Apr 05 2022
So the ingestion time transformation is anounced here: https://docs.microsoft.com/en-us/azure/azure-monitor/logs/ingestion-time-transformations
Does this mean we can send data directly to our workspace and have it filtered there without having to filter using a logstash or azure monitor agent? (as explained here: https://docs.microsoft.com/en-us/azure/sentinel/best-practices-data )
Or do they serve a different purpose ?
So: to lower our ingestion costs, can we use ingestion-time transformations in stead of the current solutions?