{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-544-find-table-overrides-before-changing-log-analytics-workspace-retention/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-544-find-table-overrides-before-changing-log-analytics-workspace-retention/",
        "slug": "dse-20260909-544-find-table-overrides-before-changing-log-analytics-workspace-retention",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-544-find-table-overrides-before-changing-log-analytics-workspace-retention/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-544-find-table-overrides-before-changing-log-analytics-workspace-retention.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-544-find-table-overrides-before-changing-log-analytics-workspace-retention/"
        },
        "title": "Find table overrides before changing Log Analytics workspace retention",
        "summary": "Why can a workspace retention change leave some Analytics tables unchanged?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:22:52+00:00",
        "modified_at": "2026-09-10T02:11:19+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 240,
        "potentially_affected": "Log Analytics tables using the Analytics plan.",
        "dse_recommendation": "Separate inherited and table-specific retention settings before approving a workspace-wide retention change.",
        "primary_source": {
            "name": "Manage Data Retention in a Log Analytics Workspace - Azure Monitor | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/azure-monitor/logs/data-retention-configure",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Analytics-plan tables inherit their workspace&#8217;s default retention unless configured otherwise. Changing the workspace default affects tables still inheriting it, not tables whose analytics retention was already changed individually. The Tables view exposes both analytics and total retention for review. <a href=\"https://learn.microsoft.com/en-us/azure/azure-monitor/logs/data-retention-configure\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<p>Analytics retention and total retention are different settings. Reducing the former without reducing the latter can move older data into long-term retention rather than discard it. Extending total retention applies to ingested data that has not already been removed; it does not restore deleted history. <a href=\"https://learn.microsoft.com/en-us/azure/azure-monitor/logs/data-retention-configure\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>This review is for Log Analytics tables using the Analytics plan. Establish the intended query-access period and total preservation period separately. Do not apply the workspace-default assumption indiscriminately to every table plan or treat this article as a retention requirement.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends a per-table change manifest identifying inherited settings, explicit overrides and the desired outcome. Ask the data owner to approve exceptions instead of removing them merely for uniformity. Preserve the prechange values and record whether older records should remain interactively available or only retained longer term.</p>\n<h2>Verification</h2>\n<p>After an approved change, inspect every table in the manifest rather than checking only the workspace slider. Compare effective analytics and total retention with the approved pair of values. Investigate an unchanged table by checking for an override first. Retain the comparison and a representative data-access observation for the affected age range.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/azure-monitor/logs/data-retention-configure\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Manage data retention</a>.</p>",
        "content_text": "Source facts\nAnalytics-plan tables inherit their workspace’s default retention unless configured otherwise. Changing the workspace default affects tables still inheriting it, not tables whose analytics retention was already changed individually. The Tables view exposes both analytics and total retention for review. Microsoft Learn.\nAnalytics retention and total retention are different settings. Reducing the former without reducing the latter can move older data into long-term retention rather than discard it. Extending total retention applies to ingested data that has not already been removed; it does not restore deleted history. Microsoft Learn.\nApplicability\nThis review is for Log Analytics tables using the Analytics plan. Establish the intended query-access period and total preservation period separately. Do not apply the workspace-default assumption indiscriminately to every table plan or treat this article as a retention requirement.\nDSE recommendation\nDSE recommends a per-table change manifest identifying inherited settings, explicit overrides and the desired outcome. Ask the data owner to approve exceptions instead of removing them merely for uniformity. Preserve the prechange values and record whether older records should remain interactively available or only retained longer term.\nVerification\nAfter an approved change, inspect every table in the manifest rather than checking only the workspace slider. Compare effective analytics and total retention with the approved pair of values. Investigate an unchanged table by checking for an override first. Retain the comparison and a representative data-access observation for the affected age range.\nOfficial references\nMicrosoft Learn: Manage data retention.",
        "content_markdown": "## Source facts\n\nAnalytics-plan tables inherit their workspace’s default retention unless configured otherwise. Changing the workspace default affects tables still inheriting it, not tables whose analytics retention was already changed individually. The Tables view exposes both analytics and total retention for review. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/data-retention-configure).\n\nAnalytics retention and total retention are different settings. Reducing the former without reducing the latter can move older data into long-term retention rather than discard it. Extending total retention applies to ingested data that has not already been removed; it does not restore deleted history. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/data-retention-configure).\n\n## Applicability\n\nThis review is for Log Analytics tables using the Analytics plan. Establish the intended query-access period and total preservation period separately. Do not apply the workspace-default assumption indiscriminately to every table plan or treat this article as a retention requirement.\n\n## DSE recommendation\n\nDSE recommends a per-table change manifest identifying inherited settings, explicit overrides and the desired outcome. Ask the data owner to approve exceptions instead of removing them merely for uniformity. Preserve the prechange values and record whether older records should remain interactively available or only retained longer term.\n\n## Verification\n\nAfter an approved change, inspect every table in the manifest rather than checking only the workspace slider. Compare effective analytics and total retention with the approved pair of values. Investigate an unchanged table by checking for an override first. Retain the comparison and a representative data-access observation for the affected age range.\n\n## Official references\n\n[Microsoft Learn: Manage data retention](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/data-retention-configure)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-544-find-table-overrides-before-changing-log-analytics-workspace-retention/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-544-find-table-overrides-before-changing-log-analytics-workspace-retention/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-544-find-table-overrides-before-changing-log-analytics-workspace-retention/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Find table overrides before changing Log Analytics workspace retention",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-544-find-table-overrides-before-changing-log-analytics-workspace-retention/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-544-find-table-overrides-before-changing-log-analytics-workspace-retention/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-544-find-table-overrides-before-changing-log-analytics-workspace-retention/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-544-find-table-overrides-before-changing-log-analytics-workspace-retention/",
                "headline": "Find table overrides before changing Log Analytics workspace retention",
                "description": "Why can a workspace retention change leave some Analytics tables unchanged?",
                "abstract": "Why can a workspace retention change leave some Analytics tables unchanged?",
                "articleBody": "Source facts\nAnalytics-plan tables inherit their workspace’s default retention unless configured otherwise. Changing the workspace default affects tables still inheriting it, not tables whose analytics retention was already changed individually. The Tables view exposes both analytics and total retention for review. Microsoft Learn.\nAnalytics retention and total retention are different settings. Reducing the former without reducing the latter can move older data into long-term retention rather than discard it. Extending total retention applies to ingested data that has not already been removed; it does not restore deleted history. Microsoft Learn.\nApplicability\nThis review is for Log Analytics tables using the Analytics plan. Establish the intended query-access period and total preservation period separately. Do not apply the workspace-default assumption indiscriminately to every table plan or treat this article as a retention requirement.\nDSE recommendation\nDSE recommends a per-table change manifest identifying inherited settings, explicit overrides and the desired outcome. Ask the data owner to approve exceptions instead of removing them merely for uniformity. Preserve the prechange values and record whether older records should remain interactively available or only retained longer term.\nVerification\nAfter an approved change, inspect every table in the manifest rather than checking only the workspace slider. Compare effective analytics and total retention with the approved pair of values. Investigate an unchanged table by checking for an override first. Retain the comparison and a representative data-access observation for the affected age range.\nOfficial references\nMicrosoft Learn: Manage data retention.",
                "datePublished": "2026-09-10T00:22:52+00:00",
                "dateModified": "2026-09-10T02:11:19+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-544-find-table-overrides-before-changing-log-analytics-workspace-retention/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-544-find-table-overrides-before-changing-log-analytics-workspace-retention/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Find table overrides before changing Log Analytics workspace retention"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 240,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Manage Data Retention in a Log Analytics Workspace - Azure Monitor | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/azure-monitor/logs/data-retention-configure"
                }
            }
        ]
    }
}