How to find the azure vm ingested log size to sentinel

%3CLINGO-SUB%20id%3D%22%5C%26quot%3Blingo-sub-3135098%5C%26quot%3B%22%20slang%3D%22%5C%26quot%3Ben-US%5C%26quot%3B%22%3EHow%20to%20find%20the%20azure%20vm%20ingested%20log%20size%26lt%3B%5C%2Flingo-sub%26gt%3B%3CLINGO-BODY%20id%3D%22%5C%26quot%3Blingo-body-3135098%5C%26quot%3B%22%20slang%3D%22%5C%26quot%3Ben-US%5C%26quot%3B%22%3E%3CP%3EHi%20all%2C%20I%20need%20some%20help.%26lt%3B%5C%2FP%26gt%3B%3C%2FP%3E%3CP%3EI%20want%20to%20find%20the%20total%20ingested%20log%20size%20(daily%20or%20weekly)%20from%20azure%20VM%20which%20is%20used%20for%20syslog-forwarder.%20I%20can%20find%20the%20only%20Usage%20table%20which%20is%20billable%20or%20not.%26lt%3B%5C%2FP%26gt%3B%3C%2FP%3E%3CP%3EThanks%20all.%26lt%3B%5C%2FP%26gt%3B%26lt%3B%5C%2Flingo-body%26gt%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3C%2FLINGO-SUB%3E
Occasional Contributor

Hi all, I need some help.

I want to find the total ingested log size (daily or weekly) from azure VM which is used for syslog-forwarder. I can find the only Usage table which is billable or not.

Thanks all.

1 Reply

@zaylinhtun

 

Usage no longer holds Computer info, so you can check the Syslog Table instead.  This shows each day for the last 7days (adjust to suit).

 

Syslog
| where TimeGenerated > ago(7d)
| where _IsBillable = true
| where Computer == ' name of your Syslog server '
| summarize sum(_BilledSize) by bin(TimeGenerated, 1d)

 

Syslog
| where TimeGenerated > ago(7d)
| where _IsBillable = true
//| where Computer == ' .. '
| summarize GBytes=sum(_BilledSize)/(1024*1024*1024) by bin(TimeGenerated, 1d), Computer
| render barchart 

Syslog
| where TimeGenerated > ago(7d)
| where _IsBillable = true
| summarize bytes=sum(_BilledSize) by bin(TimeGenerated, 1d), Computer
| render barchart 

or for all Syslog Servers