Lab — Find out what you can and cannot see about yesterday
AZ-104 › Unit 5 › Lab
Lab — Find out what you can and cannot see about yesterday
Lab brief
- AZ104-U5.T1
- 25 minutes
- A resource group, a diagnostic setting, an alert rule and an action group
- required
- Core
The claim to make physical: turning collection on today tells you nothing about yesterday. This is the single most common wrong answer in Unit 5 and it takes ten minutes to become permanent knowledge.
Before you start
A subscription and any existing resource with no diagnostic setting on it — a resource group is enough for the activity-log half. A Log Analytics workspace is optional and the free ingestion allowance covers this lab's volume; skip it if you would rather not create one.
Walkthrough
Find out what you can and cannot see about yesterday
1. Read the activity log for something you did last week
Query the activity log for an operation from several days ago. It is there. The activity log is automatically collected without configuration — you never turned it on.
Did it teach you what it was meant to?
An incident happened last Tuesday on a resource that has never had a diagnostic setting. What can you actually investigate?
An alert rule is firing hourly and the on-call engineer wants it quiet tonight without losing the detection. Which object?
What goes wrong
Tear it down
Run this whether or not the lab worked. Everything above was chosen to cost approximately nothing, and leaving it in place is how approximately nothing becomes something.
Teardown
Delete the rule, the action group, the setting, then the group
Delete in that order, because the rule references the action group. If you created a Log Analytics workspace, delete it too — an idle workspace ingests nothing, but leaving one is how a free lab becomes a line on a bill.
Where these figures come from
Every figure above was read from the raw documentation below on the day this sheet was written. The sha1 is git hash-object over the bytes as fetched, so a doc that changes underneath this sheet can be detected rather than assumed.
| Document | sha1 |
|---|---|
| Diagnostic settings in Azure Monitor | 123baaa50c7f |
| What are Azure Monitor alerts? | 7080cb554190 |