Microsoft Certified: Azure Security Engineer AssociateManage security operationsMedium
A security engineer needs to configure Azure Monitor to detect when a specific security event ID (e.g., Event ID 4625 for failed logins) appears more than 50 times within a 15-minute window from any server connected to a Log Analytics workspace. Which type of alert rule should the engineer create?
- AMetric alert rule
- BAzure Service Health alert rule
- CLog search alert rule
- DActivity log alert rule
Show answer & explanationAnswer & explanation
Correct answer: C. Log search alert rule
Log search alert rules are used to run Kusto queries against data in a Log Analytics workspace and trigger an alert if the query results meet specific criteria, such as a count exceeding a threshold within a time window.
Why the other options are wrong
- A. Metric alerts monitor numerical metrics, not specific event IDs within log data.
- B. Azure Service Health alerts are for Azure service incidents, not custom log event monitoring.
- D. Activity log alerts monitor control-plane events, not granular operating system or application logs.
Azure Monitor Log Search Alerts
Azure Monitor Log Search Alerts trigger when the results of a scheduled Kusto Query Language (KQL) query against Log Analytics data meet a specified condition, such as a count exceeding a threshold.
- Queries log data in Log Analytics workspaces.
- Uses KQL for flexible and powerful query conditions.
- Ideal for detecting specific events, patterns, or trends in logs.
Memory trick: Logs are for searching, metrics are for measuring, activity is for actions, health is for service.