Place configuration and ingestion DCEs in the regions each function requires

Which region should a data collection endpoint use when agents and their workspace are in different regions?

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

Which region should a data collection endpoint use when agents and their workspace are in different regions?

Potentially affected

DCR-based Azure Monitor deployments that require data collection endpoints across resource and workspace regions.

DSE recommendation

Draw configuration retrieval and data ingestion as separate regional paths before assigning DCEs.

Source facts

Microsoft assigns different regional roles to DCE components. Configuration access belongs in the monitored resources’ region; log ingestion belongs with the destination Log Analytics workspace, and metric ingestion with the Azure Monitor workspace. For agents sending logs across regions, the documented design uses configuration endpoints in agent regions and ingestion in the workspace region. DCEs are not required for every collection scenario. Microsoft Learn.

Applicability

Apply this distinction to DCR-based collection after establishing that the source and connectivity design require a DCE. Inventory agent regions, destination workspace regions, and each endpoint’s purpose. Do not use this article as a claim that every Azure Monitor data path passes through a DCE.

DSE recommendation

Draw configuration retrieval and data ingestion as separate regional paths before assigning DCEs. For each monitored population, identify where its rules are retrieved and where its records enter the destination pipeline. Have the monitoring and network owners resolve an endpoint selected only because it sits near the agent when that endpoint is intended for workspace ingestion.

Verification

Inspect the configured endpoint identities and regions against the two paths. Check that representative agents obtain their intended configuration, then trace harmless records to the intended workspace independently. Preserve both results. An endpoint resource that was created successfully is not the acceptance record for regional routing, and successful configuration retrieval should not close an unresolved ingestion-path investigation.

Official references

Microsoft Learn: Data collection endpoints in Azure Monitor. Source reviewed September 9, 2026.

Primary reference

Review the official source

Data collection endpoints in Azure Monitor - Azure Monitor | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE