When using the Azure Monitor Agent and a data collection rule to collect only Windows System event log entries with event ID 1001, which query type should you use for the data source?
Choose an answer
Tap an option to check your answer.
Correct answer: XPath.
Why this is the answer
XPath is the correct query type because it is specifically designed for selecting nodes from an XML document, and Windows event logs are stored in an XML-based format. Using an XPath query allows you to precisely filter for specific event IDs, such as 1001, within the event log data. SQL is for relational databases, not event logs. KQL (Kusto Query Language) is used for querying data that has already been ingested into Azure Monitor Logs, not for defining the initial collection filter at the data source level for the Azure Monitor Agent.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed