# Find table overrides before changing Log Analytics workspace retention

> Why can a workspace retention change leave some Analytics tables unchanged?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-544-find-table-overrides-before-changing-log-analytics-workspace-retention/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:22:52+00:00
- Modified: 2026-09-10T02:11:19+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Why can a workspace retention change leave some Analytics tables unchanged?

## Potentially affected

Log Analytics tables using the Analytics plan.

## DSE recommendation

Separate inherited and table-specific retention settings before approving a workspace-wide retention change.

## Article

## Source facts

Analytics-plan tables inherit their workspace’s default retention unless configured otherwise. Changing the workspace default affects tables still inheriting it, not tables whose analytics retention was already changed individually. The Tables view exposes both analytics and total retention for review. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/data-retention-configure).

Analytics retention and total retention are different settings. Reducing the former without reducing the latter can move older data into long-term retention rather than discard it. Extending total retention applies to ingested data that has not already been removed; it does not restore deleted history. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/data-retention-configure).

## Applicability

This review is for Log Analytics tables using the Analytics plan. Establish the intended query-access period and total preservation period separately. Do not apply the workspace-default assumption indiscriminately to every table plan or treat this article as a retention requirement.

## DSE recommendation

DSE recommends a per-table change manifest identifying inherited settings, explicit overrides and the desired outcome. Ask the data owner to approve exceptions instead of removing them merely for uniformity. Preserve the prechange values and record whether older records should remain interactively available or only retained longer term.

## Verification

After an approved change, inspect every table in the manifest rather than checking only the workspace slider. Compare effective analytics and total retention with the approved pair of values. Investigate an unchanged table by checking for an override first. Retain the comparison and a representative data-access observation for the affected age range.

## Official references

[Microsoft Learn: Manage data retention](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/data-retention-configure).

## Primary reference

- Name: Manage Data Retention in a Log Analytics Workspace - Azure Monitor | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/data-retention-configure
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Find table overrides before changing Log Analytics workspace retention,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-544-find-table-overrides-before-changing-log-analytics-workspace-retention/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
