{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-398-treat-export-job-cancellation-as-a-permanent-stop-with-partial-output-left-behind/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-398-treat-export-job-cancellation-as-a-permanent-stop-with-partial-output-left-behind/",
        "slug": "dse-20260909-398-treat-export-job-cancellation-as-a-permanent-stop-with-partial-output-left-behind",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-398-treat-export-job-cancellation-as-a-permanent-stop-with-partial-output-left-behind/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-398-treat-export-job-cancellation-as-a-permanent-stop-with-partial-output-left-behind.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-398-treat-export-job-cancellation-as-a-permanent-stop-with-partial-output-left-behind/"
        },
        "title": "Treat export-job cancellation as a permanent stop with partial output left behind",
        "summary": "Can a canceled Azure Monitor Logs export be resumed, and what happens to files already written?",
        "format": {
            "slug": "briefing",
            "name": "Briefing"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:25:18+00:00",
        "modified_at": "2026-09-10T02:01:57+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 247,
        "potentially_affected": "Historical Azure Monitor Logs export jobs, currently in preview, using supported Analytics or Basic tables.",
        "dse_recommendation": "Approve cancellation with an explicit disposition for the partial dataset and a separate plan for any later export.",
        "primary_source": {
            "name": "Run an Export Job in Azure Monitor Logs (Preview) - Azure Monitor | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/azure-monitor/logs/export-job",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Azure Monitor Logs export jobs are a preview feature for historical records in Analytics or Basic tables; Auxiliary tables are unsupported. Microsoft says canceling a job ends it permanently and prevents retries, while data already exported remains in the destination storage account. The returned operationId is the jobId used to inspect, cancel, or retry an eligible job. <a href=\"https://learn.microsoft.com/en-us/azure/azure-monitor/logs/export-job\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this decision for an existing export job, not a continuous export rule or a source-table deletion. Confirm the job identity, requested interval, query, and destination accounts. Review current feature restrictions before planning a replacement operation; this brief does not establish new-job eligibility.</p>\n<h2>DSE recommendation</h2>\n<p>Approve cancellation with an explicit disposition for the partial dataset and a separate plan for any later export. Have the data owner distinguish stopping further work from removing files already produced. Mark an incomplete dataset accordingly, and retain its provenance so another operator does not accept it as the requested full interval. Avoid describing cancellation as a pause.</p>\n<h2>Verification</h2>\n<p>Inspect the terminal job status and account for the output already present at every configured destination. Compare that output with the requested scope before handing it to an investigation or reporting consumer. If another export is authorized, track its job and output separately and define how the two datasets will be reconciled. Do not remove partial evidence merely because the job is no longer running.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/azure-monitor/logs/export-job\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Run an export job in Azure Monitor Logs (preview)</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nAzure Monitor Logs export jobs are a preview feature for historical records in Analytics or Basic tables; Auxiliary tables are unsupported. Microsoft says canceling a job ends it permanently and prevents retries, while data already exported remains in the destination storage account. The returned operationId is the jobId used to inspect, cancel, or retry an eligible job. Microsoft Learn.\nApplicability\nUse this decision for an existing export job, not a continuous export rule or a source-table deletion. Confirm the job identity, requested interval, query, and destination accounts. Review current feature restrictions before planning a replacement operation; this brief does not establish new-job eligibility.\nDSE recommendation\nApprove cancellation with an explicit disposition for the partial dataset and a separate plan for any later export. Have the data owner distinguish stopping further work from removing files already produced. Mark an incomplete dataset accordingly, and retain its provenance so another operator does not accept it as the requested full interval. Avoid describing cancellation as a pause.\nVerification\nInspect the terminal job status and account for the output already present at every configured destination. Compare that output with the requested scope before handing it to an investigation or reporting consumer. If another export is authorized, track its job and output separately and define how the two datasets will be reconciled. Do not remove partial evidence merely because the job is no longer running.\nOfficial references\nMicrosoft Learn: Run an export job in Azure Monitor Logs (preview). Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nAzure Monitor Logs export jobs are a preview feature for historical records in Analytics or Basic tables; Auxiliary tables are unsupported. Microsoft says canceling a job ends it permanently and prevents retries, while data already exported remains in the destination storage account. The returned operationId is the jobId used to inspect, cancel, or retry an eligible job. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/export-job).\n\n## Applicability\n\nUse this decision for an existing export job, not a continuous export rule or a source-table deletion. Confirm the job identity, requested interval, query, and destination accounts. Review current feature restrictions before planning a replacement operation; this brief does not establish new-job eligibility.\n\n## DSE recommendation\n\nApprove cancellation with an explicit disposition for the partial dataset and a separate plan for any later export. Have the data owner distinguish stopping further work from removing files already produced. Mark an incomplete dataset accordingly, and retain its provenance so another operator does not accept it as the requested full interval. Avoid describing cancellation as a pause.\n\n## Verification\n\nInspect the terminal job status and account for the output already present at every configured destination. Compare that output with the requested scope before handing it to an investigation or reporting consumer. If another export is authorized, track its job and output separately and define how the two datasets will be reconciled. Do not remove partial evidence merely because the job is no longer running.\n\n## Official references\n\n[Microsoft Learn: Run an export job in Azure Monitor Logs (preview)](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/export-job). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-398-treat-export-job-cancellation-as-a-permanent-stop-with-partial-output-left-behind/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-398-treat-export-job-cancellation-as-a-permanent-stop-with-partial-output-left-behind/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-398-treat-export-job-cancellation-as-a-permanent-stop-with-partial-output-left-behind/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Treat export-job cancellation as a permanent stop with partial output left behind",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-398-treat-export-job-cancellation-as-a-permanent-stop-with-partial-output-left-behind/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-398-treat-export-job-cancellation-as-a-permanent-stop-with-partial-output-left-behind/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-398-treat-export-job-cancellation-as-a-permanent-stop-with-partial-output-left-behind/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-398-treat-export-job-cancellation-as-a-permanent-stop-with-partial-output-left-behind/",
                "headline": "Treat export-job cancellation as a permanent stop with partial output left behind",
                "description": "Can a canceled Azure Monitor Logs export be resumed, and what happens to files already written?",
                "abstract": "Can a canceled Azure Monitor Logs export be resumed, and what happens to files already written?",
                "articleBody": "Source facts\nAzure Monitor Logs export jobs are a preview feature for historical records in Analytics or Basic tables; Auxiliary tables are unsupported. Microsoft says canceling a job ends it permanently and prevents retries, while data already exported remains in the destination storage account. The returned operationId is the jobId used to inspect, cancel, or retry an eligible job. Microsoft Learn.\nApplicability\nUse this decision for an existing export job, not a continuous export rule or a source-table deletion. Confirm the job identity, requested interval, query, and destination accounts. Review current feature restrictions before planning a replacement operation; this brief does not establish new-job eligibility.\nDSE recommendation\nApprove cancellation with an explicit disposition for the partial dataset and a separate plan for any later export. Have the data owner distinguish stopping further work from removing files already produced. Mark an incomplete dataset accordingly, and retain its provenance so another operator does not accept it as the requested full interval. Avoid describing cancellation as a pause.\nVerification\nInspect the terminal job status and account for the output already present at every configured destination. Compare that output with the requested scope before handing it to an investigation or reporting consumer. If another export is authorized, track its job and output separately and define how the two datasets will be reconciled. Do not remove partial evidence merely because the job is no longer running.\nOfficial references\nMicrosoft Learn: Run an export job in Azure Monitor Logs (preview). Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:25:18+00:00",
                "dateModified": "2026-09-10T02:01:57+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-398-treat-export-job-cancellation-as-a-permanent-stop-with-partial-output-left-behind/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-398-treat-export-job-cancellation-as-a-permanent-stop-with-partial-output-left-behind/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Treat export-job cancellation as a permanent stop with partial output left behind"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Briefing",
                    "Information priority"
                ],
                "genre": "Briefing",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 247,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Run an Export Job in Azure Monitor Logs (Preview) - Azure Monitor | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/azure-monitor/logs/export-job"
                }
            }
        ]
    }
}