You need to collect Windows event logs and performance counters from multiple Azure virtual machines and query the data centrally by using Kusto Query Language. Which Azure resource should you deploy?
Trap 1: A Recovery Services vault
A Recovery Services vault handles backup and recovery rather than centralized log analytics.
Trap 2: Azure Network Watcher
Network Watcher focuses on network diagnostics and is not the main platform for general VM log analytics.
Trap 3: A load balancer
A load balancer distributes traffic and does not store monitoring data.
- A
A Log Analytics workspace
A Log Analytics workspace stores and enables KQL querying of collected monitoring data.
- B
A Recovery Services vault
Why it fails: A Recovery Services vault handles backup and recovery rather than centralized log analytics.
- C
Azure Network Watcher
Why it fails: Network Watcher focuses on network diagnostics and is not the main platform for general VM log analytics.
- D
A load balancer
Why it fails: A load balancer distributes traffic and does not store monitoring data.