Guidance on Filtering AppTraces Logs to Optimize Sentinel Workspace Usage
Hi Community,
I'm seeking advice on how to filter out AppTraces logs from being ingested into our Sentinel workspace. These logs are consuming significant storage space and, being categorized under Analytics logs, are contributing to increased costs. Since we're not utilizing them for our security monitoring purposes, I'd like to exclude them from ingestion.
I understand that implementing data collection rules (DCRs) can help manage log ingestion. However, I'm uncertain about the specific steps to configure these rules to filter out AppTraces logs effectively. Additionally, I'm aware that certain tables, including AppTraces, can be configured for Basic Logs, which might offer a more cost-effective solution.
Could anyone provide detailed guidance or share best practices on setting up these configurations? Any insights or resources would be greatly appreciated.
Thank you in advance for your assistance.