Home
%3CLINGO-SUB%20id%3D%22lingo-sub-917316%22%20slang%3D%22en-US%22%3ENew%3A%20Per%20data%20type%20retention%20is%20now%20available%20for%20Azure%20Sentinel%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-917316%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3EThe%20capability%20to%20set%20the%20retention%20period%20per%20data%20type%20is%20now%20available%20for%20Log%20Analytics%20and%20Azure%20Sentinel.%20Setting%20per%20data%20type%20retention%20enables%20significant%20cost%20saving%20on%20retention%20cost.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3EFor%20example%2C%20you%20may%20collect%20firewall%20logs%20using%20CEF%20or%20DNS%20logs%2C%20both%20of%20which%20are%20voluminous%20but%20become%20stale%20quite%20fast%2C%20but%20on%20the%20other%20hand%2C%20you%20need%20to%20keep%20Office%20365%20logs%20for%20a%20more%20extended%20period%20for%20compliance%20reasons.%20This%20is%20now%20possible%20as%20you%20can%20set%20the%20retention%20for%20CEF%20and%20DNS%20to%2090%20days%2C%20which%20incurs%20no%20retention%20cost%2C%20and%20the%20retention%20for%20Office%20365%20for%20a%20longer%20period%2C%20say%202%20years.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3ETo%20configure%20that%2C%20you%20will%20need%20to%20use%20ARM%20template%2C%20though%20the%20documentation%20suggests%20a%20handy%20tool%20that%20enables%20using%20the%20feature%20without%20in-depth%20knowledge%20of%20ARM%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3EMore%20info%20here%3A%26nbsp%3B%3C%2FSPAN%3E%3CA%20class%3D%22_e75a791d-denali-editor-page-rtfLink%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fmanage-cost-storage%23retention-by-data-type%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fmanage-cost-storage%23retention-by-data-type%3C%2FSPAN%3E%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3E3rd%20party%20blog%3A%26nbsp%3B%3C%2FSPAN%3E%3CA%20class%3D%22_e75a791d-denali-editor-page-rtfLink%22%20href%3D%22https%3A%2F%2Fcloudadministrator.net%2F2019%2F10%2F16%2Fset-per-table-retention-in-log-analytics-via-arm-template%2Famp%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3Ehttps%3A%2F%2Fcloudadministrator.net%2F2019%2F10%2F16%2Fset-per-table-retention-in-log-analytics-via-arm-template%2Famp%2F%3C%2FSPAN%3E%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3E%26nbsp%3B%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F138127i3032051F13940D35%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22manage-cost-change-retention-01%22%20title%3D%22manage-cost-change-retention-01%22%20%2F%3E%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-917316%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3EThe%20capability%20to%20set%20the%20retention%20period%20per%20data%20type%20is%20now%20available%20for%20Log%20Analytics%20and%20Azure%20Sentinel.%20Setting%20per%20data%20type%20retention%20enables%20significant%20cost%20saving%20on%20retention%20cost.%3C%2FSPAN%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-917316%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAnnouncements%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ELogManagement%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Microsoft

The capability to set the retention period per data type is now available for Log Analytics and Azure Sentinel. Setting per data type retention enables significant cost saving on retention cost.

 

For example, you may collect firewall logs using CEF or DNS logs, both of which are voluminous but become stale quite fast, but on the other hand, you need to keep Office 365 logs for a more extended period for compliance reasons. This is now possible as you can set the retention for CEF and DNS to 90 days, which incurs no retention cost, and the retention for Office 365 for a longer period, say 2 years.

 

To configure that, you will need to use ARM template, though the documentation suggests a handy tool that enables using the feature without in-depth knowledge of ARM

 

More info here: https://docs.microsoft.com/en-us/azure/azure-monitor/platform/manage-cost-storage#retention-by-data-...

3rd party blog: https://cloudadministrator.net/2019/10/16/set-per-table-retention-in-log-analytics-via-arm-template/...

 

 manage-cost-change-retention-01