An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
Unable to see Key Vault audit logs in Log Analytics
I have diagnostics enabled for an Azure Key Vault, with alllogs selected, connected to a Log Analytics workspace. I have queried the AZKVAuditLogs table, and find no data in there. I also see no data in AZKVPolicyEvaluationDetailsLogs.
In researching, I found azure documentation about diagnostic settings for Key Vaults listing the above tables, and AzureActivity and AzureMetrics
I queried AzureActivity and there is also no data in this table.
When I say no data, I mean NO data (not even trying to filter to just the KV I'm looking at).
AzureMetrics does have data, including the KV I'm looking at.
Other log tables in this workspace do have data, for example I've queried several of the tables related to Azure Synapse diagnostics.
I have tried to create a support request for this, but it appears that I have to post here instead
Azure Monitor
-
Bharath Y P • 10,610 Reputation points • Microsoft External Staff • Moderator
2025-09-30T19:43:05.7066667+00:00 Hello Mike Rees,
You have enabled diagnostics for an Azure Key Vault with allLogs selected and connected it to a Log Analytics workspace. But your Key Vault diagnostic logs aren’t flowing into the expected tables, even though metrics are working and other services are logging fine.
Can you help confirm a few things so I can better understand the issue:
- Did you select both "AuditEvent" (or "Audit") and "AllLogs" when setting up the diagnostic settings? You mentioned only "AllLogs" was selected.
- Have there been any recent access attempts or changes to Key Vault’s policies? These actions are what typically generate audit logs.
- When you checked the AZKVAuditLogs table and saw no data, were you querying from the time diagnostics were enabled? Or did you first perform an action on the Key Vault (like retrieving or setting a secret), then wait 10–15 minutes before running the query?
Thanks,
-
Mike Rees • 40 Reputation points • Microsoft Employee
2025-09-30T21:51:47.5333333+00:00 @Bharath Y P , Sorry, that was an omission on my part.
for the diagnostic settings for AKV, all three are checked (audit, allLogs and AllMetrics)In the categories, (and appropriately greyed out) are Audit Logs and Azure Policy Evaluation Details)
The KV is used by our production ETL processes, so there should be retrievals throughout each day.
For my query, it was with time frame first, and when I saw none, I removed the where clause entirely, and just took 10 rows (or attempted to take them)
I want to eventually see when a stored Certificate is accessed. Would this table include Certificate access? If not, what table would?
Even so, with the KV being used regularly during the day, I expect to see secrets being retrieved in this table. I did not need to delay my queries because there is expected activity throughout the day.
-
Bharath Y P • 10,610 Reputation points • Microsoft External Staff • Moderator
2025-10-01T00:31:31.14+00:00 Hello Mike Rees,
Thanks for the update, selecting the allLogs category group automatically includes ALL underlying log categories for that resource, which in this case are Audit Logs and Azure Policy Evaluation Details.
You’re probably not seeing any Key Vault logs even though your production ETL process is running because there may be a delay in data ingestion, querying the wrong table, or a missing link between the Key Vault and the Log Analytics workspace.
Since you’ve confirmed that diagnostic settings are enabled and the correct categories are selected, here are the next steps to troubleshoot, focusing on how you're querying Log Analytics:
Depending on how your diagnostic settings are configured, logs may appear in one of two tables:
AzureDiagnostics: This is the standard table that collects logs from many different Azure services.
AzureDiagnostics | where ResourceProvider == "MICROSOFT.KEYVAULT" | where Resource == "YourKeyVaultName" // Optional but recommended | take 10AzureKeyVaults: This is a newer, specialized table that stores logs specifically for Key Vaults, but only if you chose the resource-specific option when setting up diagnostics.
AzureKeyVaults | take 10If the logs exist, one of these queries will return data.
Since the diagnostic setting was created recently, one of the most common issues is that it's pointing to the wrong Log Analytics Workspace, or the ETL process hasn’t triggered a true “data plane” operation that would generate audit logs.
- Go to the Azure Portal > Navigate to your Key Vault.
- Select Monitoring > Diagnostic settings.
- Open the diagnostic setting you configured.
- Confirm that the destination workspace is the same one where you're running your KQL queries.
The certificate access events are considered data plane operations, and they should be captured in the Key Vault audit logs, assuming diagnostics are correctly configured.
The AuditEvent category in your diagnostic settings records operations like GetCertificate, , DeleteCertificate, UpdateCertificate and ListCertificate. These types of events are usually logged in the AZKVAuditLogs table.
-
Bharath Y P • 10,610 Reputation points • Microsoft External Staff • Moderator
2025-10-02T00:35:18.27+00:00 Hello Mike Rees, kindly let us know if the solution provided was helpful. If you need any further assistance, please let us know.
Thanks.
-
Mike Rees • 40 Reputation points • Microsoft Employee
2025-10-02T15:11:14.6766667+00:00 I will. Sorry, I was unable to check back into this yesterday. I will do this today
-
Mike Rees • 40 Reputation points • Microsoft Employee
2025-10-02T18:44:28.44+00:00 @Bharath Y P , thank you so much. A minor correction, The diagnostic settings were set up a couple of years ago at least. Not sure I communicated this properly earlier since you mentioned they were set up recently.
As for the two new tables you mentioned. The AzureDiagnostics has Cert access info. Going to play with it to see if it is useful, but this is definitely what we need!
I see these operations in this table
I do not see the table, AzureKeyVaults. Should I? Or could this be because the diag settings were set up some time ago.
BTW, these are the settings as I see them
-
Bharath Y P • 10,610 Reputation points • Microsoft External Staff • Moderator
2025-10-02T22:48:58.8833333+00:00 Hello Mike Rees, Thanks for the update. Apologies for the miss understanding, The actual, current resource-specific table used by Azure Monitor for Key Vault's audit logs is AZKVAuditLogs, not AzureKeyVaults.
Since you can see the data in the AzureDiagnostics table. The AZKVAuditLogs table only receives data if you have explicitly configured your Key Vault's diagnostic setting to use the Resource-Specific collection mode. If that setting was created some time ago, it defaulted to the older mode.
To ensure logs are sent to the dedicated AZKVAuditLogs table, you need to select the specific log, category for Key Vault, which is AuditEvent/Audit. Make sure to deselect allLogs, as that option defaults back to the old AzureDiagnostics table. After deselecting allLogs, check if the logs appear in the AZKVAuditLogs table and let us know if this resolves the issue
Reference document:
Resource logs in Azure Monitor - Azure Monitor | Microsoft Learn
-
Mike Rees • 40 Reputation points • Microsoft Employee
2025-10-02T22:57:59.44+00:00 @Bharath Y P , are you saying to leave 'allLogs' unchecked and save it? Or uncheck it, Save, then check it again and Save?
Should I expect the interface to change? I don't see anything change when I do that? But I also tried adding a new setting, and see the same Logs options.
Also, is there a method available for updating settings or at least identifying when Diagnostic Settings functionality has changed? If I understand you correctly, we're trying to trigger a change so that the old default is not used. But without having opened this post, I would have never known that Diag settings had changes and therefore never know that any action was needed to update them
-
Bharath Y P • 10,610 Reputation points • Microsoft External Staff • Moderator
2025-10-03T19:42:47.6633333+00:00 Hello Mike Rees, Yes, you can manually uncheck allLogs, save, then recheck and save again to trigger a refresh. This action helps ensure that the latest Diagnostic Settings schema and behavior are applied, especially if your settings were created before recent platform updates.
Manual Updates to Diagnostic Settings Created via Tag Rules - Azure | Microsoft Learn
-
Mike Rees • 40 Reputation points • Microsoft Employee
2025-10-03T19:47:18.7766667+00:00 @Bharath Y P, This is an issue, that existing settings are impacted by platform updates but there is no visibility into the impact. In this case, you are telling me that the process is to write to a different table (or tables), but we would have never known this without this discussion.
Is there any way to notify us (through alert, notification or email or other) to let us know that there are platform updates that our older settings won't be getting ? Or any way to force the update to take on the changes?
-
Mike Rees • 40 Reputation points • Microsoft Employee
2025-10-09T22:40:47.9766667+00:00 @Bharath Y P, I checked, and there are still no logs in AZKVAuditLogs table.
I'm going to try again, but this time I'm leaving "audit" and "allLogs" unchecked
and making sure that "Audit Logs" and "Azure Policy Evaluation Details" are checked.
-
Anonymous
2025-10-15T06:10:00.25+00:00 Hello Mike Rees, Thanks for updating
After filtering to view only audit logs and Azure Policy evaluation details, are you able to see the entries in the AZKVAuditLogs table? could you please confirm ?
Sign in to comment