To report Azure Virtual Desktop (AVD) CPU usage, daily connected hours, and the busiest users and session hosts, configure two telemetry paths: AVD host-pool/workspace diagnostic settings and session-host performance collection through Azure Monitor Agent (AMA), a Data Collection Rule (DCR), Windows counters, and Log Analytics. A diagnostic setting alone does not collect VM CPU data.
The finished Azure Monitor Workbook can show connection activity, active and disconnected sessions, CPU statistics, daily trends, and rankings while highlighting data freshness and cost-saving opportunities.
What the dashboard measures
- AVD activity: management activities, feed, connections, errors, checkpoints, host registration, and agent health from host-pool diagnostics; workspaces provide management activities, feed, errors, and checkpoints.
- Session-host performance: CPU, memory, disk counters, and Windows events collected by AMA through a DCR.
- User activity: connection start and completion records in
WVDConnections, joined byCorrelationIdto calculate observed connection duration. - Workbook output: interactive Azure Monitor visualizations backed by Log Analytics queries.
AVD Insights is an Azure Monitor Workbook experience. Microsoft’s supported setup is documented at AVD Insights documentation. Standard Log Analytics ingestion and retention charges still apply; see Azure Monitor pricing.
Architecture and prerequisites
The data flow is:
AVD host pools and workspaces ── diagnostic settings ──┐ Session hosts ── AMA + DCR + counters ────────────────┤→ Log Analytics → Workbook/AVD Insights
- Azure Virtual Desktop deployed through Azure Resource Manager.
- A Log Analytics workspace and permission to query it.
- Permission to configure host pools, workspaces, diagnostic settings, DCRs, and VM extensions.
- AMA installed on every monitored session host, with a DCR association and managed identity where required.
- At least one real connection before connection queries can return data.
- For viewing, Microsoft documents Desktop Virtualization Reader on AVD resources and Log Analytics Reader on the workspace: role requirements.
The workspace receiving session-host data may differ from the workspace receiving AVD resource diagnostics. Choose boundaries by region, environment, retention, and governance, and document expected ingestion volume.
#1 Best Overall
Configure AVD diagnostic settings
Recommended workbook method
- Open Azure Virtual Desktop Insights in the Azure portal.
- Select Workbooks, then Check Configuration.
- Choose the subscription, resource group, and host pool.
- Under Resource diagnostic settings, choose the Log Analytics destination.
- For Host pool, select Configure host pool, then Deploy.
- For Workspace, select Configure workspace, then Deploy.
- Refresh the workbook and repeat for every host pool and workspace in scope.
Host-pool categories are Management Activities, Feed, Connections, Errors, Checkpoints, HostRegistration, and AgentHealthStatus. Workspace categories are Management Activities, Feed, Errors, and Checkpoints. Current portal labels can change; the concepts and categories are the important checks.
Manual portal method
- Open Azure Virtual Desktop → Host pools → select a host pool.
- Open Diagnostic settings, create or edit a setting, select the required categories, and send them to Log Analytics.
Do not select the same category in duplicate diagnostic settings when Azure rejects the configuration. Edit the existing setting instead. Microsoft describes this issue in its Autoscale monitoring guidance.
Collect CPU and other session-host telemetry
- In the host pool’s Insights configuration workbook, open Session host data settings.
- Select the Log Analytics workspace under Workspace destination.
- Select the DCR resource group and choose Create data collection rule.
- Choose Deploy association for all relevant session hosts.
- Choose Add extension to install AMA and add a system-managed identity if prompted.
- Under Workspace performance counters, review configured and missing counters, select Configure performance counters, then Apply Config.
- Refresh until every host reports and the missing-counter list is clear.
Microsoft’s automated configuration supports 1,000 session hosts or fewer. For larger pools or failed deployments, use ARM templates or another infrastructure-as-code process: deployment limits and configuration.
Rank #2
Validate ingestion before designing charts
Connection-quality data may take up to 15 minutes to appear and requires prior active-user connections: connection monitoring guidance. Generate a successful connection, disconnect/reconnect, and use at least two users and hosts when testing rankings.
Recommended Free Tools
Check connection states
WVDConnections
| where TimeGenerated > ago(24h)
| summarize Count = count() by State
| order by Count desc
Inspect connection schema
WVDConnections
| take 20
Inspect performance-counter values
Perf
| take 20
Perf
| distinct ObjectName, CounterName, InstanceName
| order by ObjectName asc, CounterName asc
Counter names vary with the DCR and agent configuration. Confirm actual values before filtering for Processor, % Processor Time, or _Total.
Design the Workbook
Add parameters for subscription, resource group, host pool, workspace, session host, user, time range, aggregation grain, and CPU statistic. A practical layout is:
Rank #3
Summary cards
- Connected users and active sessions.
- Disconnected sessions.
- Hosts reporting telemetry.
- Average and peak CPU.
- Total connected hours.
- Idle-host hours where your query defines them.
Daily utilization
Chart sessions, connected hours, average CPU, P95 CPU, active versus idle hosts, and connected hours by host pool. Built-in utilization views distinguish active from idle/disconnected sessions: AVD Insights use cases.
Ranking tables
For users show rank, user, connected hours, connection count, average duration, last connection, and host pools used. For hosts show rank, host, host pool, average/P95/peak CPU, connected hours, distinct users, sessions, and last telemetry timestamp.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteInvestigation visuals
Pair CPU with input delay, memory, disk latency or queue length, and session count. Microsoft presents CPU thresholds and input delay as investigation indicators, not universal sizing rules.
Rank #4
KQL templates
Validate table names, columns, state values, and time semantics in your workspace. The connection-duration pattern follows Microsoft’s WVDConnections examples.
Daily connected hours by user
let CompletedConnections =
WVDConnections
| where State == "Completed"
| project CorrelationId, EndTime = TimeGenerated;
WVDConnections
| where State == "Connected"
| project CorrelationId, UserName, SessionHostName, StartTime = TimeGenerated
| join kind=leftouter CompletedConnections on CorrelationId
| extend EndTime = coalesce(EndTime, now())
| where EndTime >= StartTime
| extend ConnectedHours = datetime_diff("second", EndTime, StartTime) / 3600.0
| extend Day = startofday(StartTime)
| summarize ConnectedHours = sum(ConnectedHours), Connections = count(), AverageConnectionHours = avg(ConnectedHours) by Day, UserName
| order by Day asc, ConnectedHours desc
Top 10 users
let CompletedConnections = WVDConnections | where State == "Completed" | project CorrelationId, EndTime = TimeGenerated;
WVDConnections
| where State == "Connected"
| project CorrelationId, UserName, StartTime = TimeGenerated
| join kind=leftouter CompletedConnections on CorrelationId
| extend EndTime = coalesce(EndTime, now())
| where EndTime >= StartTime
| extend ConnectedHours = datetime_diff("second", EndTime, StartTime) / 3600.0
| summarize ConnectedHours = sum(ConnectedHours), Connections = count(), LastConnection = max(StartTime) by UserName
| top 10 by ConnectedHours desc
Top 10 hosts by connected hours
let CompletedConnections = WVDConnections | where State == "Completed" | project CorrelationId, EndTime = TimeGenerated;
WVDConnections
| where State == "Connected"
| project CorrelationId, SessionHostName, UserName, StartTime = TimeGenerated
| join kind=leftouter CompletedConnections on CorrelationId
| extend EndTime = coalesce(EndTime, now())
| where EndTime >= StartTime
| extend ConnectedHours = datetime_diff("second", EndTime, StartTime) / 3600.0
| summarize ConnectedHours = sum(ConnectedHours), DistinctUsers = dcount(UserName), Connections = count() by SessionHostName
| top 10 by ConnectedHours desc
Daily CPU and top hosts
Perf
| where TimeGenerated > ago(30d)
| where ObjectName == "Processor" and CounterName == "% Processor Time" and InstanceName == "_Total"
| summarize AvgCPU = avg(CounterValue), P95CPU = percentile(CounterValue, 95), PeakCPU = max(CounterValue)
by Day = startofday(TimeGenerated), Computer
| order by Day asc, P95CPU desc
Use P95 or another stated statistic for host rankings; averages can hide short saturation. Aggregate connection and performance data independently before joining them by day and host. A combined view is an investigation aid, not proof that CPU caused a user problem.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Interpret the numbers correctly
Connected hours
Connected hours are observed duration between AVD connection events. They do not prove productivity, active keyboard use, CPU intensity, or a unique-user count. An open session has no completion event yet; using now() makes current-day totals provisional and changeable.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
Active and disconnected sessions
Keep active and disconnected sessions separate. A disconnected session can continue consuming host resources and affect scaling and cost decisions.
CPU pressure
Review average, P95, maximum, time above a chosen threshold, and concurrent session count. Correlate with input delay, memory, disk, profile storage, network quality, and application behavior. High CPU alone does not establish user impact.
Troubleshooting
| Symptom | Likely cause | Recovery |
|---|---|---|
| No connection data | Wrong scope, diagnostics, time range, or no test session | Check workspace/category settings, generate a connection, and allow ingestion delay. |
| No CPU rows | Missing DCR association, AMA, counters, or wrong schema | Inspect Perf, verify DCR/extension and counter names, and confirm destination workspace. |
| Some hosts missing | Agent or DCR association absent | Deploy the association and extension, then refresh the configuration workbook. |
| Duration query is empty | No Connected events, narrow filter, or different state names | Summarize raw states and inspect sample rows before changing the query. |
| Current day keeps changing | Open sessions or late completion events | Label it provisional, exclude open sessions, or recompute after a defined cutoff. |
| Duplicate-category error | Category already exists in another diagnostic setting | Edit the existing setting rather than creating a duplicate. |
Cost and scaling decisions
- Limit diagnostic categories and counter frequency to what operators use.
- Set retention deliberately and monitor Log Analytics ingestion.
- Use one or more workspaces according to operational boundaries rather than copying all telemetry everywhere.
- Use low-demand and idle-host trends to evaluate VM right-sizing or Autoscale.
- AVD Insights Autoscale monitoring applies to pooled host pools; personal pools have different behavior: Autoscale monitoring documentation.
- Use Workbooks for operational, near-real-time analysis; use Power BI, scheduled exports, or a data lake for long-term chargeback and cross-environment reporting.
Workbooks combine KQL, parameters, metrics, and visualizations: Workbook capabilities. They do not remove the underlying Log Analytics charges.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →




