Skip to content

[log-analytics] az monitor log-analytics query fails in AzureChinaCloud with CloudEndpointNotSetException #10318

Description

@x-engineering-agent

Source: Azure/azure-cli#32631 (by MattCosturos)
Affected extension: log-analytics (src/log-analytics/)


<<UNTRUSTED:issue-32631>>

Issue #32631 (by MattCosturos)

Title

az monitor log-analytics query fails in AzureChinaCloud with CloudEndpointNotSetException

Body

Describe the bug

When running az monitor log-analytics query in Azure China (AzureChinaCloud), the command consistently fails with:

azure.cli.core.cloud.CloudEndpointNotSetException
The exception is thrown during client initialization, before any HTTP request is sent to the Log Analytics service.

This issue occurs across:

Different workspaces
Different KQL queries (e.g. Usage, AzureDiagnostics, StorageBlobLogs)

To Reproduce
Set Azure CLI cloud to Azure China:

az cloud set --name AzureChinaCloud
Login:

az login
Run any Log Analytics query:

az monitor log-analytics query \
--workspace \
--analytics-query "Usage"

Expected behavior
The command should successfully execute the Log Analytics query and return results, the same way it does in Azure Public Cloud.

Actual behavior
The command fails immediately with:

azure.cli.core.cloud.CloudEndpointNotSetException
No HTTP request is sent to the Log Analytics service.

Debug output
Relevant part of the stack trace:

File ".../azext_loganalytics/aaz/latest/monitor/log_analytics/_query.py", line 75
self.QueryExecute(ctx=self.ctx)()

File ".../azure/cli/core/aaz/_operation.py", line 37, in init
self.client = ctx.get_http_client(self.CLIENT_TYPE)

File ".../azure/cli/core/aaz/_client.py", line 75, in init
raise CloudEndpointNotSetException()

azure.cli.core.cloud.CloudEndpointNotSetException

Analysis / Root Cause
Based on the Azure CLI Core implementation in:

azure/cli/core/_profile.py
Azure CLI resolves service endpoints from the current cloud profile:

endpoint = cloud.endpoints.get(endpoint_name)
if not endpoint:
raise CloudEndpointNotSetException()
In AzureChinaCloud, the cloud profile does not appear to define the required endpoint for Log Analytics Query used by the log-analytics extension (AAZ-based).

As a result:

Client initialization fails
CloudEndpointNotSetException is raised
The query is never executed
This suggests a missing or incomplete Log Analytics endpoint definition for AzureChinaCloud, rather than a user configuration or query issue.

Environment
Azure CLI version:

az version

2.78.0

Extension:

log-analytics 1.0.0b1
OS:Windows 11

Cloud: AzureChinaCloud

Other Log Analytics access methods (e.g. REST API / PowerShell) work in Azure China
This appears to be a gap in Sovereign Cloud support for the new AAZ-based log-analytics extension
**Ask
Please confirm whether this is a known issue and advise:

Whether a missing endpoint definition for AzureChinaCloud needs to be added
Or if there is a recommended workaround until full support is available**

Related command

az monitor log-analytics query --workspace XXXXX --analytics-query 'kusto query' --debug

Errors

PS C:\Users<[~]USER>\AppData\Roaming\Code\User> az monitor log-analytics query --workspace <WORKSPACE_ID> --analytics-query <KQL_QUERY> --debug

cli.knack.cli: Command arguments:
['monitor', 'log-analytics', 'query',
'--workspace', '<WORKSPACE_ID>',
'--analytics-query', '<KQL_QUERY>',
'--debug']

cli.knack.cli: init debug log: Enable color in terminal.
cli.knack.cli: Event: Cli.PreExecute []
cli.knack.cli: Event: CommandParser.OnGlobalArgumentsCreate [...]
cli.knack.cli: Event: CommandInvoker.OnPreCommandTableCreate []

cli.azure.cli.core: Modules found from index for 'monitor':
['azure.cli.command_modules.monitor', 'azext_loganalytics']

cli.azure.cli.core: Loading command modules:
Name Load Time Groups Commands
monitor 1.729 23 70

cli.azure.cli.core: Loading extensions:
Name Load Time Groups Commands Directory
log-analytics 0.018 2 1 C:\Users<[~]USER>.azure\cliextensions\log-analytics

cli.azure.cli.core: Loaded 23 groups, 71 commands.
cli.azure.cli.core: Found a match in the command table.
cli.azure.cli.core: Raw command : monitor log-analytics query
cli.azure.cli.core: Command table: monitor log-analytics query

cli.azure.cli.core.azlogging:
metadata file logging enabled - writing logs to:
C:\Users<[~]USER>.azure\commands<TIMESTAMP>.monitor_log-analytics_query.log

az_command_data_logger:
command args: monitor log-analytics query --workspace {} --analytics-query {} --debug

az_command_data_logger:
extension name: log-analytics
extension version: 1.0.0b

Issue script & Debug output

PS C:\Users<[~]USER>\AppData\Roaming\Code\User> az monitor log-analytics query --workspace <WORKSPACE_ID> --analytics-query <KQL_QUERY> --debug

cli.knack.cli: Command arguments:
['monitor', 'log-analytics', 'query',
'--workspace', '<WORKSPACE_ID>',
'--analytics-query', '<KQL_QUERY>',
'--debug']

cli.knack.cli: init debug log: Enable color in terminal.
cli.knack.cli: Event: Cli.PreExecute []
cli.knack.cli: Event: CommandParser.OnGlobalArgumentsCreate [...]
cli.knack.cli: Event: CommandInvoker.OnPreCommandTableCreate []

cli.azure.cli.core: Modules found from index for 'monitor':
['azure.cli.command_modules.monitor', 'azext_loganalytics']

cli.azure.cli.core: Loading command modules:
Name Load Time Groups Commands
monitor 1.729 23 70

cli.azure.cli.core: Loading extensions:
Name Load Time Groups Commands Directory
log-analytics 0.018 2 1 C:\Users<[~]USER>.azure\cliextensions\log-analytics

cli.azure.cli.core: Loaded 23 groups, 71 commands.
cli.azure.cli.core: Found a match in the command table.
cli.azure.cli.core: Raw command : monitor log-analytics query
cli.azure.cli.core: Command table: monitor log-analytics query

cli.azure.cli.core.azlogging:
metadata file logging enabled - writing logs to:
C:\Users<[~]USER>.azure\commands<TIMESTAMP>.monitor_log-analytics_query.log

az_command_data_logger:
command args: monitor log-analytics query --workspace {} --analytics-query {} --debug

az_command_data_logger:
extension name: log-analytics
extension version: 1.0.0b

Expected behavior

The command should successfully execute the Log Analytics query and return results, the same way it does in Azure Public Cloud.

Environment Summary

Cloud:
AzureChinaCloud

OS:
Windows (PowerShell)

Azure CLI:
2.78.0

Extension:
log-analytics 1.0.0b1

Additional context

No response

Comments

Comment by Yong Zhang (@yonzhan)

Thank you for opening this issue, we will look into it.

Comment by MattCosturos

Running Az cli 2.83.0, log-analytics 1.0.0b1 and USGovCloud generates the same error
<<END:issue-32631>>

Activity

  1. yonzhan commented on Sep 10, 2026

    @yonzhan
    Collaborator

    Thank you for opening this issue, we will look into it.

  2. x-engineering-agent commented on Sep 10, 2026

    @x-engineering-agent
    Author

    Bug Analysis

    Root cause (confirmed by source inspection):

    In src/log-analytics/azext_loganalytics/aaz/latest/_clients.py, the
    AAZMicrosoftOperationalinsightsDataPlaneClient class defines:

    _CLOUD_HOST_TEMPLATES = {
        CloudNameEnum.AzureCloud: "https://api.loganalytics.io",
    }
    _CLOUD_HOST_METADATA_INDEX = "logAnalyticslogAnalyticsResourceId"

    _build_base_url first tries cls.get_cloud_endpoint(ctx, cls._CLOUD_HOST_METADATA_INDEX)
    (which resolves via CloudEndpoints.ARM_METADATA_INDEX or ARM cloud metadata),
    and falls back to _CLOUD_HOST_TEMPLATES.get(ctx.cli_ctx.cloud.name). Because
    _CLOUD_HOST_TEMPLATES only has an entry for AzureCloud, and AzureChinaCloud's
    built-in cloud profile (azure.cli.core.cloud AZURE_CHINA_CLOUD) does not
    define a logAnalyticslogAnalyticsResourceId / equivalent ARM metadata endpoint,
    _build_base_url returns None, and AAZBaseClient.__init__ raises
    CloudEndpointNotSetException() before any HTTP request is sent. This matches
    the reported stack trace exactly:
    _query.py:75 -> _operation.py:37 -> _client.py:75 CloudEndpointNotSetException.

    Fix: Add the AzureChinaCloud (Mooncake) Log Analytics data-plane host to
    _CLOUD_HOST_TEMPLATES in
    src/log-analytics/azext_loganalytics/aaz/latest/_clients.py, e.g.:

    _CLOUD_HOST_TEMPLATES = {
        CloudNameEnum.AzureCloud: "https://api.loganalytics.io",
        CloudNameEnum.AzureChinaCloud: "https://api.loganalytics.azure.cn",
    }

    Verify the exact Mooncake hostname against Microsoft's published Azure China
    service endpoint documentation before committing (do not guess). Also check
    whether AzureUSGovernment needs a corresponding entry (https://api.loganalytics.us
    is the commonly documented US Gov endpoint) since the same gap likely exists
    there — confirm from official docs rather than assuming.

    This file is aaz-generated output (# Code generated by aaz-dev-tools).
    Prefer regenerating it from the durable Azure/aaz command model per the
    Codegen protocol below; only hand-edit _clients.py directly if the durable
    source model does not carry cloud-host templates and regeneration would not
    change this file.

    Reported issue: Azure/azure-cli#32631 — az monitor log-analytics query
    fails in AzureChinaCloud with CloudEndpointNotSetException, confirmed
    reproducible on az 2.78.0 with the log-analytics extension.

    Use this EXACT PR title: [Log Analytics] Fix #10318: az monitor log-analytics query: Add AzureChinaCloud host template for log-analytics data-plane client

    Mandatory Codegen execution protocol

    Before editing implementation files, determine whether the affected log-analytics command is AAZ-generated. Files under aaz/<profile>/ are generated output and must never be patched directly, including by an AI agent. Check out Azure/aaz beside Azure/azure-rest-api-specs, Azure/aaz-dev-tools, and the downstream repository. API-schema defects start in the specification; command naming, grouping, arguments, API-version selection, help, and examples belong in the durable Azure/aaz command model; non-modelable client behavior belongs in a handwritten subclass or wrapper in custom.py, registered from commands.py. X Engineering Agent creates and promotes the corresponding durable Azure/aaz source pull request before it promotes downstream generated output.

    Follow the Azure CLI repository's Codegen workflow and the aaz-dev setup documentation. Set up the checked-out repositories with azdev setup. Use generate only when importing or redesigning command models from Swagger/TypeSpec. For an existing module whose durable Azure/aaz model has been updated, render that model with regenerate:

    aaz-dev cli regenerate --name log-analytics --cli-extension-path <azure-cli-extensions>
    
    # New/imported command model only:
    aaz-dev cli generate --spec <specification-name> --module log-analytics

    You MUST actually run the generator; do not merely describe it or imitate its output. If the AAZ/specification checkout, local source change, credentials, or generator is unavailable, stop and report the blocker instead of editing generated files. Inspect _aaz_info provenance and the complete regenerated diff, then run focused azdev style, azdev linter, and azdev test validation. For an extension, also update its version and HISTORY.rst, preserve azext_metadata.json compatibility, and let release automation update src/index.json.

    PR title & description format (required)

    This repo enforces a PR format (guide). Please author the PR exactly as follows or CI's Check the Format of Pull Request Title and Content will fail.

    Use this EXACT PR title (copy verbatim, do not reword):

    [Log Analytics] Fix #10318: `az monitor log-analytics query`: Add AzureChinaCloud host template for log-analytics data-plane client
    

    Keep the backticks around the command and the Fix #10318: prefix. You may only adjust the wording after the command (the final summary) if the fix changes; the [Log Analytics] prefix, issue link, and backticked command must stay.

    Description — follow the PR template and fill in:

    • Link the issue — start the Description with a closing keyword so the PR auto-links and closes it: Fixes #10318.
    • Related command — the az ... command this affects.
    • Description (mandatory) — why the bug happens, what you changed, and the resulting behavior.
    • Testing Guide — example command(s) showing the fix works.
    • History Notes — leave the title to drive the history note, or add extra lines in the same format (component in brackets + the command in backticks), e.g. [Log Analytics] `az <command>`: <note>.
    • Keep the template checklist and tick the items you've satisfied.
  3. x-engineering-agent commented on Sep 10, 2026

    @x-engineering-agent
    Author

    Started a Copilot task in a0x1ab/azure-cli-extensions using claude-sonnet-4.6: https://github.com/a0x1ab/azure-cli-extensions/tasks/01ad7f6e-1546-487f-a1e9-ae615b0cea90

  4. added
    Service AttentionThis issue is responsible by Azure service team.
    and removed
    Azure CLI TeamThe command of the issue is owned by Azure CLI team
    on Sep 10, 2026
  5. added a commit that references this issue on Sep 10, 2026
    1d1e2e9
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions