Capacity planning needs CPU counters from canal VMs while the SOC needs failed logon events in the same Log Analytics workspace. How should the Azure security engineer configure collection?
Select an answer to reveal the explanation.
Short Explanation
CPU counters and failed logons are different streams—don’t pretend Activity logs cover both. Put performance counters and Windows events or syslog in your DCR (or split DCRs) and send them to Log Analytics.
Full Explanation
A data collection rule can include performance counters for capacity metrics and Windows events or syslog for security telemetry, either in one DCR or in separate DCRs, with a Log Analytics workspace destination. Azure Activity logs and Network Watcher tools do not replace host performance and security-event streams. UEBA notebooks are beyond the AZ-500 enable-and-configure DCR skill for this item.