# Treat export-job cancellation as a permanent stop with partial output left behind

> Can a canceled Azure Monitor Logs export be resumed, and what happens to files already written?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-398-treat-export-job-cancellation-as-a-permanent-stop-with-partial-output-left-behind/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:25:18+00:00
- Modified: 2026-09-10T02:01:57+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Briefing
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Can a canceled Azure Monitor Logs export be resumed, and what happens to files already written?

## Potentially affected

Historical Azure Monitor Logs export jobs, currently in preview, using supported Analytics or Basic tables.

## DSE recommendation

Approve cancellation with an explicit disposition for the partial dataset and a separate plan for any later export.

## Article

## Source facts

Azure Monitor Logs export jobs are a preview feature for historical records in Analytics or Basic tables; Auxiliary tables are unsupported. Microsoft says canceling a job ends it permanently and prevents retries, while data already exported remains in the destination storage account. The returned operationId is the jobId used to inspect, cancel, or retry an eligible job. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/export-job).

## Applicability

Use this decision for an existing export job, not a continuous export rule or a source-table deletion. Confirm the job identity, requested interval, query, and destination accounts. Review current feature restrictions before planning a replacement operation; this brief does not establish new-job eligibility.

## DSE recommendation

Approve cancellation with an explicit disposition for the partial dataset and a separate plan for any later export. Have the data owner distinguish stopping further work from removing files already produced. Mark an incomplete dataset accordingly, and retain its provenance so another operator does not accept it as the requested full interval. Avoid describing cancellation as a pause.

## Verification

Inspect the terminal job status and account for the output already present at every configured destination. Compare that output with the requested scope before handing it to an investigation or reporting consumer. If another export is authorized, track its job and output separately and define how the two datasets will be reconciled. Do not remove partial evidence merely because the job is no longer running.

## Official references

[Microsoft Learn: Run an export job in Azure Monitor Logs (preview)](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/export-job). Source reviewed September 9, 2026.

## Primary reference

- Name: Run an Export Job in Azure Monitor Logs (Preview) - Azure Monitor | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/export-job
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Treat export-job cancellation as a permanent stop with partial output left behind,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-398-treat-export-job-cancellation-as-a-permanent-stop-with-partial-output-left-behind/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
