# Unused Restored Tables in Log Analytics Workspaces

Canonical: https://www.pointfive.co/efficiency-hub/inefficiencies/unused-restored-tables-in-log-analytics-workspaces

The Log Analytics restore operation brings a time range of data from long-term retention (or from any Analytics table) into the hot cache as a new...

By: PointFive

Updated: 2026-09-28

[Cloud Efficiency Hub](https://www.pointfive.co/efficiency-hub) 

The short version

The Log Analytics restore operation brings a time range of data from long-term retention (or from any Analytics table) into the hot cache as a new table ending in \_RST, so that it can be queried with full KQL at high performance.

PointFive Research

Cloud cost research at PointFive

Azure service

[Azure Log Analytics](https://www.pointfive.co/efficiency-hub/cloud-services/azure-log-analytics)

Category

[Other](https://www.pointfive.co/efficiency-hub/service-category/other)

Reference

CER-0424

Type

Idle or Unused Resource

## Explanation

Why the waste happens and who it affects.

It is typically used for incident investigations, audits and one-off analyses. Billing starts when the restore begins and continues every day until the restored table is dismissed by deleting it.

Investigators often finish their analysis and move on without deleting the \_RST table, so the restore keeps billing for days or weeks with no queries against it. Because restores are billed on a minimum of 2 TB, even a small restore that is left running costs as much per day as a 2 TB one. Azure Advisor flags workspaces with active restored tables through its Consider removing unused restored tables recommendation.

## Billing model

The pricing dimensions that drive this cost.

Restore is billed on the volume restored and the time the restore stays active.

Restore charge

Billed per GB per day for each UTC day the restore is active, until the \_RST table is deleted

Minimum volume

Each restore is billed for at least 2 TB, even if less data is restored

Minimum duration

Each restore is billed for at least 12 hours, with partial-day billing on the first and last days

Queries

Querying a restored table has no extra charge because restored tables use the Analytics plan

## How to detect

4 checks to find it in your estate.

- Review the Azure Advisor cost recommendation Consider removing unused restored tables on microsoft.operationalinsights/workspaces resources

- List tables in each workspace (Tables view in the portal or the Tables - Get API without a table name) and find those whose name ends in \_RST and that carry restoredLogs properties

- With query auditing enabled, search LAQueryLogs QueryText for each \_RST table name; restores with no queries for several days are idle

- In Cost Management, filter to the Log Analytics workspace and look for data restore charges on days when no investigation is open

## How to fix

4 ways to remove the waste.

- Delete the \_RST table as soon as the investigation is finished; deleting a restored table stops restore billing and does not delete data in the source table

- Restore only the time range needed, keeping in mind the 2 TB and 12-hour billing minimums, and set an owner and end date for every restore

- Use search jobs when only records matching specific criteria are needed, and export jobs for one-time bulk extracts, instead of restoring whole time ranges

- Set up an Azure Advisor alert on the unused restored tables recommendation so leftover restores are caught automatically

## Documentation

Vendor references for pricing and configuration.

- [Restore logs in Azure Monitor  learn.microsoft.com](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/restore)

- [Azure Monitor Logs Cost Calculations And Options  learn.microsoft.com](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/cost-logs)

- [Cost recommendations - Azure Advisor  learn.microsoft.com](https://learn.microsoft.com/en-us/azure/advisor/advisor-reference-cost-recommendations)

- [Cost optimization in Azure Monitor  learn.microsoft.com](https://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/best-practices-cost)

- [Pricing - Azure Monitor  azure.microsoft.com](https://azure.microsoft.com/en-us/pricing/details/monitor/)

## Related inefficiencies

[Browse the library](https://www.pointfive.co/efficiency-hub)

- Azure Log Analytics  CER-0197

### [Suboptimal Table Plan Selection in Log Analytics](https://www.pointfive.co/efficiency-hub/inefficiencies/suboptimal-table-plan-selection-in-log-analytics)

By default, all Log Analytics tables are created under the Analytics plan, which is optimized for high-performance querying and interactive analysis. However, not all telemetry requires real-time access or frequent querying. Some tables...

Other

- Azure Log Analytics  CER-0422

### [Missing Commitment Tier on High-Volume Log Analytics Workspaces](https://www.pointfive.co/efficiency-hub/inefficiencies/missing-commitment-tier-on-high-volume-log-analytics-workspaces)

Log Analytics workspaces default to pay-as-you-go pricing for Analytics Logs ingestion, with no minimum volume. Workspaces that grow to ingest a steady 100 GB or more per day keep paying the full per-GB rate unless someone changes the...

Other

- Azure Log Analytics  CER-0423

### [Excessive Analytics Retention in Log Analytics Workspaces](https://www.pointfive.co/efficiency-hub/inefficiencies/excessive-analytics-retention-in-log-analytics-workspaces)

Log Analytics keeps data in two states: analytics (interactive) retention, where it can be queried directly, and long-term retention, a lower-cost state from which data is retrieved with search jobs or restore. When a compliance or audit...

Other

---
Source: the public page above. Product screenshots and illustrative interfaces are examples, not live customer data.

