See the explanation below.
Explanation
Azure Monitor can collect events from the Windows event logs or Linux Syslog and performance counters that you specify for longer term analysis and reporting, and take action when a particular condition is detected.
Follow these steps to configure collection of events from the Windows system log and Linux Syslog, and several common performance counters to start with.
Data collection from Windows VM
1. In the Azure portal, locate the WS11641655 Azure Log Analytics workspace then select Advanced settings
.

2. データを選択し、Windowsイベントログを選択します。
3. イベントログを追加するには、ログの名前を入力します。「System」と入力し、プラス記号(+)を選択します。
4. 表で、重大度の「エラー」と「警告」をチェックします。(この質問では、すべてのログが収集されるように、すべての重大度を選択します)。
5. ページの上部にある [保存] を選択して、設定を保存します。
参照:
https://docs.microsoft.com/en-us/azure/azure-monitor/learn/quick-collect-azurevm