# Unfiltered Diagnostic Settings and Agent Data Collection Inflating Log Ingestion

Canonical: https://www.pointfive.co/efficiency-hub/inefficiencies/unfiltered-diagnostic-settings-and-agent-data-collection-inflating-log-ingestion

Most Azure Monitor Logs cost comes from the volume of data ingested into Log Analytics workspaces, and much of that volume is collected by default...

By: PointFive

Updated: 2026-09-28

[Cloud Efficiency Hub](https://www.pointfive.co/efficiency-hub) 

The short version

Most Azure Monitor Logs cost comes from the volume of data ingested into Log Analytics workspaces, and much of that volume is collected by default rather than by design.

PointFive Research

Cloud cost research at PointFive

Azure service

[Azure Monitor](https://www.pointfive.co/efficiency-hub/cloud-services/azure-monitor)

Category

[Other](https://www.pointfive.co/efficiency-hub/service-category/other)

Reference

CER-0425

Type

Excessive Ingestion or Processing

## Explanation

Why the waste happens and who it affects.

Diagnostic settings are commonly created with the allLogs category group or every category ticked, platform metrics are exported to the workspace even though they are already available in metrics explorer, agent data collection rules gather every performance counter at short intervals and verbose event levels, VM insights collects process and dependency data for a Map view nobody opens, and machines with both the legacy Log Analytics agent and Azure Monitor Agent, or overlapping data collection rules, send the same records twice.

Each billable GB is charged at ingestion whether or not anyone queries it, so this data inflates the bill every day. Microsoft's Azure Monitor cost optimization guidance tells teams to collect only the resource log categories they need, filter agent data, reduce counter polling frequency, decide deliberately what VM insights collects, and make sure VMs are not sending duplicate data.

## Billing model

The pricing dimensions that drive this cost.

Log Analytics charges for the billable size of every record that reaches the workspace.

Ingestion

Billed per GB ingested at the rate of the destination table plan; the billed size includes columns added during ingestion and column entries that do not match the destination schema

Diagnostic setting categories

Everything in an enabled category is ingested; diagnostic settings cannot filter within a category

Transformations on Analytics and Basic tables

Usually free, but if a transformation drops more than 50 percent of incoming data, the dropped volume above 50 percent is charged as data processing

Free tables

Some tables such as AzureActivity, Heartbeat, Usage and Operation are free from ingestion charges, shown by the \_IsBillable column

## How to detect

6 checks to find it in your estate.

- Use Log Analytics workspace insights (Usage tab) or the Usage table, for example Usage | where IsBillable == true | summarize BillableDataGB = sum(Quantity) / 1000 by Solution, DataType, to find the tables driving ingestion

- For top tables, break volume down by source with the documented find queries on \_BilledSize by \_ResourceId or Computer, and inspect Perf by CounterName, Event by EventID and Syslog by Facility and SeverityLevel

- Review diagnostic settings on high-volume resources for the allLogs category group, categories nobody queries, and AllMetrics sent to the workspace

- Check VM insights for process and dependency collection (VMComputer, VMProcess, VMConnection and VMBoundPort tables) where the Map feature is not used, and data collection rules with short performance counter sampling intervals

- Look for machines reporting through both the Log Analytics agent and Azure Monitor Agent, or covered by overlapping DCRs, by comparing duplicate records per Computer

- Enable the Azure Advisor alert for Data ingestion anomaly was detected (Increase in log ingestion volume detected) so sudden growth is surfaced

## How to fix

5 ways to remove the waste.

- Change diagnostic settings to only the categories used for alerting, dashboards or investigations, and drop AllMetrics from workspace destinations unless metrics are needed in log queries

- Filter at the source first: tune data collection rules for Azure Monitor Agent to collect only the counters, event levels and facilities needed, and lower counter polling frequency

- Use transformations in the agent DCR or the workspace transformation DCR (for diagnostic settings data on supported tables) to drop unneeded rows and columns, keeping in mind the processing charge when more than 50 percent of Analytics or Basic data is dropped

- Disable VM insights processes and dependencies collection where the Map feature is not used; Microsoft has deprecated the Dependency Agent and Map experience, which retire on 30 June 2028

- Complete the migration from the Log Analytics agent to Azure Monitor Agent and remove duplicate collection paths and overlapping DCRs

## Documentation

Vendor references for pricing and configuration.

- [Cost optimization in Azure Monitor  learn.microsoft.com](https://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/best-practices-cost)

- [Azure Monitor Logs Cost Calculations And Options  learn.microsoft.com](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/cost-logs)

- [Diagnostic Settings in Azure Monitor  learn.microsoft.com](https://learn.microsoft.com/en-us/azure/azure-monitor/data-collection/diagnostic-settings)

- [Transformations in Azure Monitor  learn.microsoft.com](https://learn.microsoft.com/en-us/azure/azure-monitor/data-collection/data-collection-transformations)

- [Analyze usage in a Log Analytics workspace in Azure Monitor  learn.microsoft.com](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/analyze-usage)

- [Pricing - Azure Monitor  azure.microsoft.com](https://azure.microsoft.com/en-us/pricing/details/monitor/)

## Related inefficiencies

[Browse the library](https://www.pointfive.co/efficiency-hub)

- Azure Monitor  CER-0569

### [Duplicate Container Metrics Collection in Container Insights](https://www.pointfive.co/efficiency-hub/inefficiencies/duplicate-container-metrics-collection-in-container-insights)

AKS clusters can send container metrics to two places: Azure Monitor managed service for Prometheus, which stores metrics in an Azure Monitor workspace, and Container insights, which can write performance and inventory data such as Perf...

Other

- Azure Monitor  CER-0221

### [Overly Frequent Querying in Azure Monitor Alerts](https://www.pointfive.co/efficiency-hub/inefficiencies/overly-frequent-querying-in-azure-monitor-alerts)

While high-frequency alerting is sometimes justified for production SLAs, it's often overused across non-critical alerts or replicated blindly across environments. Projects with multiple environments (e.g., dev, QA, staging, prod) often...

Other

- Azure Application Insights  CER-0426

### [Missing or Disabled Sampling in Application Insights Telemetry](https://www.pointfive.co/efficiency-hub/inefficiencies/missing-or-disabled-sampling-in-application-insights-telemetry)

Application Insights records requests, dependencies, traces, exceptions and page views for every instrumented call. When sampling is turned off, set to keep 100% of traces, or never configured on older instrumentation, telemetry volume...

Other

---
Source: the public page above. Product screenshots and illustrative interfaces are examples, not live customer data.

