You have an Azure Log Analytics workspace that collects security-related performance counters from 100 on-premises Windows servers. You must create alerts that support dimensions, minimize time to generate an alert, and produce a single notification when the alert is created and one when it is resolved. Which signal type should you use for the alert rules?
Choose an answer
Tap an option to check your answer.
Correct answer: Metric.
Why this is the answer
The correct answer is Metric. Azure Monitor Metric alerts are designed for time-series data, like performance counters. They support dimensions, which allow for more granular alerting based on specific characteristics (e.g., individual servers). Metric alerts also minimize the time to generate an alert because they process data more efficiently than log queries for this type of data. Crucially, they offer stateful alerting, meaning they can send a single notification when the alert condition is met and another when it resolves. Log and Log (Saved Query) alerts are based on data ingested into Log Analytics. While they are powerful for complex analysis, they generally have higher latency for alerting compared to metric alerts and are less efficient for simple performance counter monitoring. They are also not inherently stateful in the same way metric alerts are for resolution notifications. Activity Log alerts are used for events in the Azure Activity Log, such as resource creation or deletion, not for performance counters from virtual machines.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed