certslothcertsloth
AI-200/Topic 03

Azure / Associate

Azure Monitor, Logs and Alerts

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Metrics quantify, logs explain, traces connect and alerts start a response.

Must remember

  • Azure Monitor combines metrics and logs; Log Analytics workspaces hold queryable log data. Activity Log records management-plane events; resource/application logs require relevant collection configuration. Diagnostic settings route supported categories to selected destinations.
  • Azure Monitor Agent uses data collection rules for supported guest telemetry. VM, Storage and Network Insights provide focused views; Application Insights adds application performance and tracing with suitable instrumentation. Guest memory/disk metrics are not automatically identical to platform metrics.
  • KQL pipelines transform tables: where filters, project selects columns, summarize aggregates, bin() groups time intervals, and joins combine data. Example: Heartbeat | summarize LastSeen=max(TimeGenerated) by Computer finds each computer's latest recorded heartbeat; absence can mean collection failure, not only host failure.
  • Alert rules define signal, scope, evaluation and condition. Action groups define notifications/actions. Alert processing rules modify processing such as suppression under selected conditions; they do not change the source telemetry. Use dynamic thresholds where appropriate and test missing-data behaviour.
  • Network Watcher and Connection Monitor help inspect path and connectivity. Logs, effective routes/rules and an application test answer different questions. Narrow time windows and correlation IDs reduce noise; retention and ingestion volume affect cost.
  • Monitor the collection pipeline itself. Permissions, network access, workspace configuration and data collection rules can break visibility. Avoid logging secrets and unnecessary personal data, and define retention according to operational/evidence requirements.

Choose under exam pressure

Requirement Choice and reason
Who changed an Azure resource? Activity Log and relevant audit evidence.
Notify an operations group on a metric breach Alert rule linked to an action group.
Investigate recurring connection failures Connection Monitor plus route, rule and application evidence.

Traps

  • No logs can mean no collection.
  • Action groups do not define the alert threshold.
  • Average response time can conceal severe tail latency.

Active recall

1. Which KQL operator groups and aggregates rows?

summarize.

2. Why use a data collection rule?

To specify supported telemetry collection and routing for managed collection scenarios.

3. What does an alert processing rule change?

How selected alerts are processed, such as action suppression, rather than the measured signal itself.

4. Why keep correlation IDs?

To connect related requests across application and dependency telemetry.

5. Does an Activity Log replace application logs?

No. Management operations and application behaviour are different evidence.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.