Microsoft Certified: Azure Administrator AssociateMonitor and maintain Azure resourcesMedium
A developer is building a new application that will run on Azure Kubernetes Service (AKS). They need to ensure that all application logs are centralized for analysis and troubleshooting. The logs should be retained for 90 days and be easily queryable using KQL. Which Azure service should they integrate with AKS to meet these requirements?
- AAzure Monitor Logs (Log Analytics workspace)
- BAzure Storage Account
- CAzure Data Explorer
- DAzure Event Hubs
Show answer & explanationAnswer & explanation
Correct answer: A. Azure Monitor Logs (Log Analytics workspace)
Azure Monitor Logs, powered by a Log Analytics workspace, provides a centralized repository for logs, supports KQL for querying, and offers configurable retention periods, making it ideal for AKS application log management.
Why the other options are wrong
- B. Azure Storage Account can store logs, but it doesn't provide built-in KQL querying capabilities or advanced analytics features.
- C. Azure Data Explorer is a powerful analytics service for big data, but for general operational log management and querying with KQL, Log Analytics is the primary and more integrated solution within Azure Monitor.
- D. Azure Event Hubs is a streaming data platform for ingesting large volumes of data, not primarily for centralized storage and interactive querying of logs.
Log Analytics Workspace
A unique environment within Azure Monitor Logs where log data from various Azure resources, on-premises resources, and other cloud environments is collected, indexed, and stored for analysis and querying.
- Centralized log collection point.
- Uses Kusto Query Language (KQL) for powerful querying.
- Configurable data retention and export options.
- Foundation for many Azure Monitor features like alerts and workbooks.
Memory trick: Logs in the workspace, KQL queries embrace, insights in their place.