Skip to content

Commit 0f2398f

Browse files
authored
Update table action for unused data retention
1 parent 6953225 commit 0f2398f

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

articles/sentinel/soc-optimization/soc-optimization-reference.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -44,7 +44,7 @@ The following table lists the available data value SOC optimization recommendati
4444
| Observation | Action |
4545
|---------|---------|
4646
| The table wasn’t used by analytics rules or detections in the last 30 days but was used by other sources, such as workbooks, log queries, hunting queries. | Turn on analytics rule templates <br>OR<br>Move to [auxiliary logs (Preview) or basic logs](https://learn.microsoft.com/en-us/azure/sentinel/billing#auxiliary-logs-and-basic-logs) if the table is eligible. |
47-
| The table wasn’t used at all in the last 30 days. | Turn on analytics rule templates <br>OR<br> Stop data ingestion or archive the table. |
47+
| The table wasn’t used at all in the last 30 days. | Turn on analytics rule templates <br>OR<br> Stop data ingestion or move the table to long term retention. |
4848
| The table was only used by Azure Monitor. | Turn on any relevant analytics rule templates for tables with security value <br>OR<br>Move to a non-security Log Analytics workspace. |
4949

5050
If a table is chosen for [UEBA](/azure/sentinel/enable-entity-behavior-analytics) or a [threat intelligence matching analytics rule](/azure/sentinel/use-matching-analytics-to-detect-threats), SOC optimization doesn't recommend any changes in ingestion.

0 commit comments

Comments
 (0)