If you’re looking for your Azure Log Analytics workspace keys in the portal and can’t find them, you can retrieve it directly with Azure CLI. I’d use get-shared-keys with a query for the key I need and --output tsv to return it without JSON quotes.
Retrieve the primary key
Run the following command, replacing example-rg and example-workspace with your resource group and workspace names:
az monitor log-analytics workspace get-shared-keys \
--resource-group example-rg \
--workspace-name example-workspace \
--query primarySharedKey \
--output tsv
The --query primarySharedKey argument selects the primary key from the response. Adding --output tsv returns the value as plain text, which is useful when passing it to another command or configuration setting.
Without --output tsv, the CLI’s default JSON output wraps the value in quotation marks. You can find the command and its parameters in the Microsoft Learn Azure CLI reference.
Retrieve the secondary key or both keys
To return only the secondary key, change the query:
az monitor log-analytics workspace get-shared-keys \
--resource-group example-rg \
--workspace-name example-workspace \
--query secondarySharedKey \
--output tsv
If you need both keys, omit the query and request JSON output explicitly:
az monitor log-analytics workspace get-shared-keys \
--resource-group example-rg \
--workspace-name example-workspace \
--output json
The response contains primarySharedKey and secondarySharedKey
Being able to query a workspace does not automatically give you permission to retrieve its keys. Microsoft lists Microsoft.OperationalInsights/workspaces/sharedKeys/action as the permission for reading workspace keys in its Log Analytics access guidance.
Check the permissions assigned to the identity running the command at the workspace or an inherited scope. Before adding the command to a pipeline, make sure the returned key goes into the intended secret setting and is not printed in the job logs.