When creating data collection rules to collect Application and System logs from virtual machines, which query language should you use to filter events with custom criteria?
Choose an answer
Tap an option to check your answer.
Correct answer: KQL.
Why this is the answer
KQL (Kusto Query Language) is the correct choice because it is the primary query language used in Azure Monitor Logs, which is where data collection rules send their collected logs. KQL is specifically designed for querying large datasets in Azure and offers powerful filtering capabilities. LINQ (Language Integrated Query) is a query language for .NET and is not used for querying logs in Azure Monitor. XPath is a language for selecting nodes from an XML document and is not relevant for this scenario. WQL (WMI Query Language) is used for querying Windows Management Instrumentation (WMI) data on Windows systems, but not for filtering logs within Azure Monitor.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed