Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
This article provides a reference of all Azure Monitor Logs tables in a Log Analytics workspace and their support for key features.
| Feature | Icon | Description |
|---|---|---|
| Basic table support | Basic table plans provide cost-effective storage for less frequently accessed data needed for troubleshooting and incident response. | |
| Auxiliary / Lake table support | Auxiliary table plans provide long-term, inexpensive storage for high-volume, verbose logs, and data required for auditing and compliance. Auxiliary tables are also referred to as Lake-only ingestion, referring to support for ingesting to Microsoft Sentinel Datalake without being mirrored from an analytics table. | |
| DCR workspace transformation support | Data collection rules (DCRs) can use a workspace transformation to filter or modify incoming data before it's sent to a Log Analytics workspace. This feature is also referred to as ingestion-time DCR support, or the filter feature in Microsoft Sentinel. | |
| Ingestion API support | ✅ | Logs Ingestion API and client libraries that implement it can send data to tables that support the API. |
Note
Table feature support is added regularly. Check this article for updates.
The following reference matrix includes all Azure Monitor Logs tables. This same list of tables is available through the anonymous API call, https://api.loganalytics.io/v1/metadata. Feature columns are blank when a table doesn't support that feature.