An enterprise is designing a comprehensive monitoring and log routing architecture for various workloads across Azure subscriptions. You need to match the administrative and operational requirements with the most appropriate Azure Monitor destination or feature to minimize costs and administrative overhead.
Match the requirements on the left to their corresponding destinations or features on the right.
- Retain application diagnostic logs for seven years to meet regulatory compliance while minimizing storage costs.Azure Storage account with lifecycle management policies
- Collect, correlate, and run complex Kusto Query Language (KQL) queries on resource telemetry across multiple subscriptions.Azure Monitor Log Analytics workspace
- Stream Azure resource logs in near-real-time to an external third-party Security Information and Event Management (SIEM) system.Azure Event Hubs
- Monitor IP traffic patterns, identify traffic hotspots, and analyze security group rule hits for virtual networks.Azure Network Watcher Traffic Analytics
Cevap
The correct matches are: (1) Retaining logs for seven years to minimize costs matches Azure Storage account; (2) Running KQL queries and correlating telemetry matches Azure Monitor Log Analytics workspace; (3) Streaming logs to an external SIEM matches Azure Event Hubs; (4) Monitoring IP traffic patterns and NSG rules matches Azure Network Watcher Traffic Analytics.
Each requirement maps to a specific destination in Azure Monitor: Azure Storage accounts provide low-cost long-term archiving; Log Analytics workspaces enable centralized KQL querying; Azure Event Hubs provides near-real-time integration with external SIEMs; and Traffic Analytics processes NSG flow logs to analyze network traffic patterns.
Adım Adım Çözüm
Anahtar Kavram
Matching Azure log sources and regulatory requirements to the correct Azure Monitor diagnostic destinations.
Tahmini Süre:2m 0s