Data segregation in log analytic workspace for sentinel

Anonymous
2025-05-21T07:21:43+00:00

i have main table created in log analytic workspace where all the logs are coming from different source. i want to transfer those all the log into dedicated data source table. who to do that. do i need to create custom table for that? please share the step for data segregation

Microsoft 365 and Office | Microsoft 365 Defender | Other | Other

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
{count} votes
Answer accepted by question author
  1. Anonymous
    2025-05-21T09:10:34+00:00

    Hi Foram,

    I'm Maj, an Independent Advisor. Thanks for getting in touch with the Microsoft Community. Let's work on this together.

    If you want to segregate your logs in the Log Analytics workspace, you’ll want to create custom tables for each data source. This allows you to organize and query logs more efficiently. You can achieve this by setting up data collection rules or using Azure Monitor’s data ingestion features to route specific logs into these custom tables. Once the custom tables are created, configure your data sources or queries to direct logs accordingly. This approach keeps your workspace clean and improves log management.

    To help you better, could you share how your current logs are ingested? Are you using agents, diagnostic settings or something else? Also, do you want this segregation to happen in real-time or as a scheduled process?

    1 person found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Anonymous
    2025-05-21T16:29:25+00:00

    Thank you, Raj, for sharing valuable information. What is the purpose of creating endpoint before DCR? also, where should i define like transfer log from existing table into new custom data? how to achieve this?

    0 comments No comments