Concept and mechanism
Azure Activity Log describes management-plane events useful for investigating who changed a resource. Resource logs provide another perspective and need appropriate collection and destination configuration, such as diagnostic settings. Guest telemetry collected by Azure Monitor Agent depends on applicable collection rules and associations; installing the agent does not demonstrate that every required event reaches the workspace. First define the operational question, then the source and query. Retention and evidence access should match diagnostic needs and data controls.
Guided application
An alert should connect signal, time-based condition, and action to an owner. For log errors, validate filtering, aggregation, and window; a CPU metric does not automatically replace that count. During maintenance, alert processing rules can suppress actions within bounded scope and schedule without deleting detection. Recovery requires more than green dashboards: Azure Backup provides restore options and Site Recovery supports failover drills. Prepare a test network, avoid duplicated real effects, validate representative transactions, measure timing, and clean up. Handover should include a runbook executable by the team taking responsibility.
Replication is healthy, but a credential is missing in the recovery environment. A drill with RUN discovers the gap before a real incident.
Common pitfalls
Confusing installation with effective collection; silencing alerts indefinitely; measuring only VM startup; treating replication as validated restoration.
Related topics: Identities and effective access · Governance, protection, and costs
Confirm evidence arrives and the team can execute recovery.
Reference: Data collection rules · AZ-104; skills measured 2026-04-17