An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
Azure Log Analytics query intermittently times out before response headers
We are investigating an intermittent Azure Log Analytics query timeout that is blocking validation of a non-production COMPAT migration.
Workspace: workspace-rgbemtechcompatuaenoDtK
Workspace ID: 5ff58100-06de-46f9-9eea-af42ed147a74
Resource group: rg-bemtech-compat-uaen
Subscription: 7a3a1d7d-d830-4236-a88d-198471f0bde0
All timestamps below are UTC on 2026-09-19.
Observed failure:
A required application-coverage query timed out before response headers at the client's unchanged 20-second deadline.
Start: 11:49:48.671
End: 11:50:08.674
Elapsed: 20,003 ms
No HTTP response status or response body was received.
Query SHA-256:
e935b2f080199d51d0e8b38c396c94ca76673ceb17b64a56cd986aae272596c2
This does not establish an Azure service fault or an application failure.
Successful comparison:
At 12:18:51.865, a query took approximately 8.826 seconds to response headers, although reported query-engine execution was approximately 26.8 ms.
Provider request ID:
3d77488a-f516-4424-9818-8f67076ee823
Azure-hosted successful comparisons using managed identity:
Four responses returned HTTP 200 in 2442, 2189, 267 and 699 ms.
Cold comparison at 15:36:33.377:
Provider request ID:
af09a46f-0950-4d7e-8602-9cd052026791
Client request ID:
f262a31e-bfb4-45fc-bee8-f8c5e8418db0
The request body had been sent at approximately 113 ms; response headers arrived at approximately 2440 ms, while reported query-engine execution was approximately 11 ms.
Latest comparison at 15:36:53.285:
Provider request ID:
620b8266-dddd-43a7-8f36-1cd47498485f
Client request ID:
83dae89a-75b6-48c1-99e6-1fc19753f441
The comparison request IDs identify successful requests, not the original timed-out request.
A temporary managed-identity query grant used for diagnostics has already been removed and its absence verified.
Could a Microsoft/Azure engineer please advise whether service-side correlation is possible for the incident and comparison requests, including receive, authentication/routing, queue, execution and response timings?
If the original timed-out request cannot be located or those service-side traces are unavailable through Microsoft Q&A, please explicitly confirm that limitation and advise the minimum additional diagnostic capture or appropriate escalation path required.
Please do not change access permissions, resource configuration, or retention. No credentials, business records, or raw application logs are included.