Bird
Raised Fist0
Azurecloud~10 mins

Diagnostic settings for resources in Azure - Step-by-Step Execution

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Process Flow - Diagnostic settings for resources
Start: Select Resource
↓
Create Diagnostic Setting
↓
Choose Logs & Metrics
↓
Select Destination(s)
↓
Save Configuration
↓
Diagnostic Data Sent
↓
Monitor & Analyze Data
This flow shows how to set up diagnostic settings on a resource to collect logs and metrics and send them to chosen destinations for monitoring.
Execution Sample
Azure
az monitor diagnostic-settings create \
  --resource /subscriptions/123/resourceGroups/myRG/providers/Microsoft.Compute/virtualMachines/myVM \
  --name myDiagSetting \
  --logs '[{"category": "Administrative", "enabled": true}]' \
  --metrics '[{"category": "AllMetrics", "enabled": true}]' \
  --workspace /subscriptions/123/resourceGroups/myRG/providers/Microsoft.OperationalInsights/workspaces/myWorkspace
Creates a diagnostic setting on a VM resource to send logs and metrics to a Log Analytics workspace.
Process Table
StepActionInput/ParameterResult/State
1Select Resource/subscriptions/123/resourceGroups/myRG/providers/Microsoft.Compute/virtualMachines/myVMResource identified for diagnostics
2Create Diagnostic SettingName: myDiagSettingDiagnostic setting object created
3Configure LogsCategory: Administrative, Enabled: trueLogs collection enabled for Administrative category
4Configure MetricsCategory: AllMetrics, Enabled: trueMetrics collection enabled for all metrics
5Set DestinationWorkspace: myWorkspaceDestination set to Log Analytics workspace
6Save ConfigurationApply settingsDiagnostic settings saved and active
7Data FlowLogs and metrics sentData flows to workspace for monitoring
8EndN/ASetup complete, monitoring enabled
💡 Diagnostic settings saved and data flow started; monitoring active
Status Tracker
VariableStartAfter Step 2After Step 3After Step 4After Step 5Final
resourceNone/subscriptions/123/resourceGroups/myRG/providers/Microsoft.Compute/virtualMachines/myVM/subscriptions/123/resourceGroups/myRG/providers/Microsoft.Compute/virtualMachines/myVM/subscriptions/123/resourceGroups/myRG/providers/Microsoft.Compute/virtualMachines/myVM/subscriptions/123/resourceGroups/myRG/providers/Microsoft.Compute/virtualMachines/myVM/subscriptions/123/resourceGroups/myRG/providers/Microsoft.Compute/virtualMachines/myVM
diagnosticSettingNameNonemyDiagSettingmyDiagSettingmyDiagSettingmyDiagSettingmyDiagSetting
logsConfigNoneNone[{"category": "Administrative", "enabled": true}][{"category": "Administrative", "enabled": true}][{"category": "Administrative", "enabled": true}][{"category": "Administrative", "enabled": true}]
metricsConfigNoneNoneNone[{"category": "AllMetrics", "enabled": true}][{"category": "AllMetrics", "enabled": true}][{"category": "AllMetrics", "enabled": true}]
destinationNoneNoneNoneNone/subscriptions/123/resourceGroups/myRG/providers/Microsoft.OperationalInsights/workspaces/myWorkspace/subscriptions/123/resourceGroups/myRG/providers/Microsoft.OperationalInsights/workspaces/myWorkspace
Key Moments - 3 Insights
Why do we need to specify both logs and metrics categories separately?
Logs and metrics are different types of data; enabling one does not automatically enable the other. See execution_table rows 3 and 4 where logs and metrics are configured separately.
What happens if we do not specify a destination for diagnostic data?
Without a destination, diagnostic data has nowhere to go and will not be collected or stored. Execution_table row 5 shows setting the destination is essential before saving.
Can we send diagnostic data to multiple destinations at once?
Yes, diagnostic settings support multiple destinations like Log Analytics, Event Hub, and Storage. This example shows one destination, but you can add more before saving (see step 5).
Visual Quiz - 3 Questions
Test your understanding
Look at the execution_table, at which step are logs enabled for the resource?
AStep 3
BStep 2
CStep 4
DStep 5
💡 Hint
Check the 'Action' and 'Result/State' columns in execution_table row 3.
According to variable_tracker, what is the value of 'destination' after step 4?
A/subscriptions/123/resourceGroups/myRG/providers/Microsoft.OperationalInsights/workspaces/myWorkspace
BNone
CmyDiagSetting
DAdministrative
💡 Hint
Look at the 'destination' row and the column 'After Step 4' in variable_tracker.
If we skip setting the destination, what will happen according to the key moments?
AOnly metrics will be collected, not logs.
BDiagnostic data will still be collected and stored automatically.
CDiagnostic data will not be collected or stored.
DThe diagnostic setting will fail to save.
💡 Hint
Refer to key_moments question 2 about the importance of setting a destination.
Concept Snapshot
Diagnostic settings collect logs and metrics from Azure resources.
You configure categories of logs and metrics separately.
Set one or more destinations like Log Analytics workspace.
Save settings to start sending diagnostic data.
This helps monitor and analyze resource health and activity.
Full Transcript
Diagnostic settings in Azure allow you to collect logs and metrics from resources. The process starts by selecting the resource, then creating a diagnostic setting with a name. You enable specific log categories and metric categories separately. Next, you choose where to send this data, such as a Log Analytics workspace. After saving, the diagnostic data flows to the destination for monitoring. Variables like resource, diagnosticSettingName, logsConfig, metricsConfig, and destination change step-by-step as you configure. Key points include the need to enable logs and metrics separately, the necessity of specifying a destination, and the option to send data to multiple destinations. This setup helps you keep track of resource health and troubleshoot issues effectively.

Practice

(1/5)
1. What is the main purpose of Diagnostic settings in Azure resources?
easy
A. To collect logs and metrics for monitoring and troubleshooting
B. To create virtual machines automatically
C. To manage user access permissions
D. To deploy web applications

Solution

  1. Step 1: Understand diagnostic settings role

    Diagnostic settings collect logs and metrics from Azure resources to help monitor and troubleshoot.
  2. Step 2: Compare options with purpose

    Options A, B, and C describe other Azure features unrelated to diagnostics.
  3. Final Answer:

    To collect logs and metrics for monitoring and troubleshooting -> Option A
  4. Quick Check:

    Diagnostic settings = collect logs and metrics [OK]
Hint: Diagnostic settings always collect logs and metrics [OK]
Common Mistakes:
  • Confusing diagnostic settings with access control
  • Thinking diagnostic settings deploy resources
  • Assuming diagnostic settings manage applications
2. Which of the following is the correct way to specify a diagnostic setting destination in Azure CLI?
easy
A. az network watcher configure --name MyDiag --resource MyResource --workspace MyWorkspace
B. az vm create --name MyDiag --resource MyResource --workspace MyWorkspace
C. az storage account create --name MyDiag --resource MyResource --workspace MyWorkspace
D. az monitor diagnostic-settings create --name MyDiag --resource MyResource --workspace MyWorkspace

Solution

  1. Step 1: Identify correct Azure CLI command for diagnostic settings

    The command az monitor diagnostic-settings create is used to create diagnostic settings.
  2. Step 2: Verify other commands

    Commands for VM, storage account, and network watcher do not create diagnostic settings.
  3. Final Answer:

    az monitor diagnostic-settings create --name MyDiag --resource MyResource --workspace MyWorkspace -> Option D
  4. Quick Check:

    Diagnostic settings use az monitor diagnostic-settings create [OK]
Hint: Use 'az monitor diagnostic-settings create' to configure diagnostics [OK]
Common Mistakes:
  • Using VM or storage commands instead of monitor diagnostic-settings
  • Confusing resource creation with diagnostic configuration
  • Missing required parameters for diagnostic settings
3. Given this Azure CLI command:
az monitor diagnostic-settings create --name Diag1 --resource /subscriptions/123/resourceGroups/rg1/providers/Microsoft.Compute/virtualMachines/vm1 --workspace ws1 --logs '[{"category": "Administrative", "enabled": true}]'

What will this command do?
medium
A. Create a new virtual machine named Diag1
B. Enable Administrative logs to be sent to Log Analytics workspace ws1 for VM vm1
C. Disable all logs for the virtual machine vm1
D. Send metrics only to storage account ws1

Solution

  1. Step 1: Analyze command parameters

    The command creates diagnostic settings named Diag1 for VM vm1, sending logs to workspace ws1, enabling Administrative logs.
  2. Step 2: Interpret log category and destination

    Logs category "Administrative" is enabled and sent to Log Analytics workspace ws1.
  3. Final Answer:

    Enable Administrative logs to be sent to Log Analytics workspace ws1 for VM vm1 -> Option B
  4. Quick Check:

    Diagnostic settings send logs to workspace = Enable Administrative logs to be sent to Log Analytics workspace ws1 for VM vm1 [OK]
Hint: Look for --logs and --workspace to identify log destination [OK]
Common Mistakes:
  • Thinking it creates a VM instead of diagnostic settings
  • Confusing logs with metrics or storage
  • Assuming logs are disabled
4. You tried to create a diagnostic setting with this command:
az monitor diagnostic-settings create --name Diag2 --resource /subscriptions/123/resourceGroups/rg1/providers/Microsoft.Storage/storageAccounts/sa1 --storage-account sa1 --metrics '[{"category": "AllMetrics", "enabled": true}]'

But you get an error. What is the most likely cause?
medium
A. Diagnostic settings cannot send metrics to storage accounts
B. The metrics category "AllMetrics" is invalid
C. The storage account name is missing or incorrect
D. The resource ID format is wrong

Solution

  1. Step 1: Understand diagnostic settings destinations

    Diagnostic settings can send logs and metrics to Log Analytics, Storage, or Event Hub. The --storage-account parameter requires the full ARM resource ID of the storage account.
  2. Step 2: Check command parameters

    The command specifies --storage-account sa1, which is only the short name and cannot be resolved by the CLI.
  3. Final Answer:

    The storage account name is missing or incorrect -> Option C
  4. Quick Check:

    --storage-account requires full ID [OK]
Hint: Use full ARM ID for --storage-account [OK]
Common Mistakes:
  • Using short name instead of full resource ID for --storage-account
  • Thinking metrics cannot be sent to storage accounts
  • Assuming invalid metrics category or wrong resource ID
5. You want to monitor an Azure SQL Database and send both logs and metrics to a Log Analytics workspace. Which combination of diagnostic settings configuration is correct?
hard
A. Enable logs categories 'SQLSecurityAuditEvents' and 'SQLInsights' and enable metrics category 'AllMetrics' with destination set to Log Analytics workspace
B. Enable only logs categories and send to Storage account
C. Enable metrics only and send to Event Hub
D. Enable logs and metrics but send logs to Storage and metrics to Log Analytics workspace

Solution

  1. Step 1: Identify correct log and metric categories for Azure SQL Database

    Logs like 'SQLSecurityAuditEvents' and 'SQLInsights' and metrics 'AllMetrics' are valid categories for Azure SQL Database diagnostics.
  2. Step 2: Confirm destination for logs and metrics

    Both logs and metrics can be sent to Log Analytics workspace for monitoring and analysis.
  3. Final Answer:

    Enable logs categories 'SQLSecurityAuditEvents' and 'SQLInsights' and enable metrics category 'AllMetrics' with destination set to Log Analytics workspace -> Option A
  4. Quick Check:

    Logs and metrics to Log Analytics = Enable logs categories 'SQLSecurityAuditEvents' and 'SQLInsights' and enable metrics category 'AllMetrics' with destination set to Log Analytics workspace [OK]
Hint: Send both logs and metrics to Log Analytics for full monitoring [OK]
Common Mistakes:
  • Sending logs to storage but metrics elsewhere
  • Enabling only logs or only metrics
  • Using wrong categories for Azure SQL Database