Events from Azure virtual machines are collected into an Azure Log Analytics workspace and you plan to create alerts based on those events. Which two Azure services can be used to create alerts from the collected data?
Choose an answer
Tap an option to check your answer.
Correct answer: Azure Monitor, Azure Sentinel.
Why this is the answer
Azure Monitor is the foundational service for collecting, analyzing, and acting on telemetry from your Azure and on-premises environments. It directly integrates with Log Analytics workspaces and allows you to create alert rules based on Kusto Query Language (KQL) queries against the collected logs. Azure Sentinel is a Security Information and Event Management (SIEM) solution built on top of Azure Monitor and Log Analytics. It uses the data collected in Log Analytics for threat detection, investigation, and response, and includes built-in and custom alert rules for security-related events. Azure Security Center (now Microsoft Defender for Cloud) provides security posture management and threat protection, but its alerts are generally pre-defined security recommendations or detections, not custom alerts directly from arbitrary Log Analytics data. Azure Analysis Services is for analytical data models, not real-time alerting. Azure Advisor provides recommendations for optimizing Azure resources, not custom alerts from logs.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed