A new lock-lab virtual machine has Azure Monitor Agent installed, but security events never appear even though a data collection rule already exists. What is the most likely missing step?
Select an answer to reveal the explanation.
Short Explanation
A lonely DCR is just paperwork. Associate it to the VM—or scale set or Arc machine—or nothing gets collected, agent or not.
Full Explanation
Creating a data collection rule does not collect data until the rule is associated with the target virtual machine, virtual machine scale set, or Azure Arc machine (directly or via policy-deployed association). Without association, Azure Monitor Agent has no applicable rule. Switching back to MMA, removing the workspace destination, or converting the DCR into a Defender recommendation does not fix missing association.