You have an Azure subscription. The subscription contains virtual machines that run Windows Server.
You have a data collection rule (DCR) named Rule1.
You plan to use the Azure Monitor Agent to collect events from Windows System event logs.
You only need to collect system events that have an ID of 1001.
Which type of query should you use for the data source in Rule1?
SgtDumitru
Highly Voted 1 year, 5 months agoki01
1 year, 4 months ago[Removed]
Highly Voted 1 year, 4 months agoc75e123
4 months, 1 week agoJosh219
Most Recent 5 months, 1 week ago[Removed]
6 months, 3 weeks ago0378d43
6 months, 4 weeks agoDebugs_Bunny
7 months, 3 weeks agolearnazureportal
10 months, 3 weeks agoAmir1909
1 year, 1 month agoGoldBear
1 year, 4 months agoOrangeSG
1 year, 6 months agoPeter6529
1 year, 6 months agoVestibal
1 year, 6 months agoHillah
1 year, 6 months agoXtraWest
1 year, 6 months agoShaanwar2001
1 year, 7 months agoKMLearn2
1 year, 7 months agoNighty470
1 year, 7 months agoNighty470
1 year, 7 months ago