You have an Azure subscription. The subscription contains virtual machines that run Windows Server.
You have a data collection rule (DCR) named Rule1.
You plan to use the Azure Monitor Agent to collect events from Windows System event logs.
You only need to collect system events that have an ID of 1001.
Which type of query should you use for the data source in Rule1?
SgtDumitru
Highly Voted 1 year agoki01
11 months, 3 weeks ago[Removed]
Highly Voted 11 months, 3 weeks agoJosh219
Most Recent 1 week, 6 days agoSeMo0o0o0o
1 month, 3 weeks ago0378d43
1 month, 3 weeks agoDebugs_Bunny
2 months, 3 weeks agolearnazureportal
5 months, 2 weeks agoAmir1909
8 months, 2 weeks agoGoldBear
12 months agoOrangeSG
1 year, 1 month agoPeter6529
1 year, 1 month agoVestibal
1 year, 1 month agoHillah
1 year, 1 month agoXtraWest
1 year, 2 months agoShaanwar2001
1 year, 2 months agoKMLearn2
1 year, 2 months agoNighty470
1 year, 2 months agoNighty470
1 year, 2 months ago