Microsoft Certified: DevOps Engineer ExpertImplement an instrumentation strategyHard
A company is deploying a new application to Azure App Service and needs to capture all HTTP request logs, including detailed information about client IP addresses, user agents, and response times. These logs must be retained for at least 90 days for auditing purposes and be easily queryable. They also need to ensure that the logging solution is cost-effective for high-volume traffic. Which logging destination should be configured for the App Service diagnostics settings?
- AAzure SQL Database
- BLog Analytics workspace
- CEvent Hubs
- DStorage Account (Blob Storage)
Show answer & explanationAnswer & explanation
Correct answer: B. Log Analytics workspace
While Blob Storage can retain logs for 90 days, it lacks easy querying. Event Hubs is for streaming, not storage and querying. Azure SQL Database is not a cost-effective or scalable solution for high-volume raw logs. Log Analytics workspace is purpose-built for collecting, retaining (configurable retention, up to 730 days), and querying high-volume diagnostic logs, making it the most suitable and cost-effective choice for detailed, queryable logs for 90+ days.
Why the other options are wrong
- A. Azure SQL Database is not designed or cost-optimized for storing and querying high-volume raw application logs; it would be expensive and inefficient.
- C. Event Hubs is for real-time streaming; it does not store logs for querying over 90 days without a consumer service.
- D. Blob Storage is cost-effective for long-term archival but lacks native querying capabilities for high-volume log data without additional services.
Log Analytics Workspace for Diagnostics
A centralized log repository in Azure Monitor that collects diagnostic and performance data from various Azure resources, enabling powerful analysis and long-term retention.
- Scalable for high volumes of log data.
- Offers flexible data retention policies (up to 730 days).
- Supports Kusto Query Language (KQL) for complex queries.
Memory trick: Log Analytics: Store, Query, Analyze, Repeat.