Microsoft Certified: Azure Security Engineer AssociateManage security operationsMedium

A global organization uses Azure Monitor to collect logs from various Azure resources and on-premises servers. They have a strict requirement to retain security-related logs for 7 years for compliance purposes. However, due to cost considerations, they want to retain performance metrics and non-security diagnostic logs for only 90 days. How can this requirement be met efficiently within a single Log Analytics workspace?

  1. ACreate separate Log Analytics workspaces for security logs and non-security logs, each with its own retention policy.
  2. BExport all logs to Azure Storage for long-term retention and configure different lifecycle policies in Storage.
  3. CUse Azure Data Explorer for security logs and Log Analytics for non-security logs.
  4. DConfigure different retention policies for each data type in the Log Analytics workspace.
Show answer & explanation

Correct answer: D. Configure different retention policies for each data type in the Log Analytics workspace.

Log Analytics workspaces allow for granular control over data retention. You can configure different retention periods for specific data types within the same workspace, enabling cost optimization and compliance with varying requirements.

Why the other options are wrong

  • A. While technically possible, creating separate workspaces increases management overhead and complexity, and is not the most efficient solution for differing retention requirements within the same organization.
  • B. Exporting all logs to Azure Storage is an option for very long-term archival, but it adds complexity for operational querying of recent data and doesn't directly address the need for different retention periods within the Log Analytics workspace itself.
  • C. Azure Data Explorer is a powerful analytics service but is not typically used as a direct replacement or alongside Log Analytics for standard security log collection and retention in this manner. It adds unnecessary complexity and cost.

Log Analytics Data Retention

The ability to configure how long different types of data are stored within an Azure Log Analytics workspace.

  • Retention can be configured at the workspace level, applying to all data.
  • Retention can also be configured per data type (table) for more granular control.
  • Granular retention helps manage costs and meet compliance requirements.

Memory trick: Log Analytics lets you 'sort' your logs by how long they 'stay' in the 'pile'.

More Manage security operations questions