Guidance on Filtering AppTraces Logs to Optimize Sentinel Workspace Usage

Someiah C S 100 Reputation points
2025-02-27T08:50:58.91+00:00

Hi Community,

I'm seeking advice on how to filter out AppTraces logs from being ingested into our Sentinel workspace. These logs are consuming significant storage space and, being categorized under Analytics logs, are contributing to increased costs. Since we're not utilizing them for our security monitoring purposes, I'd like to exclude them from ingestion.

I understand that implementing data collection rules (DCRs) can help manage log ingestion. However, I'm uncertain about the specific steps to configure these rules to filter out AppTraces logs effectively. Additionally, I'm aware that certain tables, including AppTraces, can be configured for Basic Logs, which might offer a more cost-effective solution.

Could anyone provide detailed guidance or share best practices on setting up these configurations? Any insights or resources would be greatly appreciated.

Thank you in advance for your assistance.

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
3,502 questions
{count} votes

Accepted answer
  1. Ashok Gandhi Kotnana 4,310 Reputation points Microsoft External Staff
    2025-03-04T06:40:51.6433333+00:00

    Hello Someiah C S ,

    I'm glad that you were able to resolve your issue and thank you for posting your solution so that others experiencing the same thing can easily reference this! Since the Microsoft Q&A community has a policy that "The question author cannot accept their own answer. They can only accept answers by others ", I'll repost your solution in case you'd like to "Accept " the answer.

    Issue:

    Guidance on Filtering App Traces Logs to Optimize Sentinel Workspace Usage?

    Solution:

    To optimize costs, I have moved AppTraces logs from Analytics Logs to Basic Logs and set the retention period to 30 days, as they are not being used for search queries. These logs will still be accessible within the App Function itself.

    If you have any other questions or are still running into more issues, please let me know. Thank you again for your time and patience throughout this issue.

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.

    https://learn.microsoft.com/en-us/answers/support/accept-answer#why-only-one-accepted-answer

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.