Bird
Raised Fist0
Azurecloud~5 mins

Diagnostic settings for resources in Azure - Commands & Configuration

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Introduction
Diagnostic settings help you collect logs and metrics from your cloud resources. This lets you see what is happening inside your resources and fix problems quickly.
When you want to track how your virtual machines are performing over time.
When you need to collect logs from your storage accounts to check for access or errors.
When you want to send resource logs to a central place like a storage account or Log Analytics.
When you want to monitor your app services for errors and usage patterns.
When you want to keep a record of resource activity for security audits.
Config File - diagnostic-settings.json
diagnostic-settings.json
{
  "type": "Microsoft.Insights/diagnosticSettings",
  "apiVersion": "2021-05-01-preview",
  "name": "myResourceDiagnosticSetting",
  "properties": {
    "storageAccountId": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/example-rg/providers/Microsoft.Storage/storageAccounts/examplestorage",
    "workspaceId": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/example-rg/providers/Microsoft.OperationalInsights/workspaces/example-workspace",
    "logs": [
      {
        "category": "Administrative",
        "enabled": true,
        "retentionPolicy": {
          "enabled": false,
          "days": 0
        }
      },
      {
        "category": "Security",
        "enabled": true,
        "retentionPolicy": {
          "enabled": false,
          "days": 0
        }
      }
    ],
    "metrics": [
      {
        "category": "AllMetrics",
        "enabled": true,
        "retentionPolicy": {
          "enabled": false,
          "days": 0
        }
      }
    ]
  }
}

This JSON defines a diagnostic setting named myResourceDiagnosticSetting.

storageAccountId: Where logs are stored as files.

workspaceId: Where logs and metrics are sent for analysis.

logs: Lists which log categories to collect and if retention is enabled.

metrics: Lists which metrics to collect and retention policy.

Commands
This command creates a diagnostic setting for the virtual machine named example-vm. It sends logs to the storage account and workspace specified. It enables Administrative and Security logs and all metrics.
Terminal
az monitor diagnostic-settings create --resource /subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/example-rg/providers/Microsoft.Compute/virtualMachines/example-vm --name myResourceDiagnosticSetting --storage-account examplestorage --workspace example-workspace --logs '[{"category":"Administrative","enabled":true},{"category":"Security","enabled":true}]' --metrics '[{"category":"AllMetrics","enabled":true}]'
Expected OutputExpected
{ "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/example-rg/providers/Microsoft.Compute/virtualMachines/example-vm/providers/microsoft.insights/diagnosticSettings/myResourceDiagnosticSetting", "name": "myResourceDiagnosticSetting", "type": "Microsoft.Insights/diagnosticSettings" }
→
--resource - Specifies the full ID of the resource to monitor
→
--name - Names the diagnostic setting
→
--logs - Defines which log categories to collect
This command lists all diagnostic settings configured for the example-vm virtual machine. It helps verify the settings were applied.
Terminal
az monitor diagnostic-settings list --resource /subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/example-rg/providers/Microsoft.Compute/virtualMachines/example-vm
Expected OutputExpected
[ { "name": "myResourceDiagnosticSetting", "logs": [ { "category": "Administrative", "enabled": true }, { "category": "Security", "enabled": true } ], "metrics": [ { "category": "AllMetrics", "enabled": true } ] } ]
→
--resource - Specifies the resource to check
Key Concept

If you remember nothing else from this pattern, remember: diagnostic settings connect your resource to storage or analytics so you can see its logs and metrics.

Common Mistakes
Not specifying the full resource ID with --resource flag
The command fails because it does not know which resource to apply the diagnostic setting to.
Always provide the full resource ID path for the --resource flag.
Forgetting to enable specific log categories in the --logs flag
No logs are collected if categories are not enabled, so you get no data.
Specify the log categories you want to collect and set enabled to true.
Summary
Create diagnostic settings using az monitor diagnostic-settings create with resource ID, storage account, and log categories.
Verify diagnostic settings with az monitor diagnostic-settings list to ensure logs and metrics are enabled.
Diagnostic settings help collect logs and metrics from Azure resources for monitoring and troubleshooting.

Practice

(1/5)
1. What is the main purpose of Diagnostic settings in Azure resources?
easy
A. To collect logs and metrics for monitoring and troubleshooting
B. To create virtual machines automatically
C. To manage user access permissions
D. To deploy web applications

Solution

  1. Step 1: Understand diagnostic settings role

    Diagnostic settings collect logs and metrics from Azure resources to help monitor and troubleshoot.
  2. Step 2: Compare options with purpose

    Options A, B, and C describe other Azure features unrelated to diagnostics.
  3. Final Answer:

    To collect logs and metrics for monitoring and troubleshooting -> Option A
  4. Quick Check:

    Diagnostic settings = collect logs and metrics [OK]
Hint: Diagnostic settings always collect logs and metrics [OK]
Common Mistakes:
  • Confusing diagnostic settings with access control
  • Thinking diagnostic settings deploy resources
  • Assuming diagnostic settings manage applications
2. Which of the following is the correct way to specify a diagnostic setting destination in Azure CLI?
easy
A. az network watcher configure --name MyDiag --resource MyResource --workspace MyWorkspace
B. az vm create --name MyDiag --resource MyResource --workspace MyWorkspace
C. az storage account create --name MyDiag --resource MyResource --workspace MyWorkspace
D. az monitor diagnostic-settings create --name MyDiag --resource MyResource --workspace MyWorkspace

Solution

  1. Step 1: Identify correct Azure CLI command for diagnostic settings

    The command az monitor diagnostic-settings create is used to create diagnostic settings.
  2. Step 2: Verify other commands

    Commands for VM, storage account, and network watcher do not create diagnostic settings.
  3. Final Answer:

    az monitor diagnostic-settings create --name MyDiag --resource MyResource --workspace MyWorkspace -> Option D
  4. Quick Check:

    Diagnostic settings use az monitor diagnostic-settings create [OK]
Hint: Use 'az monitor diagnostic-settings create' to configure diagnostics [OK]
Common Mistakes:
  • Using VM or storage commands instead of monitor diagnostic-settings
  • Confusing resource creation with diagnostic configuration
  • Missing required parameters for diagnostic settings
3. Given this Azure CLI command:
az monitor diagnostic-settings create --name Diag1 --resource /subscriptions/123/resourceGroups/rg1/providers/Microsoft.Compute/virtualMachines/vm1 --workspace ws1 --logs '[{"category": "Administrative", "enabled": true}]'

What will this command do?
medium
A. Create a new virtual machine named Diag1
B. Enable Administrative logs to be sent to Log Analytics workspace ws1 for VM vm1
C. Disable all logs for the virtual machine vm1
D. Send metrics only to storage account ws1

Solution

  1. Step 1: Analyze command parameters

    The command creates diagnostic settings named Diag1 for VM vm1, sending logs to workspace ws1, enabling Administrative logs.
  2. Step 2: Interpret log category and destination

    Logs category "Administrative" is enabled and sent to Log Analytics workspace ws1.
  3. Final Answer:

    Enable Administrative logs to be sent to Log Analytics workspace ws1 for VM vm1 -> Option B
  4. Quick Check:

    Diagnostic settings send logs to workspace = Enable Administrative logs to be sent to Log Analytics workspace ws1 for VM vm1 [OK]
Hint: Look for --logs and --workspace to identify log destination [OK]
Common Mistakes:
  • Thinking it creates a VM instead of diagnostic settings
  • Confusing logs with metrics or storage
  • Assuming logs are disabled
4. You tried to create a diagnostic setting with this command:
az monitor diagnostic-settings create --name Diag2 --resource /subscriptions/123/resourceGroups/rg1/providers/Microsoft.Storage/storageAccounts/sa1 --storage-account sa1 --metrics '[{"category": "AllMetrics", "enabled": true}]'

But you get an error. What is the most likely cause?
medium
A. Diagnostic settings cannot send metrics to storage accounts
B. The metrics category "AllMetrics" is invalid
C. The storage account name is missing or incorrect
D. The resource ID format is wrong

Solution

  1. Step 1: Understand diagnostic settings destinations

    Diagnostic settings can send logs and metrics to Log Analytics, Storage, or Event Hub. The --storage-account parameter requires the full ARM resource ID of the storage account.
  2. Step 2: Check command parameters

    The command specifies --storage-account sa1, which is only the short name and cannot be resolved by the CLI.
  3. Final Answer:

    The storage account name is missing or incorrect -> Option C
  4. Quick Check:

    --storage-account requires full ID [OK]
Hint: Use full ARM ID for --storage-account [OK]
Common Mistakes:
  • Using short name instead of full resource ID for --storage-account
  • Thinking metrics cannot be sent to storage accounts
  • Assuming invalid metrics category or wrong resource ID
5. You want to monitor an Azure SQL Database and send both logs and metrics to a Log Analytics workspace. Which combination of diagnostic settings configuration is correct?
hard
A. Enable logs categories 'SQLSecurityAuditEvents' and 'SQLInsights' and enable metrics category 'AllMetrics' with destination set to Log Analytics workspace
B. Enable only logs categories and send to Storage account
C. Enable metrics only and send to Event Hub
D. Enable logs and metrics but send logs to Storage and metrics to Log Analytics workspace

Solution

  1. Step 1: Identify correct log and metric categories for Azure SQL Database

    Logs like 'SQLSecurityAuditEvents' and 'SQLInsights' and metrics 'AllMetrics' are valid categories for Azure SQL Database diagnostics.
  2. Step 2: Confirm destination for logs and metrics

    Both logs and metrics can be sent to Log Analytics workspace for monitoring and analysis.
  3. Final Answer:

    Enable logs categories 'SQLSecurityAuditEvents' and 'SQLInsights' and enable metrics category 'AllMetrics' with destination set to Log Analytics workspace -> Option A
  4. Quick Check:

    Logs and metrics to Log Analytics = Enable logs categories 'SQLSecurityAuditEvents' and 'SQLInsights' and enable metrics category 'AllMetrics' with destination set to Log Analytics workspace [OK]
Hint: Send both logs and metrics to Log Analytics for full monitoring [OK]
Common Mistakes:
  • Sending logs to storage but metrics elsewhere
  • Enabling only logs or only metrics
  • Using wrong categories for Azure SQL Database