Configure serverless Azure Metrics with Cloud Provider
Use the Grafana Cloud Provider UI to connect your Azure account and begin collecting metrics without deploying any collector or agent on your own infrastructure. When you create a credential, Cloud Provider uses your Azure service principal to discover your subscriptions and resources and begins collecting metrics automatically every two minutes.
To configure serverless Azure metrics using Terraform instead, refer to Configure serverless Azure metrics with Terraform.
Before you begin
- You have a Grafana Cloud account.
- You have either the Admin Grafana Cloud basic role or the Azure Writer plugin role for your stack. For steps to assign RBAC roles, refer to Assign RBAC roles.
- You have an Azure account with at least one subscription you want to monitor.
- You have the Client ID, Client secret, and Tenant ID for an Azure service principal with the
Monitoring Readerrole assigned. If you need to create one, follow the steps in Configure Azure authorization.
Navigate to Azure serverless
The first step in setting up serverless Azure metrics in Cloud Provider is getting to the page where you can enter your Azure credentials.
To navigate to Azure serverless in Grafana Cloud:
- Navigate to your Grafana Cloud Portal.
- Select your Grafana Cloud stack.
- In your Grafana Cloud stack, expand Observability > Cloud Provider in the main menu.
- Click Azure, then click the Configuration tab.
- Select Serverless for how to configure Azure.
- Click the Azure Metrics tile.
- At the Azure credentials page, click Add new credential.
Configure access for Grafana Cloud
After you have navigated to the Azure serverless page in Cloud Provider, you need to grant Grafana Cloud the proper authorization to pull data from your Azure Subscription.
To configure access for Grafana Cloud to access your Azure metrics:
- Click Setup instructions.
- Follow the steps to create a service principal with the
Azure Monitoring Readerrole, using the Azure CLI.
To export metrics from Azure, Grafana Cloud needs authorization to pull data from your Azure Subscriptions. Grafana Alloy uses the Azure SDK for Go which has multiple options for configuring authentication to Azure, including but not limited to the following options:
- a service principal with environment variable
- a workload identity
- a managed identity
Whichever option you choose, the identity that you use must have the Azure Monitoring Reader role for any Azure Subscriptions you are trying to monitor.
Refer to the various options for configuring authentication in Azure documentation.
Connect to Azure account
After you have configured access for Grafana Cloud to gather your Azure metrics, you need to connect your Azure account in Cloud Provider.
To connect your Azure account in Grafana Cloud:
- Enter the Name you want to give to your new credential.
- Enter the Client id you want to create the credential for.
- Enter the Client secret.
- Enter the Tenant id.
- Optionally, add tags. For more information, refer to Tag and filter metrics by Azure resource tag.
- Optionally, add static labels for easier filtering and grouping. Static labels are added to all metrics exported by this credential. For more information, refer to Set static labels.
Tag and filter metrics by Azure resource tag
Use the tags table in the Connect to Azure account step to add Azure resource tags as labels on your metrics, restrict which resources Cloud Provider collects metrics for, or both.
By default, resource information, including tags, is available on the target_info metric.
To add a tag:
- In the Key field, enter the Azure resource tag key you want to use, for example
environment. - Optionally, select Filter by tag value and enter a Value.
- Click Add. The tag appears in the table below the input fields.
Repeat for each additional tag you want to add.
Tagging only
If you don’t select Filter by tag value, Cloud Provider adds the tag key and value as a label on the target_info metric for matching resources.
In this instance, adding tags doesn’t change which resources are collected.
Tagging and filtering
If you select Filter by tag value and provide a value, Cloud Provider only collects metrics from resources whose Azure tag matches that value. Cloud Provider applies this filter in real time when it scrapes Azure Monitor, before metrics are ingested. It doesn’t reference a previously stored list of tags, so if a resource’s tag value changes, the resource is included or excluded starting with the next scrape.
For example, to collect metrics only from resources tagged environment=production:
- Enter
environmentin the Key field. - Select Filter by tag value.
- Enter
productionin the Value field.
Only resources with the tag environment=production are collected.
Resources tagged environment=staging or with no environment tag are excluded.
Note
Tag filters apply to the entire credential. Cloud Provider applies the same tag filters to every resource type discovered by that credential; you can’t scope a tag filter to a single resource type. To apply different tag filters to different resource types, create separate credentials.
Set static labels
Static labels are key-value pairs applied to all metrics collected from this credential. Use static labels to filter and group metrics in Grafana Cloud—for example, to distinguish metrics from different environments or teams.
To add a static label:
- In the Static labels field, enter a label key using the
static_label_keyplaceholder as a guide. - In the adjacent value field, enter a label value using the
static_label_valueplaceholder as a guide. - Click Add. The label appears in a table below the input fields showing the Keys and Values you have added.
- Repeat for each additional label you want to add.
To remove a static label, click the delete icon next to the label in the table.
Static label requirements:
- Label keys and values must be compatible with the Prometheus data model specification.
- Label keys must start with a letter or underscore and may contain only letters, numbers, and underscores.
- Label keys must not start with
__(double underscore), which is reserved for internal use. - Each label key must be unique within a credential. Adding a key that already exists has no effect.
Note
Static labels apply to all metrics from this credential. To apply different labels to different sets of Azure resources, create separate credentials.
When querying metrics in Grafana, filter by static labels using PromQL label matchers.
For example, if you added the label key environment with value production:
{job=~"cloud/azure/.+", environment="production"}Configure metrics
To configure metrics, select one of two ways for your credential to get data into Grafana Cloud:
- Autodiscovery: This option adds all resources found in the provided Azure account to Grafana Cloud.
- Setup manually: This option allows you to select specific resources and metrics from the Azure account provided to send to Grafana Cloud.
Autodiscovery
When you use autodiscovery:
- Cloud Provider Observability automatically discovers all supported Azure resource types in your subscriptions
- New resources are detected within one hour and automatically added to metric collection
- Resources that are deleted or stopped are automatically removed from collection
- Metrics are collected every two minutes using the Azure Monitor Metrics Batch API
- All available metrics for each discovered resource are collected by default
To use autodiscovery to configure your Azure serverless metrics:
- Choose Autodiscovery to add all resources found in the provided Azure account to Grafana Cloud.
- Click Create credential to finish creating your configuration and to begin collecting metrics.
Setup manually
To manually setup your Azure serverless metrics:
- Select Setup manually.
- In the Subscription id box, enter the subscription id you want to get data for.
- Optionally, select which resources to get for the current subscription ID. If you do not specify resources, all resources associated with this subscription ID are included.
- Optionally click Edit Metrics for the selected resources to customize which metrics, aggregations, and dimensions are sent. If you do not customize the metrics, all discovered available metrics, aggregations, and dimensions are included.
- Optionally, add additional subscription IDs.
- Click Create credential to finish creating your configuration and to begin collecting metrics.
View Azure preconfigured dashboards
After you configure metrics, preconfigured dashboards appear automatically in the Cloud Provider Observability app. You don’t need to install them.
Note
If you are not assigned a Grafana Cloud basic role, you must have the
Datasources:Readerfixed role to see dashboard data. For more information on assigning roles, refer to Assign RBAC roles.
To view a preconfigured dashboard:
- Click the Services tab.
- Use the Service or Source filters to help you find the source or service you want to see.
- Optionally, click the Services with firing alerts checkbox to limit the services displayed to only those with firing alerts.
- Locate the specific service in the list, and click the name of the service in the Service column of the table to open the preconfigured dashboard for that service. If a Service’s name is not a link it means there is not a preconfigured dashboard for that service. To add a link to the Service’s name for a dashboard, refer to Dashboards and views settings.
- Optionally, click the Configure button to add a dashboard to the Service name.
- Optionally, click the Explore button to view links for custom dashboards, drilldown metrics, or to explore metrics. Refer to Dashboards and views settings for more information on adding custom dashboards.
Install Azure preconfigured alerts
Preconfigured alerts require a one-time installation.
Note
If you are assigned the Viewer Grafana Cloud basic role or are not assigned a Grafana Cloud basic role, you must have the
Alerting:Rules Writer,Alerting:Set provisioning status, andFolders:Writerfixed roles to install alerts and access folders. For more information on assigning roles, refer to Assign RBAC roles.
To install preconfigured alerts:
- After you configure metrics, click the Configuration tab.
- Scroll down to the Alerts Installation section and click Install.
To view preconfigured alerts, click the Alerts tab.


