Skip to main content
resource · azure

Log Analytics Workspace

live rule families
1
schedulable
no
category
governance-services

Does ZopNight manage Log Analytics Workspace?

Log Analytics workspaces bill per GB ingested plus a separate retention surcharge on data kept beyond the included window. ZopNight discovers each workspace with its retentionInDays and SKU settings through Resource Graph and attributes its spend from Cost Management. Retained GB has no Azure metric, so ZopNight raises no retention recommendation.

At a glance

Log Analytics Workspace coverage facts.
Field Value
Scheduling notesdiscovery and cost visibility only.

Log Analytics workspaces ingest and retain telemetry for Azure Monitor, billed per GB ingested and per GB retained beyond the free window. Verbose diagnostic settings routinely make log ingestion a top-ten Azure line item.

Ingestion and retention meter separately

A workspace charges on two independent axes. Ingestion bills every GB written into the workspace, driven entirely by what diagnostic settings, agents, and Application Insights components send at it. Retention bills the data held past the included period, on dedicated Cost Management meters: “Pay-as-you-go Data Retention” (renamed “Analytics Logs Retention”) and the archive meter “Data Archive” (now “Long-term Retention”). Those are distinct from the ingestion meters on the same workspace. Trimming a long interactive-retention window removes exactly that surcharge without touching what gets collected.

Why ZopNight shows retention as a setting, not a price

Azure publishes no retained-GB metric for a workspace: the Usage metric measures ingested bytes, and nothing reports the cumulative volume currently held. Estimating the retention charge from ingestion would be fabrication. ZopNight records each workspace’s retentionInDays setting, but it does not separate the retention surcharge from ingestion in the bill, and the earlier excessive-retention rule (RC-1372) has been retired, so no retention recommendation fires. A workspace kept well past 90 days is still worth checking by hand in the portal.

Discovery and the commitment-tier review

Discovered via Azure Resource Graph with retention and SKU configuration. Cost Management billing attributes ingestion and retention spend, and high-ingestion workspaces surface for commitment-tier and retention review. Steady large-volume estates often pay pay-as-you-go rates a commitment tier would undercut.

The quiet ways a workspace inflates

Diagnostic settings that forward every category from every resource, sprawl of one-workspace-per-team each below any commitment tier, and retention set to the maximum on day one and never revisited are the recurring patterns worth auditing first.

Inspecting usage inside the portal

Azure portal → Log Analytics workspaces, then a workspace’s Usage and estimated costs blade, shows ingestion volume by solution and the current retention setting side by side.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·