What Should You Do First to Collect On-Premises Event Logs with Azure Monitor?
You have 50 on-premises servers that run Windows Server. You have an Azure subscription. You plan to monitor the on-premises servers by using Azure Monitor. You need to collect event logs from the on-premises servers. What should you do first?
Community Votes
80% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests your understanding of Azure resource dependency order, where candidates often mistakenly prioritize installing the agent over establishing the required backend storage and analytics workspace.
This question tests the foundational prerequisites for configuring Azure Monitor to collect on-premises Windows Server event logs. The community strongly agrees that creating a Log Analytics workspace must be completed first as it serves as the central repository for all collected telemetry data.
Option C (installing the Azure Monitor Agent) is the most frequent incorrect choice because candidates assume agent installation precedes infrastructure setup; however, the agent requires a configured destination (Log Analytics workspace or DCR) to successfully forward data.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A Log Analytics workspace acts as the primary destination and processing engine for Azure Monitor data, including Windows event logs. According to Microsoft documentation, you must provision this workspace before deploying the Azure Monitor Agent (AMA) or configuring Data Collection Rules, as the agent needs workspace credentials and endpoint configuration to authenticate and route logs. Without this foundational component, there is nowhere for the collected telemetry to reside or be queried.Why the Other Options Are Wrong
Creating a storage account (Option A) is unnecessary for standard log collection via AMA, as Log Analytics handles retention and querying natively. Installing the agent first (Option C) fails because the installation wizard requires workspace ID and keys that only exist after the workspace is created. Defining a Data Collection Rule (Option D) also depends on having both a Log Analytics workspace and the target resources configured, making it a subsequent step rather than the initial action.Community Comment Notes
Multiple users confirmed that Option B is correct, emphasizing that the workspace is the non-negotiable starting point for any Azure Monitor implementation. One highly-voted comment correctly referenced the official Microsoft documentation on agent architecture, reinforcing that infrastructure provisioning precedes client-side deployment. Another user noted that while the agent installation feels intuitive first, it will ultimately fail or remain unconfigured without the workspace endpoint.Official Reference
Exam Strategy
Always identify the target destination (like a Log Analytics workspace or Sentinel) before selecting deployment steps, as Azure services follow a strict dependency chain. When questions ask "what to do first," look for the foundational platform resource rather than the client-side tool or configuration object.