Explanation
Why the waste happens and who it affects.
Workspaces that grow to ingest a steady 100 GB or more per day keep paying the full per-GB rate unless someone changes the pricing tier, because nothing moves a workspace to a commitment tier automatically. Ingestion tends to grow gradually as resources, diagnostic settings and agents are added, so the point where a commitment tier becomes cheaper passes unnoticed.
Commitment tiers give a lower per-GB price in exchange for a daily ingestion commitment, and Microsoft states they can save as much as 30 percent compared with pay-as-you-go. Azure Advisor raises a Consider Changing Pricing Tier recommendation when a workspace's usage would be cheaper on a commitment tier. A related gap occurs when several same-region workspaces each ingest less than 100 GB per day but together exceed it; linking them to a dedicated cluster lets their combined volume use a single commitment tier.
Billing model
The pricing dimensions that drive this cost.
Commitment tiers apply only to Analytics Logs ingestion; Basic and Auxiliary Logs are billed at flat per-GB rates.
- Pay-as-you-go ingestion
- The default pricing tier (pergb2018), billed per GB of Analytics Logs ingested with no minimum
- Commitment tier
- A daily ingestion commitment starting at 100 GB per day at a lower per-GB price, billed daily per workspace; overage is billed at the same tier rate
- Commitment period
- 31 days from selecting or raising a tier, during which the workspace cannot move to a lower tier or back to pay-as-you-go; a tier can be lowered within 6 hours of an unintended change
- Dedicated cluster
- Aggregates ingestion from linked same-region workspaces under one commitment tier of at least 100 GB per day; billing starts when the cluster is created
How to detect
5 checks to find it in your estate.
- Review the Azure Advisor cost recommendation Consider Changing Pricing Tier on microsoft.operationalinsights/workspaces resources
- Open Usage and estimated costs on each workspace; it shows the estimated cost of each pricing tier based on the last 31 days and labels the cheapest as Recommended Tier
- Query the Usage table for billable Analytics ingestion per day, for example Usage | where TimeGenerated > ago(32d) | where IsBillable == true | summarize BillableDataGB = sum(Quantity) / 1000. by bin(StartTime, 1d), Plan, and look for a sustained daily volume near or above 100 GB
- List workspaces with sku.name pergb2018 and group them by region to find sets whose combined daily Analytics ingestion would reach a dedicated cluster commitment
- For workspaces with Microsoft Sentinel in the simplified pricing tier, note that Analytics ingestion is billed on Sentinel meters, so the relevant commitment is Sentinel's rather than the Log Analytics tier
How to fix
4 ways to remove the waste.
- Change the workspace to the commitment tier that matches sustained daily Analytics ingestion from Usage and estimated costs, or set sku.name to capacityreservation with a capacityReservationLevel in the ARM template
- Choose a tier at or slightly below the steady daily volume, since overage is billed at the tier rate while unused commitment is still paid, and confirm the level before the 6-hour window closes
- For several same-region workspaces below 100 GB per day each, link them to a dedicated cluster sized to their combined volume, noting that the cluster bills from creation even before workspaces are linked
- Reduce unnecessary ingestion first where possible, then re-check the tier after each 31-day period and move down when ingestion drops
Documentation
Vendor references for pricing and configuration.
- Azure Monitor Logs Cost Calculations And Optionslearn.microsoft.com
- Change pricing tier for Log Analytics workspacelearn.microsoft.com
- Cost optimization in Azure Monitorlearn.microsoft.com
- Cost recommendations - Azure Advisorlearn.microsoft.com
- Analyze usage in a Log Analytics workspace in Azure Monitorlearn.microsoft.com
- Pricing - Azure Monitorazure.microsoft.com