{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-475-place-configuration-and-ingestion-dces-in-the-regions-each-function-requires/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-475-place-configuration-and-ingestion-dces-in-the-regions-each-function-requires/",
        "slug": "dse-20260909-475-place-configuration-and-ingestion-dces-in-the-regions-each-function-requires",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-475-place-configuration-and-ingestion-dces-in-the-regions-each-function-requires/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-475-place-configuration-and-ingestion-dces-in-the-regions-each-function-requires.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-475-place-configuration-and-ingestion-dces-in-the-regions-each-function-requires/"
        },
        "title": "Place configuration and ingestion DCEs in the regions each function requires",
        "summary": "Which region should a data collection endpoint use when agents and their workspace are in different regions?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:24:01+00:00",
        "modified_at": "2026-09-10T02:08:05+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 241,
        "potentially_affected": "DCR-based Azure Monitor deployments that require data collection endpoints across resource and workspace regions.",
        "dse_recommendation": "Draw configuration retrieval and data ingestion as separate regional paths before assigning DCEs.",
        "primary_source": {
            "name": "Data collection endpoints in Azure Monitor - Azure Monitor | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/azure-monitor/data-collection/data-collection-endpoint-overview",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft assigns different regional roles to DCE components. Configuration access belongs in the monitored resources&#8217; region; log ingestion belongs with the destination Log Analytics workspace, and metric ingestion with the Azure Monitor workspace. For agents sending logs across regions, the documented design uses configuration endpoints in agent regions and ingestion in the workspace region. DCEs are not required for every collection scenario. <a href=\"https://learn.microsoft.com/en-us/azure/azure-monitor/data-collection/data-collection-endpoint-overview\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Apply this distinction to DCR-based collection after establishing that the source and connectivity design require a DCE. Inventory agent regions, destination workspace regions, and each endpoint&#8217;s purpose. Do not use this article as a claim that every Azure Monitor data path passes through a DCE.</p>\n<h2>DSE recommendation</h2>\n<p>Draw configuration retrieval and data ingestion as separate regional paths before assigning DCEs. For each monitored population, identify where its rules are retrieved and where its records enter the destination pipeline. Have the monitoring and network owners resolve an endpoint selected only because it sits near the agent when that endpoint is intended for workspace ingestion.</p>\n<h2>Verification</h2>\n<p>Inspect the configured endpoint identities and regions against the two paths. Check that representative agents obtain their intended configuration, then trace harmless records to the intended workspace independently. Preserve both results. An endpoint resource that was created successfully is not the acceptance record for regional routing, and successful configuration retrieval should not close an unresolved ingestion-path investigation.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/azure-monitor/data-collection/data-collection-endpoint-overview\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Data collection endpoints in Azure Monitor</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nMicrosoft assigns different regional roles to DCE components. Configuration access belongs in the monitored resources’ region; log ingestion belongs with the destination Log Analytics workspace, and metric ingestion with the Azure Monitor workspace. For agents sending logs across regions, the documented design uses configuration endpoints in agent regions and ingestion in the workspace region. DCEs are not required for every collection scenario. Microsoft Learn.\nApplicability\nApply this distinction to DCR-based collection after establishing that the source and connectivity design require a DCE. Inventory agent regions, destination workspace regions, and each endpoint’s purpose. Do not use this article as a claim that every Azure Monitor data path passes through a DCE.\nDSE recommendation\nDraw configuration retrieval and data ingestion as separate regional paths before assigning DCEs. For each monitored population, identify where its rules are retrieved and where its records enter the destination pipeline. Have the monitoring and network owners resolve an endpoint selected only because it sits near the agent when that endpoint is intended for workspace ingestion.\nVerification\nInspect the configured endpoint identities and regions against the two paths. Check that representative agents obtain their intended configuration, then trace harmless records to the intended workspace independently. Preserve both results. An endpoint resource that was created successfully is not the acceptance record for regional routing, and successful configuration retrieval should not close an unresolved ingestion-path investigation.\nOfficial references\nMicrosoft Learn: Data collection endpoints in Azure Monitor. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft assigns different regional roles to DCE components. Configuration access belongs in the monitored resources’ region; log ingestion belongs with the destination Log Analytics workspace, and metric ingestion with the Azure Monitor workspace. For agents sending logs across regions, the documented design uses configuration endpoints in agent regions and ingestion in the workspace region. DCEs are not required for every collection scenario. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/data-collection/data-collection-endpoint-overview).\n\n## Applicability\n\nApply this distinction to DCR-based collection after establishing that the source and connectivity design require a DCE. Inventory agent regions, destination workspace regions, and each endpoint’s purpose. Do not use this article as a claim that every Azure Monitor data path passes through a DCE.\n\n## DSE recommendation\n\nDraw configuration retrieval and data ingestion as separate regional paths before assigning DCEs. For each monitored population, identify where its rules are retrieved and where its records enter the destination pipeline. Have the monitoring and network owners resolve an endpoint selected only because it sits near the agent when that endpoint is intended for workspace ingestion.\n\n## Verification\n\nInspect the configured endpoint identities and regions against the two paths. Check that representative agents obtain their intended configuration, then trace harmless records to the intended workspace independently. Preserve both results. An endpoint resource that was created successfully is not the acceptance record for regional routing, and successful configuration retrieval should not close an unresolved ingestion-path investigation.\n\n## Official references\n\n[Microsoft Learn: Data collection endpoints in Azure Monitor](https://learn.microsoft.com/en-us/azure/azure-monitor/data-collection/data-collection-endpoint-overview). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-475-place-configuration-and-ingestion-dces-in-the-regions-each-function-requires/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-475-place-configuration-and-ingestion-dces-in-the-regions-each-function-requires/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-475-place-configuration-and-ingestion-dces-in-the-regions-each-function-requires/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Place configuration and ingestion DCEs in the regions each function requires",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-475-place-configuration-and-ingestion-dces-in-the-regions-each-function-requires/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-475-place-configuration-and-ingestion-dces-in-the-regions-each-function-requires/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-475-place-configuration-and-ingestion-dces-in-the-regions-each-function-requires/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-475-place-configuration-and-ingestion-dces-in-the-regions-each-function-requires/",
                "headline": "Place configuration and ingestion DCEs in the regions each function requires",
                "description": "Which region should a data collection endpoint use when agents and their workspace are in different regions?",
                "abstract": "Which region should a data collection endpoint use when agents and their workspace are in different regions?",
                "articleBody": "Source facts\nMicrosoft assigns different regional roles to DCE components. Configuration access belongs in the monitored resources’ region; log ingestion belongs with the destination Log Analytics workspace, and metric ingestion with the Azure Monitor workspace. For agents sending logs across regions, the documented design uses configuration endpoints in agent regions and ingestion in the workspace region. DCEs are not required for every collection scenario. Microsoft Learn.\nApplicability\nApply this distinction to DCR-based collection after establishing that the source and connectivity design require a DCE. Inventory agent regions, destination workspace regions, and each endpoint’s purpose. Do not use this article as a claim that every Azure Monitor data path passes through a DCE.\nDSE recommendation\nDraw configuration retrieval and data ingestion as separate regional paths before assigning DCEs. For each monitored population, identify where its rules are retrieved and where its records enter the destination pipeline. Have the monitoring and network owners resolve an endpoint selected only because it sits near the agent when that endpoint is intended for workspace ingestion.\nVerification\nInspect the configured endpoint identities and regions against the two paths. Check that representative agents obtain their intended configuration, then trace harmless records to the intended workspace independently. Preserve both results. An endpoint resource that was created successfully is not the acceptance record for regional routing, and successful configuration retrieval should not close an unresolved ingestion-path investigation.\nOfficial references\nMicrosoft Learn: Data collection endpoints in Azure Monitor. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:24:01+00:00",
                "dateModified": "2026-09-10T02:08:05+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-475-place-configuration-and-ingestion-dces-in-the-regions-each-function-requires/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-475-place-configuration-and-ingestion-dces-in-the-regions-each-function-requires/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Place configuration and ingestion DCEs in the regions each function requires"
                },
                "articleSection": [
                    "IT",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "IT",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 241,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Data collection endpoints in Azure Monitor - Azure Monitor | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/azure-monitor/data-collection/data-collection-endpoint-overview"
                }
            }
        ]
    }
}