# Output Plugin for Azure LAW or EventHub

**URL:** <https://discuss.elastic.co/t/output-plugin-for-azure-law-or-eventhub/377360>\
**Category:** Logstash\
**Created:** [April 22, 2025, 6:45am UTC](https://discuss.elastic.co/t/output-plugin-for-azure-law-or-eventhub/377360 "2025-04-22T06:45:28Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ricki1234](https://avatars.discourse-cdn.com/v4/letter/r/e9a140/32.png) [@ricki1234](https://discuss.elastic.co/u/ricki1234)\
**Post date:** [April 22, 2025, 6:45am UTC](https://discuss.elastic.co/t/output-plugin-for-azure-law-or-eventhub/377360/1 "2025-04-22T06:45:28Z")

</div>

Hello  
I'm trying to get data from an elasticsearch cluster to an Azure log-analytics-workspace or to an azure eventhub. Are there any output-plugins (I've read about the microsoft-logstash-output-azure-loganalytics - does this one still exists?) which I can use? Do you have a sample configuration for such a case?  
Thanks Barbara

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 22, 2025, 4:26pm UTC](https://discuss.elastic.co/t/output-plugin-for-azure-law-or-eventhub/377360/2 "2025-04-22T16:26:30Z")

</div>

> [@ricki1234](#):
>
> I've read about the microsoft-logstash-output-azure-loganalytics - does this one still exists?

It still exists (at [github](https://github.com/Azure/Azure-Sentinel/tree/master/DataConnectors/microsoft-logstash-output-azure-loganalytics)). I think the only updates since the release five years ago are to update the list of logstash versions it works with.

There is a forked version [here](https://github.com/pkhabazi/microsoft-sentinel-logstash-output) that supports managed identity.

There is another implementation (which I don't think is from Microsoft) [here](https://github.com/yokawasa/logstash-output-azure_loganalytics).

None of them appear to be under active development, but I have no idea whether they need to be. So they all exist, but may or may not work with a current logstash version.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 22, 2025, 4:41pm UTC](https://discuss.elastic.co/t/output-plugin-for-azure-law-or-eventhub/377360/3 "2025-04-22T16:41:47Z")

</div>

Azure Event Hubs works with the Kafka protocol, I would say that using Logstash the easiest way to send or read data from Event Hubs is using the `kafka` input and output.

---

<div class="post-metadata">

**Author:** ![ricki1234](https://avatars.discourse-cdn.com/v4/letter/r/e9a140/32.png) [@ricki1234](https://discuss.elastic.co/u/ricki1234)\
**Post date:** [April 23, 2025, 5:17am UTC](https://discuss.elastic.co/t/output-plugin-for-azure-law-or-eventhub/377360/4 "2025-04-23T05:17:12Z")

</div>

Hello Leandro, Badger  
Thanks for your suggestions/links - I'll try them
