HOTSPOT You have 100 Azure virtual machines that run Windows Server. You plan to use Azure Monitor agents to track occurrences of event 10 1035 in the Application log of each virtual machine. You need to ensure that the events will be available tor analysis in Log Analytics. The solution must minimize the total volume of events stored in Azure. What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Q: 1
Your Answer
Discussion
Create a data collection rule, filter with XPath query. Not 100% sure, someone confirm?
Not B or KQL, since you need to filter BEFORE the logs hit Log Analytics. Go with create a data collection rule and use XPath for filtering. Practice exams sometimes mix this up but XPath is what you want for event log filtering.
Be respectful. No spam.
Question 1 of 35
