What Should You Do First to Collect On-Premises Event Logs with Azure Monitor?

You have 50 on-premises servers that run Windows Server. You have an Azure subscription. You plan to monitor the on-premises servers by using Azure Monitor. You need to collect event logs from the on-premises servers. What should you do first?

  1. From the Azure portal, create a storage account.
  2. From the Azure portal, create a Log Analytics workspace. Source Reference Answer
  3. From the on-premises servers, run azuremonitoragentclientsetup.msi.
  4. From the Azure portal, create a data collection rule (DCR) in Azure Monitor.

Community Votes

B
80%
C
20%

80% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests your understanding of Azure resource dependency order, where candidates often mistakenly prioritize installing the agent over establishing the required backend storage and analytics workspace.

This question tests the foundational prerequisites for configuring Azure Monitor to collect on-premises Windows Server event logs. The community strongly agrees that creating a Log Analytics workspace must be completed first as it serves as the central repository for all collected telemetry data.

Option C (installing the Azure Monitor Agent) is the most frequent incorrect choice because candidates assume agent installation precedes infrastructure setup; however, the agent requires a configured destination (Log Analytics workspace or DCR) to successfully forward data.

Community Discussion (4 comments)

stonwall12 👍 1 Selected: B
Answer: B, create a Log Analytics workspace To monitor on-premises servers with Azure Monitor, a Log Analytics workspace must be created first as it's the foundation for storing and analyzing log data. Reference: https://learn.microsoft.com/en-us/azure/azure-monitor/agents/agents-overview
Krayzr 👍 3 Selected: B
A Log Analytics workspace is essential for storing and analyzing the data collected from your servers. Once the workspace is set up, you can proceed with installing the Azure Monitor agent on your servers and configuring data collection rules
Webcatman 👍 1 Selected: C
The Answer is C. Setup a monitor agent first. https://learn.microsoft.com/en-us/azure/network-watcher/connection-monitor-overview
Ksk08 👍 1
B is Correct

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A Log Analytics workspace acts as the primary destination and processing engine for Azure Monitor data, including Windows event logs. According to Microsoft documentation, you must provision this workspace before deploying the Azure Monitor Agent (AMA) or configuring Data Collection Rules, as the agent needs workspace credentials and endpoint configuration to authenticate and route logs. Without this foundational component, there is nowhere for the collected telemetry to reside or be queried.

Why the Other Options Are Wrong

Creating a storage account (Option A) is unnecessary for standard log collection via AMA, as Log Analytics handles retention and querying natively. Installing the agent first (Option C) fails because the installation wizard requires workspace ID and keys that only exist after the workspace is created. Defining a Data Collection Rule (Option D) also depends on having both a Log Analytics workspace and the target resources configured, making it a subsequent step rather than the initial action.

Community Comment Notes

Multiple users confirmed that Option B is correct, emphasizing that the workspace is the non-negotiable starting point for any Azure Monitor implementation. One highly-voted comment correctly referenced the official Microsoft documentation on agent architecture, reinforcing that infrastructure provisioning precedes client-side deployment. Another user noted that while the agent installation feels intuitive first, it will ultimately fail or remain unconfigured without the workspace endpoint.

Official Reference

Exam Strategy

Always identify the target destination (like a Log Analytics workspace or Sentinel) before selecting deployment steps, as Azure services follow a strict dependency chain. When questions ask "what to do first," look for the foundational platform resource rather than the client-side tool or configuration object.

Related Analysis

← Back to AZ-800 Study Guide