Edit

Share via


Azure Copilot observability agent (preview)

The Azure Copilot observability agent is an AI-powered system designed to help you find the root cause of issues in complex, full-stack applications.

The agent analyzes telemetry across metrics, logs, and related Azure resources. It helps you understand what changed, where the problem originated, and how different components are connected across your environment.

The observability agent provides a chat-first investigation experience, designed to support troubleshooting workflows while focusing on structured, data-driven investigations.

What the observability agent does

When you initiate an investigation (for example, from an alert), the observability agent analyzes the problem by:

  • Analyzing telemetry data from the affected resources and related systems
  • Detecting anomalies in metrics, logs, and other observability signals
  • Correlating data across multiple data sources to understand the scope of the problem
  • Generating analysis with explanations of what happened and recommended next steps

The agent surfaces its reasoning throughout the investigation, explaining how signals are correlated and why specific insights are generated. This transparency lets you follow and understand the investigation logic.

Run an investigation with the observability agent

As part of the troubleshooting experience, the observability agent can run an investigation to help identify potential root causes and contributing factors.

The agent performs deep analysis and applies relevant analysis paths based on the signals it identifies, allowing the investigation to adapt to the specific characteristics of the issue.

Depending on the scenario, the agent might analyze and correlate signals from multiple sources. These sources can include logs and tracing data, metrics, and alerts and alert context. The agent can also use resource health signals and signals related to recent releases or system changes, when available.

The agent correlates the signals and generates analysis that explains what happened, highlights abnormal behavior, and surfaces relevant insights. Investigations are interactive and conversational.

You can ask follow-up questions, refine the scope, or create other investigations to explore different aspects or hypotheses related to the same problem.

Screenshot of Azure portal displaying API-RequestFailures investigation with latency metrics and request code breakdown.

Investigation results

Investigation results describe anomalous behavior identified during the investigation that could explain a problem with a resource.

You can view investigation results for up to 48 hours unless you save them as part of an issue.

The results include:

  • What happened – A summary of the observed behavior and affected resources.
  • Next steps – Suggested actions for further investigation or mitigation.
  • Supporting data – Evidence such as metric anomalies, logs, diagnostics insights, resource changes, and related alerts.

Screenshot of Azure Monitor investigation results with summary, supporting data, and Create Issue option visible.

Investigation results are available temporarily. To persist investigation results, create an Azure Monitor issue.

Saving investigation results in an issue

When you create an Azure Monitor issue, the full investigation context is preserved, not just the final results.

The issue includes:

  • Investigation results and supporting data
  • The interactive conversation with the agent
  • The reasoning and explanations presented to the user during the investigation

By saving an issue, you can return to the investigation at any time, resume the conversation, ask other questions, and continue exploring the problem with full visibility into previous findings and reasoning.

Screenshot of Azure Monitor investigation workflow, highlighting the Create Issue form with input fields and a Create Issue option.

For more information about Azure Monitor issues and capabilities, see Azure Monitor issues.

Integration with Azure Monitor workflows

The observability agent integrates into standard Azure Monitor troubleshooting workflows, so you can investigate problems directly from familiar entry points.

Alert‑driven access (portal and notifications) – You can launch the observability agent from Azure Monitor alerts. Use the Investigate action in alert notifications, such as email, or from the alert details page in the Azure portal.

Screenshot of Azure Monitor alert summary with failed requests graph and option to start an Investigate action.

Data security and encryption

The observability agent processes conversation data and investigation context to provide troubleshooting insights.

Customer Managed Keys (CMK) aren't supported for observability agent conversation data at this time. The data is encrypted by using Microsoft-managed encryption keys in accordance with Azure data protection standards.

Support for other encryption options, including CMK, might be considered in the future.

Investigation data retention

For operational, quality, and future product improvement purposes, you might retain investigation data internally for up to 30 days after an investigation is completed.

Technical requirements

  • Azure Monitor supports the observability agent in selected Azure regions. See the following section for details.
  • To create and manage Azure Monitor issues:
    • Associate the subscription with an Azure Monitor Workspace (AMW).
    • Have appropriate permissions on the AMW, such as Contributor, Monitoring Contributor, or Issue Contributor.

If you run investigations without creating an issue, you don't need an Azure Monitor Workspace or issue-specific permissions.

Regions

The observability agent is currently available in the following Azure regions. Some parts of the processing are geographically based rather than regional.

  • australiacentral
  • australiaeast
  • australiasoutheast
  • brazilsouth
  • canadacentral
  • canadaeast
  • centralindia
  • centralus
  • chilecentral
  • eastasia
  • eastus
  • eastus2
  • eastus2euap
  • francecentral
  • germanywestcentral
  • indonesiacentral
  • israelcentral
  • italynorth
  • japaneast
  • japanwest
  • koreacentral
  • koreasouth
  • malaysiawest
  • mexicocentral
  • newzealandnorth
  • northcentralus
  • northeurope
  • northwayeast
  • polandcentral
  • southafricanorth
  • southcentralus
  • southindia
  • southeastasia
  • spaincentral
  • swedencentral
  • swedensouth
  • switzerlandnorth
  • uaenorth
  • uksouth
  • ukwest
  • westcentralus
  • westeurope
  • westus
  • westus2
  • westus3