Build DCR configs for Azure Monitor Agent with performance counters, Windows event logs, KQL transforms, and Log Analytics destinations.
Build DCR configs for Azure Monitor Agent with performance counters, Windows event logs, syslog, KQL transforms, and Log Analytics destinations.
Required Fields
ruleNameresourceGroupdataSourcesdestinationsdataFlowsOutput will appear here...Build an Azure Monitor Agent Data Collection Rule (DCR) wiring dataSources (performance counters, Windows event logs via xPathQueries, extensions like ChangeTracking) through dataFlows that route each named stream to one or more destinations, optionally applying a transformKql filter or projection before ingestion. dataFlows' transformKql runs at ingestion time, before data lands in Log Analytics, which is a genuinely different cost/filtering point than filtering in a query afterward, a transformKql filtering out noisy, low-value events (like the example's Error/Critical-only filter on Microsoft-Event) reduces actual Log Analytics ingestion volume and cost, whereas filtering the same data only in downstream KQL queries still pays full ingestion cost for data that's discarded on every query anyway.
The builder validates that ruleName, resourceGroup, dataSources, destinations, and dataFlows all resolve before accepting the JSON as a valid Data Collection Rule definition, the fields Azure Monitor needs to know what to collect, where it goes, and how it's transformed en route; it can't verify the transformKql syntax is valid or that referenced workspace resource IDs exist, those are only confirmed against the live Azure Monitor resource provider.
Use transformKql filtering deliberately for high-volume, low-signal streams (routine Information-level events, verbose performance counters you don't actually query), the ingestion cost savings from filtering at the DCR level rather than downstream can be substantial for a high-volume Windows fleet.
Scope Windows Security event collection via xPathQueries to specific, meaningful EventIDs rather than the entire Security log, both for cost control and to keep the resulting Log Analytics data genuinely useful for security investigation rather than diluted with routine noise.
Verify every stream referenced in dataFlows actually corresponds to a declared dataSources entry, a mismatch is a common and easy-to-introduce error when a DCR is edited incrementally over time.
Was this tool helpful?
Disclaimer: This tool runs entirely in your browser. No data is sent to our servers. Always verify outputs before using them in production. AWS, Azure, and GCP are trademarks of their respective owners.