Incorrect data in the Usage table

Sándor Tőkési 181 Reputation points
2024-08-13T09:11:05.1833333+00:00

Hi folks

A few days ago I noticed an odd behavior in multiple environments. In these Sentinel instances we don't have any logs in the AzureDiagnotics table. But when I query the Usage table it shows some data for the AzureDiagnostics DataType. So, while the table itself is empty, the Usage table indicates some data is stored in it.

We are talking about a really low amount of data, sub-megabyte.

I've seen this behavior started to appear a week ago (around 6th of Aug) in most of the environments, but in some other ones I can see the same thing even on 2nd of Aug (that was the earliest I found).

No changes were made in these environments recently.

Is this a bug somewhere in Sentinel, or were some changes made by Microsoft in the background that creates un-queryable data in the AzureDiagnotics table? This behavior messes with some of my queries and rules, so I would like to understand why it started to happen recently?

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,154 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.