az-104 Practice Question 727

Exam: az-104
Domain: Describe Azure management and governance
Topic: Describe monitoring tools in Azure
Difficulty: medium
You have an Azure subscription named Subscription1 that contains an Azure Log Analytics workspace named Workspace1. You need to view the error events from a table named Event. Which query should you run in Workspace1?

Answer Options

A
Get-Event Event | where {$_.EventType == "error"}
B
Event | search "error"
C
select * from Event where EventType == "error"
D
search in (Event) * | where EventType -eq "error"

Correct Answer

B: Event | search "error"

Explanation

The search operator provides a multi-table/multi-column search experience. The syntax is: Table_name | search "search term" Note: There are several versions of this question in the exam. The question has three possible correct answers: 1. search in (Event) "error" 2. Event | search "error" 3. Event | where EventType == "error" Other incorrect answer options you may see on the exam include the following: 1. Get-Event Event | where {$_.EventTye -eq "error"} 2. Event | where EventType is "error" 3. select * from Event where EventType is "error" 4. search in (Event) * | where EventType -eq "error"