# Account for checkpoint reset when recreating Event Hubs log ingestion

> What can happen to retained events when a direct Event Hubs-to-Logs association is removed and rebuilt?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-468-account-for-checkpoint-reset-when-recreating-event-hubs-log-ingestion/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:24:08+00:00
- Modified: 2026-09-10T02:08:04+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

What can happen to retained events when a direct Event Hubs-to-Logs association is removed and rebuilt?

## Potentially affected

Existing eligible direct Event Hubs ingestion into Azure Monitor Logs, a public-preview feature.

## DSE recommendation

Treat removal of the last ingestion association as a checkpoint change, not just temporary configuration cleanup.

## Article

## Source facts

Direct Event Hubs ingestion into Azure Monitor Logs is in public preview. Microsoft states that removing all related DCR associations stops ingestion; deleting those associations or their DCRs also resets Event Hub checkpointing. When an association is created, ingestion includes events already retained in the hub as well as new arrivals. Recreating configuration therefore needs a deliberate review of the retained-event starting point. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/ingest-logs-event-hub).

## Applicability

Apply this review to an existing eligible direct-ingestion setup. Confirm the Event Hub, consumer group, associations, rules, and destination table before a rebuild. Check the current preview prerequisites and regional capacity if establishing a new deployment; this article does not replace that readiness work.

## DSE recommendation

Treat removal of the last ingestion association as a checkpoint change, not just temporary configuration cleanup. Record what is already stored at the destination and what remains retained at the source. Ask the ingestion owner to define how any re-read events will be recognized and reconciled. Do not assume that restoring a similarly named association preserves the former progress record.

## Verification

Rehearse the approved rebuild in a test stream containing identifiable retained events and fresh arrivals. Compare destination records before and after association recreation. Preserve observed re-reading, gaps, and timing as separate findings rather than hiding them in a total row count. Use the resulting evidence to approve the production reconciliation approach before removing an existing ingestion relationship.

## Official references

[Microsoft Learn: Ingest Event Hubs events into Azure Monitor Logs (Public Preview)](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/ingest-logs-event-hub). Source reviewed September 9, 2026.

## Primary reference

- Name: Ingest events from Azure Event Hubs into Azure Monitor Logs (Preview) - Azure Monitor | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/ingest-logs-event-hub
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Account for checkpoint reset when recreating Event Hubs log ingestion,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-468-account-for-checkpoint-reset-when-recreating-event-hubs-log-ingestion/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
