Configure data retention for logs in Microsoft Sentinel or Azure Monitor (2024)

  • Article

In this tutorial, you'll set a retention policy for a table in your Log Analytics workspace that you use for Microsoft Sentinel or Azure Monitor. These steps allow you to keep older, less used data in your workspace at a reduced cost.

Retention policies in a Log Analytics workspace define when to transition old records in data tables in the workspace to the low-cost, minimal-access long-term retention (formerly known as archive) state. By default, all tables in your workspace inherit the workspace's interactive retention setting and have no long-term retention (archive) policy. You can modify the interactive and long-term retention policies of individual tables, except for workspaces in the legacy Free Trial pricing tier.

In this tutorial, you learn how to:

  • Set the retention policy for a table
  • Review interactive and long-term retention policies

Prerequisites

To complete the steps in this tutorial, you must have the following resources and roles.

  • Azure account with an active subscription. Create an account for free.

  • Azure account with the following roles:

    Built-in RoleScopeReason
    Log Analytics ContributorAny of
    • Subscription
    • Resource group
    • Table
    To set retention policy on tables in Log Analytics
  • Log Analytics workspace.

Set the retention policy for a table

In your Log Analytics workspace, change the interactive retention policy of the SecurityEvent table from the workspace default of 90 days to 180 days, and the total retention policy to 3 years. The total retention period is the sum of the interactive and long-term (archive) retention periods.

  1. Sign in to the Azure portal.

  2. In the Azure portal, search for and open Log Analytics workspaces.

  3. Select the appropriate workspace.

  4. Under Settings, select Tables.

  5. Find the SecurityEvent table in the list, and open the context menu (...).

  6. Select Manage table.

    Configure data retention for logs in Microsoft Sentinel or Azure Monitor (1)

  7. Under Data retention settings, enter the following values.

    FieldValue
    Interactive retention180 days
    Total retention period3 years

    Configure data retention for logs in Microsoft Sentinel or Azure Monitor (2)

    See that the time graph shows that the long-term retention period equals the total retention period in days minus the interactive retention period in days. In this case, 915 days, or 2.5 years.

  8. Select Save.

Review interactive and total retention policies

On the Tables page for the table you updated, review the field values for Interactive retention and Total retention.

Configure data retention for logs in Microsoft Sentinel or Azure Monitor (3)

Clean up resources

No resources were created but you might want to restore the data retention settings you changed.

Next steps

Configure data retention for logs in Microsoft Sentinel or Azure Monitor (2024)
Top Articles
KINETIC Less Lethal 12 Gauge Round - 10ct
How to close a checking account in 6 steps
Jordanbush Only Fans
Citibank Branch Locations In Orlando Florida
Unity Stuck Reload Script Assemblies
News - Rachel Stevens at RachelStevens.com
Seething Storm 5E
Puretalkusa.com/Amac
Slapstick Sound Effect Crossword
Southland Goldendoodles
Blog:Vyond-styled rants -- List of nicknames (blog edition) (TouhouWonder version)
Pvschools Infinite Campus
Kinkos Whittier
Tracking Your Shipments with Maher Terminal
Saberhealth Time Track
8664751911
Yakimacraigslist
Iu Spring Break 2024
Craigslist Battle Ground Washington
What Are The Symptoms Of A Bad Solenoid Pack E4od?
Dark Entreaty Ffxiv
1979 Ford F350 For Sale Craigslist
Marlene2995 Pagina Azul
The Clapping Song Lyrics by Belle Stars
49S Results Coral
Salemhex ticket show3
Vip Lounge Odu
Greater Orangeburg
Home Auctions - Real Estate Auctions
Does Circle K Sell Elf Bars
Craigslist Free Puppy
Murphy Funeral Home & Florist Inc. Obituaries
Greater Keene Men's Softball
The disadvantages of patient portals
Www Craigslist Com Brooklyn
This 85-year-old mom co-signed her daughter's student loan years ago. Now she fears the lender may take her house
Cpmc Mission Bernal Campus & Orthopedic Institute Photos
Stewartville Star Obituaries
The Realreal Temporary Closure
Jamesbonchai
Promo Code Blackout Bingo 2023
Mychart University Of Iowa Hospital
Elven Steel Ore Sun Haven
Ssc South Carolina
Darkglass Electronics The Exponent 500 Test
Playboi Carti Heardle
Phone Store On 91St Brown Deer
Euro area international trade in goods surplus €21.2 bn
Horseneck Beach State Reservation Water Temperature
53 Atms Near Me
Craigslist.raleigh
Arre St Wv Srj
Latest Posts
Article information

Author: Annamae Dooley

Last Updated:

Views: 6155

Rating: 4.4 / 5 (45 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Annamae Dooley

Birthday: 2001-07-26

Address: 9687 Tambra Meadow, Bradleyhaven, TN 53219

Phone: +9316045904039

Job: Future Coordinator

Hobby: Archery, Couponing, Poi, Kite flying, Knitting, Rappelling, Baseball

Introduction: My name is Annamae Dooley, I am a witty, quaint, lovely, clever, rich, sparkling, powerful person who loves writing and wants to share my knowledge and understanding with you.