Forum Discussion
Review events of a File Server de Windows with azure Monitor
Hi,
I agree with Noa Kuperberg , you need to ensure you get your on-premises server logs (and / or metrics) to an Azure Monitor workspace, where you can analyze it, visualize it, create alerts, etc. You could then create a Kusto query that would search for events from that particular machine or even for specific events (IDs, sources, etc.).
I would only add that an alternative to installing a MMA agent to your server(s) would be integrating your existing SCOM environment with Azure Monitor, but obviously only in case you have one 🙂
Have a nice day.
For example, mention Event ID 4659 at the local event viewer level if it appears, but in log analytics it does not appear.
For them my question if you can have control of all the events generated with Azure Monitor or to what extent.
I hope you can help me, regards.