Forum Discussion
Sharjeel-Khan
Dec 05, 2023Copper Contributor
Log Analytics Workspace Daily Cap
Hello everyone, I am new to Microsoft Sentinel, and I hope all of you are doing good.
I wanted to know that I set a daily cap limit on my log analytics workspace of 23 MB, as it was the lowest I could go in my test environment. I created alerts on that too, like whenever the daily cap is reached I am notified via email. I wanted to know a couple of things.
- If I set the daily cap limit, it should stop ingesting data after reaching 23 MB right? Considering that the data is coming from my windows and Linux virtual machines via AMA. But I can see around 27 MB of data being ingested as of today. I want to know the reason behind it.
- If it is not stopping the ingestion of data is there any rule that I can configure which forces to stop this ingestion? I have gone through all the Alerts that are present in the Log Analytics Workspace but there is no option.
Thanking in advance. Best Regards,
Sharjeel Khan.
- Sidra_RazaBrass ContributorI am facing the same issue. Anyone here who can guide us?
- MHenshawBrass ContributorThe daily cap states this "Note that there can be some latency in applying the daily cap, so stopping data ingestion precisely at the specified cap cannot be guaranteed." Because of this in my expierence we have to slightly decrease from the cap we actually want for example, if we want the cap to be 23 MB you could set it at 20 MB. Hope that helps
- Sidra_RazaBrass ContributorHello. I want the ingestion to be stopped at 30 MB that is why I set limit to 23MB but the ingestion is increasing continuously.