# Excessive Analytics Retention in Log Analytics Workspaces

Canonical: https://www.pointfive.co/efficiency-hub/inefficiencies/excessive-analytics-retention-in-log-analytics-workspaces

Log Analytics keeps data in two states: analytics (interactive) retention, where it can be queried directly, and long-term retention, a lower-cost...

By: PointFive

Updated: 2026-09-28

[Cloud Efficiency Hub](https://www.pointfive.co/efficiency-hub) 

The short version

Log Analytics keeps data in two states: analytics (interactive) retention, where it can be queried directly, and long-term retention, a lower-cost state from which data is retrieved with search jobs or restore.

PointFive Research

Cloud cost research at PointFive

Azure service

[Azure Log Analytics](https://www.pointfive.co/efficiency-hub/cloud-services/azure-log-analytics)

Category

[Other](https://www.pointfive.co/efficiency-hub/service-category/other)

Reference

CER-0423

Type

Excessive Data Retention

## Explanation

Why the waste happens and who it affects.

When a compliance or audit requirement asks for a year or more of logs, teams commonly raise the workspace or table analytics retention to that full period instead of adding long-term retention, and pay the higher analytics retention rate every day for data that is almost never queried.

The setting is usually applied once at the workspace level, so it spreads to every Analytics table that inherits the default, including verbose diagnostic and performance tables that nobody investigates beyond a few weeks. Microsoft's Azure Monitor cost guidance recommends configuring interactive and long-term retention separately, keeping only the period needed for day-to-day queries in analytics retention and the rest in long-term retention.

## Billing model

The pricing dimensions that drive this cost.

Retention is billed per GB per day on top of ingestion, with different rates for analytics and long-term retention.

Included analytics retention

Analytics Logs ingestion includes 31 days of analytics retention; some tables such as Usage, AzureActivity and Application Insights tables keep 90 days at no charge

Extended analytics retention

Analytics retention beyond the included period, up to 730 days per table, billed per GB per day

Long-term retention

Data kept beyond analytics retention up to a total of 12 years at a reduced per-GB rate, with search job scan or query charges when accessed

Purge

Deleting data with the Purge feature does not reduce retention cost; only shortening the retention period does

## How to detect

4 checks to find it in your estate.

- In the workspace Tables view, or with az monitor log-analytics workspace table show or the Tables - Get API, list each table's retentionInDays and totalRetentionInDays; flag Analytics tables with retentionInDays well above 31 or 90 days

- Check the workspace default retention (properties.retentionInDays) under Usage and estimated costs \> Data Retention, since tables that inherit it all carry the same analytics retention

- Compare the analytics retention with how far back queries actually reach: with query auditing enabled, the LAQueryLogs StatsDataProcessedStart field shows the oldest data each query accessed (scheduled alert queries are not logged)

- In Cost Management, track the Log Analytics data retention meters against ingestion over time; retention cost rising faster than ingestion signals long analytics retention

## How to fix

4 ways to remove the waste.

- Set analytics retention per table to the period needed for live queries, dashboards and alerts, and set totalRetentionInDays to the compliance period so the remainder moves to long-term retention; Azure Monitor treats the difference as long-term retention without losing data

- Lower the workspace default retention so new and inheriting tables do not get long analytics retention by default, and override it per table where longer interactive access is justified

- Retrieve older data with search jobs or restore when needed, and use an export job for one-time bulk extracts to Blob Storage instead of keeping data interactive

- Do not set analytics retention below 31 days to save money, since the first 31 days are included in the ingestion price

## Documentation

Vendor references for pricing and configuration.

- [Manage Data Retention in a Log Analytics Workspace  learn.microsoft.com](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/data-retention-configure)

- [Azure Monitor Logs Cost Calculations And Options  learn.microsoft.com](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/cost-logs)

- [Cost optimization in Azure Monitor  learn.microsoft.com](https://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/best-practices-cost)

- [Audit queries in Azure Monitor log queries  learn.microsoft.com](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/query-audit)

- [Pricing - Azure Monitor  azure.microsoft.com](https://azure.microsoft.com/en-us/pricing/details/monitor/)

## Related inefficiencies

[Browse the library](https://www.pointfive.co/efficiency-hub)

- Azure Log Analytics  CER-0197

### [Suboptimal Table Plan Selection in Log Analytics](https://www.pointfive.co/efficiency-hub/inefficiencies/suboptimal-table-plan-selection-in-log-analytics)

By default, all Log Analytics tables are created under the Analytics plan, which is optimized for high-performance querying and interactive analysis. However, not all telemetry requires real-time access or frequent querying. Some tables...

Other

- Azure Log Analytics  CER-0422

### [Missing Commitment Tier on High-Volume Log Analytics Workspaces](https://www.pointfive.co/efficiency-hub/inefficiencies/missing-commitment-tier-on-high-volume-log-analytics-workspaces)

Log Analytics workspaces default to pay-as-you-go pricing for Analytics Logs ingestion, with no minimum volume. Workspaces that grow to ingest a steady 100 GB or more per day keep paying the full per-GB rate unless someone changes the...

Other

- Azure Log Analytics  CER-0424

### [Unused Restored Tables in Log Analytics Workspaces](https://www.pointfive.co/efficiency-hub/inefficiencies/unused-restored-tables-in-log-analytics-workspaces)

The Log Analytics restore operation brings a time range of data from long-term retention (or from any Analytics table) into the hot cache as a new table ending in \_RST, so that it can be queried with full KQL at high performance. It is...

Other

---
Source: the public page above. Product screenshots and illustrative interfaces are examples, not live customer data.

