A global admin for BlueNova enabled Traffic Analytics but sees data aggregated every 5 minutes while they expect hourly aggregates for billing-level reports. They have Traffic Analytics configured to use workspace 'net-ws-01' in West US and flow logs are version 2. How can they change Traffic Analytics to produce hourly aggregates?
Choose an answer
Tap an option to check your answer.
Correct answer: Update the Traffic Analytics configuration for the NSG flow logs (flowAnalyticsConfiguration) to set the aggregation interval to 60 minutes (1 hour) and ensure flow logs are v2 and referenced to the Log Analytics workspace 'net-ws-01'..
Why this is the answer
Traffic Analytics aggregation intervals are configured directly within the flowAnalyticsConfiguration settings of the Network Security Group (NSG) flow logs. To achieve hourly aggregates, the aggregationIntervalInMinutes property needs to be set to 60. Flow logs v2 fully support this configuration. Changing the Log Analytics workspace retention setting would affect data retention, not the aggregation interval for Traffic Analytics. Disabling flow logs v2 is incorrect as v2 is the recommended and supported version, and v1 does not inherently force hourly aggregation. Aggregation intervals are not tied to the region of the Log Analytics workspace; they are a configurable setting within the flow log resource itself.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed