# Data Collection Rules

Source: /azure/services/data-collection-rules/

## Introduction

Azure Monitor Data Collection Rules (DCR) define the data to collect, how to transform it, and where to send it.
Data Collection Endpoints (DCE) expose the endpoints used for configuration access and for ingesting data in DCR-based pipelines, while Data Collection Rule Associations (DCRA) link a DCR to a specific monitored resource.
Together, DCRs, DCEs, and DCRAs form the foundation of the Azure Monitor Logs ingestion pipeline. For more information, see [Data collection rules in Azure Monitor](https://learn.microsoft.com/en-us/azure/azure-monitor/essentials/data-collection-rule-overview).

LocalStack for Azure provides a local environment for building and testing applications that make use of Azure Monitor Data Collection Rules.
The supported APIs are available on our [API Coverage section](#api-coverage), which provides information on the extent of Data Collection Rules' integration with LocalStack.

## Getting started

This guide walks you through creating a Data Collection Endpoint, a Data Collection Rule, and associating the rule with a virtual machine.

Launch LocalStack using your preferred method. For more information, see [Introduction to LocalStack for Azure](/azure/getting-started/). Once the container is running, enable Azure CLI interception by running:

```bash
lstk az start-interception
```

This command points the `az` CLI away from the public Azure management REST API and toward the LocalStack for Azure emulator API.
To revert this configuration, run:

```bash
lstk az stop-interception
```

This reconfigures the `az` CLI to send commands to the official Azure management REST API.

### Create a resource group

Create a resource group to hold all resources created in this guide:

```bash
az group create --name rg-dcr-demo --location westeurope
```

```bash title="Output"
{
  "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/rg-dcr-demo",
  "location": "westeurope",
  "name": "rg-dcr-demo",
  "properties": { "provisioningState": "Succeeded" },
  "type": "Microsoft.Resources/resourceGroups"
}
```

### Create a data collection endpoint

Create a data collection endpoint (DCE) to serve as the ingestion target:

```bash
az monitor data-collection endpoint create \
  --name my-dce \
  --resource-group rg-dcr-demo \
  --location westeurope \
  --public-network-access Enabled
```

```bash title="Output"
{
  "configurationAccess": { "endpoint": "https://my-dce-a1b2.westeurope-1.control.monitor.azure.com" },
  "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/rg-dcr-demo/providers/Microsoft.Insights/dataCollectionEndpoints/my-dce",
  "immutableId": "dce-82f06343382a4872ba2270b5dba2eee7",
  "location": "westeurope",
  "logsIngestion": { "endpoint": "https://my-dce-a1b2.westeurope-1.ingest.monitor.azure.com" },
  "name": "my-dce",
  "networkAcls": { "publicNetworkAccess": "Enabled" },
  "provisioningState": "Succeeded",
  "resourceGroup": "rg-dcr-demo",
  "type": "Microsoft.Insights/dataCollectionEndpoints"
...
}
```

### Create a data collection rule

Save the following JSON to `my-dcr.json`:

```json title="my-dcr.json"
{
  "location": "westeurope",
  "properties": {
    "dataSources": {
      "performanceCounters": [
        {
          "name": "perfCounterDataSource",
          "samplingFrequencyInSeconds": 60,
          "counterSpecifiers": ["\\Processor(_Total)\\% Processor Time"],
          "streams": ["Microsoft-Perf"]
        }
      ]
    },
    "destinations": {
      "logAnalytics": [
        {
          "workspaceResourceId": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/rg-dcr-demo/providers/Microsoft.OperationalInsights/workspaces/my-workspace",
          "name": "myWorkspace"
        }
      ]
    },
    "dataFlows": [
      {
        "streams": ["Microsoft-Perf"],
        "destinations": ["myWorkspace"]
      }
    ]
  }
}
```

Create the data collection rule from the configuration file:

```bash
az monitor data-collection rule create \
  --name my-dcr \
  --resource-group rg-dcr-demo \
  --location westeurope \
  --rule-file my-dcr.json
```

```bash title="Output"
{
  "dataFlows": [ { "destinations": ["myWorkspace"], "streams": ["Microsoft-Perf"] } ],
  "dataSources": {
    "performanceCounters": [
      { "counterSpecifiers": ["\\Processor(_Total)\\% Processor Time"], "name": "perfCounterDataSource", "samplingFrequencyInSeconds": 60, "streams": ["Microsoft-Perf"] }
    ]
  },
  "destinations": {
    "logAnalytics": [
      { "name": "myWorkspace", "workspaceResourceId": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/rg-dcr-demo/providers/Microsoft.OperationalInsights/workspaces/my-workspace" }
    ]
  },
  "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/rg-dcr-demo/providers/Microsoft.Insights/dataCollectionRules/my-dcr",
  "immutableId": "dcr-d7f9c291105845b8b470d40631e5c883",
  "location": "westeurope",
  "name": "my-dcr",
  "provisioningState": "Succeeded",
  "resourceGroup": "rg-dcr-demo",
  "type": "Microsoft.Insights/dataCollectionRules"
...
}
```

### List data collection rules

List the data collection rules in the resource group:

```bash
az monitor data-collection rule list --resource-group rg-dcr-demo
```

```bash title="Output"
[
  {
    "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/rg-dcr-demo/providers/Microsoft.Insights/dataCollectionRules/my-dcr",
    "location": "westeurope",
    "name": "my-dcr",
    "provisioningState": "Succeeded",
    "resourceGroup": "rg-dcr-demo",
    "type": "Microsoft.Insights/dataCollectionRules",
    ...
  }
]
```

### Create a data collection rule association

Associate the rule with a virtual machine:

```bash
VM_ID="/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/rg-dcr-demo/providers/Microsoft.Compute/virtualMachines/my-vm"

az monitor data-collection rule association create \
  --name my-dcra \
  --resource "$VM_ID" \
  --rule-id "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/rg-dcr-demo/providers/Microsoft.Insights/dataCollectionRules/my-dcr"
```

```bash title="Output"
{
  "dataCollectionRuleId": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/rg-dcr-demo/providers/Microsoft.Insights/dataCollectionRules/my-dcr",
  "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/rg-dcr-demo/providers/Microsoft.Compute/virtualMachines/my-vm/providers/Microsoft.Insights/dataCollectionRuleAssociations/my-dcra",
  "name": "my-dcra",
  "resourceGroup": "rg-dcr-demo",
  "type": "Microsoft.Insights/dataCollectionRuleAssociations"
...
}
```

### Delete and verify

Delete the data collection rule and confirm it no longer appears in the list:

```bash
az monitor data-collection rule delete \
  --name my-dcr \
  --resource-group rg-dcr-demo \
  --yes
```

Then list data collection rules again to confirm none remain in the resource group:

```bash
az monitor data-collection rule list --resource-group rg-dcr-demo
```

```bash title="Output"
[]
```

## Features

- **Data Collection Rule lifecycle:** Create, read, list, update, and delete DCRs.
- **Data Collection Endpoint lifecycle:** Create, read, list, and delete DCEs.
- **Data Collection Rule Association lifecycle:** Create, read, list, and delete DCRAs linking a DCR to a resource.
- **Data source configuration:** Accept performance counter, Windows event log, Syslog, and custom log data sources.
- **Destination configuration:** Accept Log Analytics workspace and storage account destinations.
- **Data flow configuration:** Define stream-to-destination routing in the data flow section.

## Limitations

- **No data ingestion:** Data sent to a DCE ingestion URL is not processed or stored.
- **No transformation:** KQL-based data transformations defined in DCRs are not executed.
- **No agent-managed collection:** The Azure Monitor Agent (AMA) interacting with LocalStack does not collect or forward real metrics or logs.

## Samples

Explore end-to-end examples in the [LocalStack for Azure Samples](https://github.com/localstack/localstack-azure-samples) repository.

## API Coverage


### Data Collection Rules API coverage

Source service: `data-collection-rules`. 18 of 21 tracked operations are implemented.

Service documentation: /azure/services/data-collection-rules/

| Operation | Status |
| --- | --- |
| DataCollectionEndpoints.Create | Implemented |
| DataCollectionEndpoints.Delete | Implemented |
| DataCollectionEndpoints.Get | Implemented |
| DataCollectionEndpoints.GetNSP | Not implemented |
| DataCollectionEndpoints.ListByResourceGroup | Implemented |
| DataCollectionEndpoints.ListBySubscription | Implemented |
| DataCollectionEndpoints.ListNSP | Not implemented |
| DataCollectionEndpoints.ReconcileNSP | Not implemented |
| DataCollectionEndpoints.Update | Implemented |
| DataCollectionRuleAssociations.Create | Implemented |
| DataCollectionRuleAssociations.Delete | Implemented |
| DataCollectionRuleAssociations.Get | Implemented |
| DataCollectionRuleAssociations.ListByDataCollectionEndpoint | Implemented |
| DataCollectionRuleAssociations.ListByResource | Implemented |
| DataCollectionRuleAssociations.ListByRule | Implemented |
| DataCollectionRules.Create | Implemented |
| DataCollectionRules.Delete | Implemented |
| DataCollectionRules.Get | Implemented |
| DataCollectionRules.ListByResourceGroup | Implemented |
| DataCollectionRules.ListBySubscription | Implemented |
| DataCollectionRules.Update | Implemented |
