AZ-104 · Question #598
You have an Azure subscription named Subscription1 that contains an Azure Log Analytics workspace named Workspace1. You need to view the error events from a table named Event. Which query should you r
The correct answer is A. search in (Event) "error". To search a term in a specific table, add the table-name just after the search operator. There are several versions of this question in the exam. The question has two possible correct 1. Event | search "error" 2. Event | where EventType == "error" 3. search in (Event) "error" Oth
Question
Options
- Asearch in (Event) "error"
- BEvent | where EventType is "error"
- Cselect * from Event where EventType == "error"
- DGet-Event Event | where {$_.EventType == "error"}
How the community answered
(64 responses)- A70% (45)
- B9% (6)
- C16% (10)
- D5% (3)
Explanation
To search a term in a specific table, add the table-name just after the search operator. There are several versions of this question in the exam. The question has two possible correct 1. Event | search "error" 2. Event | where EventType == "error" 3. search in (Event) "error" Other incorrect answer options you may see on the exam include the following: 1. Get-Event Event | where {$_.EventTye ג €"eq "error"} 2. Event | where EventType is "error" 3. search in (Event) * | where EventType ג €"eq "error" 4. select * from Event where EventType is "error" https://docs.microsoft.com/en-us/azure/azure-monitor/log-query/search-queries https://docs.microsoft.com/en-us/azure/azure-monitor/log-query/get-started-portal https://docs.microsoft.com/en-us/azure/data- explorer/kusto/query/searchoperator?pivots=azuredataexplorer
Topics
Community Discussion
No community discussion yet for this question.