What you need to know
Why can an ingestion-volume increase be missing from records grouped by event time?
Potentially affected
Log Analytics investigations comparing Usage records with raw records grouped by TimeGenerated.
DSE recommendation
Compare receipt time with event time for the implicated table before interpreting the mismatch as changed workload activity.
Source facts
A Log Analytics Usage increase can disagree with raw-record totals grouped by TimeGenerated when older events arrive late. Microsoft gives disconnected agents sending accumulated data and incorrect host clocks as examples. The _TimeReceived field records arrival at Azure Monitor; comparing it with TimeGenerated helps investigate that discrepancy. Usage’s StartTime and EndTime describe its reporting buckets. Microsoft Learn.
Applicability
Use this investigation when receipt-oriented usage and event-time analysis disagree. The examples are possible explanations, not a diagnosis of the organization’s hosts. Identify the affected table and interval before widening the search or assuming new activity occurred at the same time as ingestion.
DSE recommendation
Compare receipt time with event time for the implicated table before interpreting the mismatch as changed workload activity. Ask the collection owner to retain the spike interval and the query definitions used on both sides. Examine the event-time distribution within that receipt interval, then relate any older records to actual agent connectivity and clock evidence. Avoid immediately reducing collection to hide a spike whose origin is still unknown.
Verification
Run a bounded table-specific comparison and preserve the arrival interval, event-time grouping and observed record totals. Confirm that the query’s time scope can include the older events being investigated. Document whether the evidence supports delayed delivery, a timestamp problem, another explanation, or an unresolved mismatch. Do not label historical records as newly generated solely because they became visible during the spike.
Official references
Microsoft Learn: Analyze Log Analytics usage. Source reviewed September 9, 2026.
Review the official source
Analyze usage in a Log Analytics workspace in Azure Monitor - Azure Monitor | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE