By Cloudledger · Updated
Ingestion volume drives the bill
Azure Monitor Logs is generally charged on the volume of data ingested and on retention beyond the included period, with commitment tiers available at higher volumes. A single verbose diagnostic setting, a chatty application log or a newly onboarded subscription can change the monthly figure sharply.
Find the tables and resources responsible
Use workspace usage queries to rank data volume by table and by resource. Ingestion is rarely spread evenly: a small number of tables usually dominates. Investigate the top contributors before adjusting anything globally.
- Review workspace usage by table over a representative period.
- Identify the resources sending the largest volumes.
- Check which diagnostic settings and agents produce that data.
- Confirm which logs are used by alerts, dashboards or investigations.
Keep what is used, reduce what is not
Options include narrowing diagnostic categories, filtering at the source, choosing a lower-cost table plan where appropriate, adjusting retention and archiving data that is needed only occasionally. Each option changes what you can query later, so review with the people who rely on those logs during incidents.
Retention and archive are different questions
Interactive retention keeps data immediately queryable; archive or long-term retention usually costs less but adds a restore or search step. Security and compliance requirements often set a floor. Confirm those requirements before reducing retention to save money.
Verify the change
After adjusting settings, compare ingestion volume and cost over a complete period and confirm alerts and dashboards still work. A saving that quietly breaks an incident workflow is not a saving. Cloudledger can surface the monitoring meters in the wider cost picture so the trade-off is visible.