Explanation
Why the waste happens and who it affects.
When a compliance or audit requirement asks for a year or more of logs, teams commonly raise the workspace or table analytics retention to that full period instead of adding long-term retention, and pay the higher analytics retention rate every day for data that is almost never queried.
The setting is usually applied once at the workspace level, so it spreads to every Analytics table that inherits the default, including verbose diagnostic and performance tables that nobody investigates beyond a few weeks. Microsoft's Azure Monitor cost guidance recommends configuring interactive and long-term retention separately, keeping only the period needed for day-to-day queries in analytics retention and the rest in long-term retention.
Billing model
The pricing dimensions that drive this cost.
Retention is billed per GB per day on top of ingestion, with different rates for analytics and long-term retention.
- Included analytics retention
- Analytics Logs ingestion includes 31 days of analytics retention; some tables such as Usage, AzureActivity and Application Insights tables keep 90 days at no charge
- Extended analytics retention
- Analytics retention beyond the included period, up to 730 days per table, billed per GB per day
- Long-term retention
- Data kept beyond analytics retention up to a total of 12 years at a reduced per-GB rate, with search job scan or query charges when accessed
- Purge
- Deleting data with the Purge feature does not reduce retention cost; only shortening the retention period does
How to detect
4 checks to find it in your estate.
- In the workspace Tables view, or with az monitor log-analytics workspace table show or the Tables - Get API, list each table's retentionInDays and totalRetentionInDays; flag Analytics tables with retentionInDays well above 31 or 90 days
- Check the workspace default retention (properties.retentionInDays) under Usage and estimated costs > Data Retention, since tables that inherit it all carry the same analytics retention
- Compare the analytics retention with how far back queries actually reach: with query auditing enabled, the LAQueryLogs StatsDataProcessedStart field shows the oldest data each query accessed (scheduled alert queries are not logged)
- In Cost Management, track the Log Analytics data retention meters against ingestion over time; retention cost rising faster than ingestion signals long analytics retention
How to fix
4 ways to remove the waste.
- Set analytics retention per table to the period needed for live queries, dashboards and alerts, and set totalRetentionInDays to the compliance period so the remainder moves to long-term retention; Azure Monitor treats the difference as long-term retention without losing data
- Lower the workspace default retention so new and inheriting tables do not get long analytics retention by default, and override it per table where longer interactive access is justified
- Retrieve older data with search jobs or restore when needed, and use an export job for one-time bulk extracts to Blob Storage instead of keeping data interactive
- Do not set analytics retention below 31 days to save money, since the first 31 days are included in the ingestion price
Documentation
Vendor references for pricing and configuration.