex replaces non-alphanumeric characters with - and lowercases the letters. If multiple special characters appear together in a tag, Cortex replaces the group of characters with only one -. For example, mY_e%ntity#$_tag would become my-e-ntity-tag.

Enable automatic discovery of Azure Resource entities

You can configure automatic import from Azure:

  1. In Cortex, navigate to the Entities Settings page.

  2. Next to Auto import from AWS, Azure, and/or Google Cloud, click the toggle to enable the import.\

Discover ownership for Azure Resources

Cortex can automatically discover ownership for your Azure resources. To configure this:

  • Make sure that your Azure resources have a tag matching the x-cortex-tag of the corresponding Cortex team

  • Enable the “Sync ownership from Azure” toggle in the Azure Resources Settings page in Cortex.

    • By default, Cortex looks for the owner tag. You can also customize the tag key name on the Settings page.

Cortex syncs ownership from Azure Resources every day at 6 a.m. UTC.

Define a dependency

Cortex automatically discovers dependencies between your services and resources by scanning for resources with specific Azure Resources tags. By default, a service will have dependencies on any Cortex resource that has a corresponding Azure Resources resource with Azure Resources tag key = "service" and tag value = the service's Cortex tag.

On the Azure Resources settings page, you can customize the tag key names for dependencies.

For more information on defining dependencies, please see the Dependencies documentation.

Import entities from Azure Resources

See the Create services documentation for instructions on importing entities.

Editing the entity descriptor

You can associate a Cortex entity with one or more Azure Resources entities. Cortex will display those Azure Resources entities' metadata on the Cortex entity page.

When the entity is connected to Azure, the entity YAML will look like the following:

Using the Azure Resources integrations

Scorecards and CQL

With the Azure Resources integration, you can create Scorecard rules and write CQL queries based on Azure Resources details.

See more examples in the CQL Explorer in Cortex.

Get Azure Resource details for entity

Get Azure Resource details for an entity.

Definition: azureResource.details(): Object

Examples

In a Scorecard, you can write a rule to make sure an entity has Azure Resource details:

Make sure an entity has an environment tag:

Make sure an entity has a health check:

Make sure an entity has a tag with a certain key and value:

Availability zones

Availability zone data (VM Scale Sets, Redis, Application Gateways) is a first-class .zones field, sourced directly from Azure Resource Graph.

If you have existing "Resource Redundancy" rules for these resource types, update them to reference .zones instead of deriving zone data from the ARM export template.

Example

App Service health-check path and minimum TLS version

Cortex reads App Service configuration data, including healthCheckPath and minimum TLS version.

Existing "Health Check" and App Service Scorecard rules will continue to work as-is, no Scorecard rule changes needed.

Example

View integration logs

This feature is available in Cortex cloud.

While viewing an integration's settings page, select the Logs tab to view error logs from the last 7 days. You can filter the logs list by configuration and by operation (for example, you could filter to view errors surfaced only via Scorecards).

The 'Logs' tab on an integration's settings page shows error information over the past 7 days.

Click into a row to get more information, including time stamp, status code, full error, and request path.

Troubleshooting and FAQ

Why is the Azure resource type microsoft-resources-subscriptions-resourcegroups not pulling in Azure Resource details?

Cortex pulls from the Azure Resource API, but not from the Azure Resource Group API. If you would like to submit a feature request for support of Azure Resource Groups, please contact our customer engineering team.

Why is ARM template data sometimes missing or stale?

Cortex uses the Azure ARM export template endpoint to ingest resource data for some resource types. This endpoint has known reliability limitations acknowledged in Microsoft's documentation, which can cause intermittent failures that result in missing or outdated data.

Cortex is actively migrating away from ARM template-based ingestion toward Azure Resource Graph and the resource metadata endpoint. In the interim, if you see empty or stale data for a resource, this is likely caused by an ARM export failure on the Microsoft side.

Last updated

Was this helpful?