Forum Discussion

Isy's avatar
Isy
New Member I
14 hours ago

Microsoft Sentinel Deployment & Log Ingestion: Ingesting Platform Logs via Diagnostic Settings

Hello Immersive Labs community,

I’ve been working through the lab tasks and successfully completed tasks 1 through 6. However, I’m stuck on task 7, which asks:

"A storage account has been deleted. What would be the data type of the generated log?"

The task seems oddly described, and I can’t find any clear hints in the lab briefing or online resources. I’ve tried querying various data types like AzureActivityAuditLogsStorageBlobLogsStorageFileLogs, and others, but none seem to fit correctly.

Could anyone provide guidance or confirm which data type is actually relevant for this scenario? Are there any specific tips or resources I might be missing?

Thanks in advance for your help!

No RepliesBe the first to reply