An organization has several virtual machines and web applications running in Azure. The security operations team requires all application transaction logs to be streamed to a third-party Security Information and Event Management (SIEM) system located on-premises in near real-time. Which destination should you configure in the Azure Monitor diagnostic settings to meet this requirement?
- AAn Azure Log Analytics workspace
- An Azure event hubAnswer
- CAn Azure Storage account
- DAn Azure Service Bus queue
Answer
An Azure event hub
An Azure event hub is the correct destination because Azure Monitor diagnostic settings natively support routing logs to Event Hubs. This configuration enables immediate ingestion and streaming of telemetry to third-party on-premises or cloud-based SIEM systems.
Step-by-Step Solution
Key Concept
Azure Monitor diagnostic settings export destinations