GuideInformationCybersecurityIT

Reconcile a Log Analytics volume spike against receipt time before changing collection

Why can an ingestion-volume increase be missing from records grouped by event time?

Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.
DSE visual intelligenceCyber defenseGuide · 2 min read
Executive summary

What you need to know

Why can an ingestion-volume increase be missing from records grouped by event time?

Potentially affected

Log Analytics investigations comparing Usage records with raw records grouped by TimeGenerated.

DSE recommendation

Compare receipt time with event time for the implicated table before interpreting the mismatch as changed workload activity.

Source facts

A Log Analytics Usage increase can disagree with raw-record totals grouped by TimeGenerated when older events arrive late. Microsoft gives disconnected agents sending accumulated data and incorrect host clocks as examples. The _TimeReceived field records arrival at Azure Monitor; comparing it with TimeGenerated helps investigate that discrepancy. Usage’s StartTime and EndTime describe its reporting buckets. Microsoft Learn.

Applicability

Use this investigation when receipt-oriented usage and event-time analysis disagree. The examples are possible explanations, not a diagnosis of the organization’s hosts. Identify the affected table and interval before widening the search or assuming new activity occurred at the same time as ingestion.

DSE recommendation

Compare receipt time with event time for the implicated table before interpreting the mismatch as changed workload activity. Ask the collection owner to retain the spike interval and the query definitions used on both sides. Examine the event-time distribution within that receipt interval, then relate any older records to actual agent connectivity and clock evidence. Avoid immediately reducing collection to hide a spike whose origin is still unknown.

Verification

Run a bounded table-specific comparison and preserve the arrival interval, event-time grouping and observed record totals. Confirm that the query’s time scope can include the older events being investigated. Document whether the evidence supports delayed delivery, a timestamp problem, another explanation, or an unresolved mismatch. Do not label historical records as newly generated solely because they became visible during the spike.

Official references

Microsoft Learn: Analyze Log Analytics usage. Source reviewed September 9, 2026.

Primary reference

Review the official source

Analyze usage in a Log Analytics workspace in Azure Monitor - Azure Monitor | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE