Forum Discussion

Sharjeel-Khan's avatar
Sharjeel-Khan
Copper Contributor
Dec 05, 2023

Log Analytics Workspace Daily Cap

Hello everyone, I am new to Microsoft Sentinel, and I hope all of you are doing good.

 

I wanted to know that I set a daily cap limit on my log analytics workspace of 23 MB, as it was the lowest I could go in my test environment. I created alerts on that too, like whenever the daily cap is reached I am notified via email. I wanted to know a couple of things.

 

  1. If I set the daily cap limit, it should stop ingesting data after reaching 23 MB right? Considering that the data is coming from my windows and Linux virtual machines via AMA. But I can see around 27 MB of data being ingested as of today. I want to know the reason behind it.
  2. If it is not stopping the ingestion of data is there any rule that I can configure which forces to stop this ingestion? I have gone through all the Alerts that are present in the Log Analytics Workspace but there is no option. 

 

Thanking in advance. Best Regards,

Sharjeel Khan.

    • MHenshaw's avatar
      MHenshaw
      Brass Contributor
      The daily cap states this "Note that there can be some latency in applying the daily cap, so stopping data ingestion precisely at the specified cap cannot be guaranteed." Because of this in my expierence we have to slightly decrease from the cap we actually want for example, if we want the cap to be 23 MB you could set it at 20 MB. Hope that helps
      • Sidra_Raza's avatar
        Sidra_Raza
        Brass Contributor
        Hello. I want the ingestion to be stopped at 30 MB that is why I set limit to 23MB but the ingestion is increasing continuously.

Resources