Configure data retention for logs in Microsoft Sentinel or Azure Monitor (2024)

  • Article

In this tutorial, you'll set a retention policy for a table in your Log Analytics workspace that you use for Microsoft Sentinel or Azure Monitor. These steps allow you to keep older, less used data in your workspace at a reduced cost.

Retention policies in a Log Analytics workspace define when to transition old records in data tables in the workspace to the low-cost, minimal-access long-term retention (formerly known as archive) state. By default, all tables in your workspace inherit the workspace's interactive retention setting and have no long-term retention (archive) policy. You can modify the interactive and long-term retention policies of individual tables, except for workspaces in the legacy Free Trial pricing tier.

In this tutorial, you learn how to:

  • Set the retention policy for a table
  • Review interactive and long-term retention policies

Prerequisites

To complete the steps in this tutorial, you must have the following resources and roles.

  • Azure account with an active subscription. Create an account for free.

  • Azure account with the following roles:

    Built-in RoleScopeReason
    Log Analytics ContributorAny of
    • Subscription
    • Resource group
    • Table
    To set retention policy on tables in Log Analytics
  • Log Analytics workspace.

Set the retention policy for a table

In your Log Analytics workspace, change the interactive retention policy of the SecurityEvent table from the workspace default of 90 days to 180 days, and the total retention policy to 3 years. The total retention period is the sum of the interactive and long-term (archive) retention periods.

  1. Sign in to the Azure portal.

  2. In the Azure portal, search for and open Log Analytics workspaces.

  3. Select the appropriate workspace.

  4. Under Settings, select Tables.

  5. Find the SecurityEvent table in the list, and open the context menu (...).

  6. Select Manage table.

    Configure data retention for logs in Microsoft Sentinel or Azure Monitor (1)

  7. Under Data retention settings, enter the following values.

    FieldValue
    Interactive retention180 days
    Total retention period3 years

    Configure data retention for logs in Microsoft Sentinel or Azure Monitor (2)

    See that the time graph shows that the long-term retention period equals the total retention period in days minus the interactive retention period in days. In this case, 915 days, or 2.5 years.

  8. Select Save.

Review interactive and total retention policies

On the Tables page for the table you updated, review the field values for Interactive retention and Total retention.

Configure data retention for logs in Microsoft Sentinel or Azure Monitor (3)

Clean up resources

No resources were created but you might want to restore the data retention settings you changed.

Next steps

Configure data retention for logs in Microsoft Sentinel or Azure Monitor (2024)
Top Articles
What are "personal data" and when are they "processed"? | Data Protection Commission
How to Calculate your App Startup's Valuation | Rapptr Labs
104 Presidential Ct Lafayette La 70503
477 Job Calls
Craigslist Rooms For Rent Oxnard
Vlb Aurora
Funeral Homes in Grand Forks, North Dakota
Varsity Tutors, a Nerdy Company hiring Hoboken Vietnamese Tutor in Hoboken, NJ | LinkedIn
Virginia Family Resort (Kallithea): Alle Infos zum Hotel
Grifolsplasma.com Donor-Portal
Serenity Nail Salon Brentwood Tn
Study Restaurants Near Me
Katamari Games Ranked
Dan Mora Growth
Unc Healthchart
Pokemon Fire Red Cheats
florence, SC general for sale - craigslist
Chrome Hearts Schmuck und Uhren – 15 im Angebot bei 1stDibs
Boom Truck Blues for Your Amusem*nt
Www Acpny Com Login
Hannibal Mo Craigslist Pets
Palm Coast Permits Online
Brazos County Mugshots Busted Newspaper
Page 1328 – Christianity Today
Viprow Net Football
Bob Wright Yukon Accident
Ascension St John Tulsa Patient Portal
Truist Bank Near Here
Craigslist Bronx Ny Free Stuff
Complete Growth Inhibition of Pseudomonas aeruginosa by Organo-Selenium-Incorporated Urinary Catheter Material.
149 Capstone Project Ideas & Examples – 2024
Pestweb Login
How to Tell if Battery, Alternator, or Starter is Bad
9294726233
Chris Medlin: Credits, Bio, News & More | Broadway World
L'Hôpital's rule - Conditions, Formula, and Examples
3 Days in the Tri-Cities
Skyrim Showracemenu
Eve Fastest Ship
Rok Gold Head Calculator
Hodgkins Il Ups Delay 2022
Costco Gas Prices Sioux Falls
4084716729
Onondaga Imagemate
NOXIOUS - Englisch-Deutsch Übersetzung | PONS
Coffey Leaked
Qhc Learning
Top 10 Soap2Day Alternatives That Work Today [2024 List] | X-VPN
Hmh Zip Code Locator
Tricare Dermatologists Near Me
Water Displacement Worksheet Answer Key Pdf
Latest Posts
Article information

Author: Annamae Dooley

Last Updated:

Views: 6155

Rating: 4.4 / 5 (45 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Annamae Dooley

Birthday: 2001-07-26

Address: 9687 Tambra Meadow, Bradleyhaven, TN 53219

Phone: +9316045904039

Job: Future Coordinator

Hobby: Archery, Couponing, Poi, Kite flying, Knitting, Rappelling, Baseball

Introduction: My name is Annamae Dooley, I am a witty, quaint, lovely, clever, rich, sparkling, powerful person who loves writing and wants to share my knowledge and understanding with you.