Explanation
Why the waste happens and who it affects.
Diagnostic settings are commonly created with the allLogs category group or every category ticked, platform metrics are exported to the workspace even though they are already available in metrics explorer, agent data collection rules gather every performance counter at short intervals and verbose event levels, VM insights collects process and dependency data for a Map view nobody opens, and machines with both the legacy Log Analytics agent and Azure Monitor Agent, or overlapping data collection rules, send the same records twice.
Each billable GB is charged at ingestion whether or not anyone queries it, so this data inflates the bill every day. Microsoft's Azure Monitor cost optimization guidance tells teams to collect only the resource log categories they need, filter agent data, reduce counter polling frequency, decide deliberately what VM insights collects, and make sure VMs are not sending duplicate data.
Billing model
The pricing dimensions that drive this cost.
Log Analytics charges for the billable size of every record that reaches the workspace.
- Ingestion
- Billed per GB ingested at the rate of the destination table plan; the billed size includes columns added during ingestion and column entries that do not match the destination schema
- Diagnostic setting categories
- Everything in an enabled category is ingested; diagnostic settings cannot filter within a category
- Transformations on Analytics and Basic tables
- Usually free, but if a transformation drops more than 50 percent of incoming data, the dropped volume above 50 percent is charged as data processing
- Free tables
- Some tables such as AzureActivity, Heartbeat, Usage and Operation are free from ingestion charges, shown by the _IsBillable column
How to detect
6 checks to find it in your estate.
- Use Log Analytics workspace insights (Usage tab) or the Usage table, for example Usage | where IsBillable == true | summarize BillableDataGB = sum(Quantity) / 1000 by Solution, DataType, to find the tables driving ingestion
- For top tables, break volume down by source with the documented find queries on _BilledSize by _ResourceId or Computer, and inspect Perf by CounterName, Event by EventID and Syslog by Facility and SeverityLevel
- Review diagnostic settings on high-volume resources for the allLogs category group, categories nobody queries, and AllMetrics sent to the workspace
- Check VM insights for process and dependency collection (VMComputer, VMProcess, VMConnection and VMBoundPort tables) where the Map feature is not used, and data collection rules with short performance counter sampling intervals
- Look for machines reporting through both the Log Analytics agent and Azure Monitor Agent, or covered by overlapping DCRs, by comparing duplicate records per Computer
- Enable the Azure Advisor alert for Data ingestion anomaly was detected (Increase in log ingestion volume detected) so sudden growth is surfaced
How to fix
5 ways to remove the waste.
- Change diagnostic settings to only the categories used for alerting, dashboards or investigations, and drop AllMetrics from workspace destinations unless metrics are needed in log queries
- Filter at the source first: tune data collection rules for Azure Monitor Agent to collect only the counters, event levels and facilities needed, and lower counter polling frequency
- Use transformations in the agent DCR or the workspace transformation DCR (for diagnostic settings data on supported tables) to drop unneeded rows and columns, keeping in mind the processing charge when more than 50 percent of Analytics or Basic data is dropped
- Disable VM insights processes and dependencies collection where the Map feature is not used; Microsoft has deprecated the Dependency Agent and Map experience, which retire on 30 June 2028
- Complete the migration from the Log Analytics agent to Azure Monitor Agent and remove duplicate collection paths and overlapping DCRs
Documentation
Vendor references for pricing and configuration.
- Cost optimization in Azure Monitorlearn.microsoft.com
- Azure Monitor Logs Cost Calculations And Optionslearn.microsoft.com
- Diagnostic Settings in Azure Monitorlearn.microsoft.com
- Transformations in Azure Monitorlearn.microsoft.com
- Analyze usage in a Log Analytics workspace in Azure Monitorlearn.microsoft.com
- Pricing - Azure Monitorazure.microsoft.com