You have an Azure subscription. The subscription contains virtual machines that run Windows Server.
You have a data collection rule (DCR) named Rule1.
You plan to use the Azure Monitor Agent to collect events from Windows System event logs.
You only need to collect system events that have an ID of 1001.
Which type of query should you use for the data source in Rule1?
SgtDumitru
Highly Voted 1 year, 6 months agoki01
1 year, 6 months ago[Removed]
Highly Voted 1 year, 6 months agoc75e123
5 months, 3 weeks agoJosh219
Most Recent 6 months, 4 weeks ago[Removed]
8 months, 1 week ago0378d43
8 months, 1 week agoDebugs_Bunny
9 months, 1 week agolearnazureportal
1 year agoAmir1909
1 year, 2 months agoGoldBear
1 year, 6 months agoOrangeSG
1 year, 7 months agoPeter6529
1 year, 8 months agoVestibal
1 year, 8 months agoHillah
1 year, 8 months agoXtraWest
1 year, 8 months agoShaanwar2001
1 year, 8 months agoKMLearn2
1 year, 8 months agoNighty470
1 year, 8 months agoNighty470
1 year, 8 months ago