Build Lab196 words

Lab — Find out what you can and cannot see about yesterday

AZ-104 › Unit 5 › Lab

Lab — Find out what you can and cannot see about yesterday

Lab brief

AZ104-U5.T1
25 minutes
A resource group, a diagnostic setting, an alert rule and an action group
required
Core

The claim to make physical: turning collection on today tells you nothing about yesterday. This is the single most common wrong answer in Unit 5 and it takes ten minutes to become permanent knowledge.

Before you start

A subscription and any existing resource with no diagnostic setting on it — a resource group is enough for the activity-log half. A Log Analytics workspace is optional and the free ingestion allowance covers this lab's volume; skip it if you would rather not create one.

Walkthrough

Find out what you can and cannot see about yesterday

  1. 1. Read the activity log for something you did last week

    Query the activity log for an operation from several days ago. It is there. The activity log is automatically collected without configuration — you never turned it on.

Did it teach you what it was meant to?

Multiple choice · HardRetroactive collection

An incident happened last Tuesday on a resource that has never had a diagnostic setting. What can you actually investigate?

Multiple choice · MediumAlert objects

An alert rule is firing hourly and the on-call engineer wants it quiet tonight without losing the detection. Which object?

What goes wrong

Tear it down

Run this whether or not the lab worked. Everything above was chosen to cost approximately nothing, and leaving it in place is how approximately nothing becomes something.

Teardown

  1. Delete the rule, the action group, the setting, then the group

    Delete in that order, because the rule references the action group. If you created a Log Analytics workspace, delete it too — an idle workspace ingests nothing, but leaving one is how a free lab becomes a line on a bill.

Where these figures come from

Every figure above was read from the raw documentation below on the day this sheet was written. The sha1 is git hash-object over the bytes as fetched, so a doc that changes underneath this sheet can be detected rather than assumed.

Ready to study Microsoft Azure Administrator (AZ-104)?

Practice tests, flashcards, and all study notes — free, no sign-up needed.

Start Studying — Free