This article provides a practical workflow for reviewing and reducing Azure Log Analytics ingestion costs for Azure Virtual Desktop (AVD) monitoring, by tuning performance counter collection and retention settings.
The goal is to reduce avoidable ingestion while preserving enough data for operations, alerting, reporting, troubleshooting, and features that depend on Nerdio Manager or Azure Monitor.
The workflow applies to Log Analytics workspaces that collect AVD performance counters, diagnostics, and monitoring data. For the individual workspace tasks, see Log Analytics Management.
Nerdio Manager lets you manage Log Analytics workspaces and performance counters. Azure Monitor collects the specified counters at the configured sample rate on agents that have the counter installed. A higher sample frequency results in more collected data.
High-frequency collection is useful during active troubleshooting. For steady-state monitoring, many environments can use a less aggressive sample interval for selected counters, after you validate reporting and alert dependencies.
The following factors drive Log Analytics cost:
-
Number of session hosts sending data
-
Number of counters collected
-
Counter sample frequency
-
Number of instances per counter
-
Amount of diagnostic logging enabled
-
Data retention period
-
Number of host pools using the workspace
-
Troubleshooting settings left enabled after an incident
-
Duplicate or overlapping collection rules
-
Non-AVD resources sharing the same workspace
Performance counter cardinality matters. A single machine-level counter collected every few minutes is usually low volume. A per-disk, per-process, or multi-instance counter collected every 30 seconds across many hosts can create much more data.
Log Analytics management in Nerdio Manager is available only in the Premium edition.
Before you change any settings, answer the following questions:
-
Is this workspace used only for AVD monitoring?
-
Is the workspace shared with other Azure workloads?
-
Which host pools send data to this workspace?
-
Which dashboards, alerts, workbooks, or reports depend on this data?
-
Does your organization have a retention requirement?
-
Are any counters currently used for active troubleshooting?
-
Do you use Nerdio Manager Insights, Azure Monitor workbooks, custom KQL, or external reporting?
Caution
Don't remove counters or reduce retention blindly. Measure, document, and be able to reverse every cost reduction.
Match the collection level to the way you use the data:
|
Monitoring level |
Use case |
Recommended approach |
|---|---|---|
|
Baseline monitoring |
Normal operations |
Keep the core CPU, memory, disk, and session host health signals. Use a moderate or lower sample frequency where appropriate. |
|
Active troubleshooting |
Short-term incident or performance investigation |
Temporarily increase the sample frequency for the affected scope. Document the reason, and revert after resolution. |
|
Audit or historical reporting |
Compliance, trend analysis, executive reporting |
Keep retention aligned to your requirements. Focus optimization on counter selection and sample frequency. |
Start with Azure Monitor or Log Analytics usage analysis to understand where the data volume comes from. For details, see Microsoft Learn: Analyze usage in a Log Analytics workspace.
The following example KQL query shows high-level usage by data type:
Usage | where TimeGenerated > ago(30d) | where IsBillable == true | summarize TotalVolumeGB = sum(Quantity) / 1000 by DataType | order by TotalVolumeGB desc
The following example uses billed size, where supported:
search * | where TimeGenerated > ago(7d) | where _IsBillable == true | summarize BillableGB = sum(_BilledSize) / 1024 / 1024 / 1024 by $table | order by BillableGB desc
Validate the queries in your environment, because workspace schema and table usage can vary.
To review the workspace settings:
-
Navigate to Cloud Desktops > Storage > Log Analytics.
-
Locate the workspace.
-
Review the workspace configuration and data retention.
-
From the action menu, select Manage counters to review the collected counters and their sample rates.
Before you make any changes, record the following:
-
Workspace and host pools
-
Retention period
-
Counter names and sample rates
-
Custom counters
-
Recent changes
-
Estimated ingestion and the monthly cost trend
Look for:
-
Counters collected every 30 seconds
-
Per-disk counters
-
Per-process counters
-
Counters with many instances
-
Counters that aren't used in dashboards or alerts
-
Counters enabled during a prior troubleshooting event
-
Counters collected across all hosts when only one host pool requires them
Caution
Don't reduce a counter only because it's high volume. First confirm whether it's used for operational monitoring, alerting, right-sizing, troubleshooting, or customer reporting.
For steady-state monitoring, many environments don't need every performance counter at a very frequent sample rate. Increasing the interval from 30 seconds to 180 seconds can materially reduce ingestion for that counter, because fewer samples are collected. Use the following intervals as a guide:
|
Sample interval |
Typical use |
|---|---|
|
30 seconds |
Active troubleshooting or short-term investigation |
|
60 seconds |
Higher-resolution operational monitoring |
|
180 seconds |
Normal baseline monitoring for many counters |
|
300 seconds or higher |
Long-term trend monitoring where real-time granularity isn't required |
To change a counter's sample rate:
-
Navigate to Cloud Desktops > Storage > Log Analytics.
-
Locate the workspace, and then from the action menu select Manage counters.
-
Under Windows performance counters, change the Sample rate for each counter that you want to tune.
-
Select Apply.
Retention should match your business requirement. For many operational monitoring scenarios, 30 days can be enough. For audit, compliance, trend analysis, or executive reporting, you might need longer retention. Before you change retention, confirm:
-
Compliance requirements
-
Reporting requirements
-
Whether historical troubleshooting is required
-
Whether another system stores long-term data
Document the approved retention setting.
To change the retention period:
-
Navigate to Cloud Desktops > Storage > Log Analytics.
-
Locate the workspace, and then select Edit retention.
-
Enter the retention days, between 30 and 730.
-
Select OK.
Confirm that the following still work as expected:
-
Nerdio Manager dashboards
-
Nerdio Manager Insights. See Insights overview.
-
Azure Monitor workbooks
-
Alerts
-
KQL queries
-
Right-sizing reports. See Rules: Right-size AVD pooled desktops and Rules: Right-size AVD personal desktops.
-
Host pool utilization views
-
Support troubleshooting workflows
-
Exports or external reports
After you tune, allow enough time for ingestion patterns to normalize. In many environments, 24 to 72 hours is enough to see the directional impact. Review the monthly cost impact over a longer period. Compare:
-
Daily ingestion before and after
-
Top billable tables before and after
-
Estimated monthly cost before and after
-
Alert or dashboard impact
-
Troubleshooting impact
-
User experience impact
Log Analytics cost tuning isn't a one-time task. Review your settings after any of the following:
-
You add host pools or increase the session host count.
-
You change the monitoring configuration.
-
You enable new workbooks or diagnostics.
-
You complete a major Nerdio Manager upgrade. See Release Notes.
-
A troubleshooting event ends.
-
Security or audit requirements change.
-
Don't remove counters that active alerts or dashboards require.
-
Don't reduce retention below your compliance requirements.
-
Don't assume that all AVD-related tables can move to lower-cost table plans. Validate Microsoft support and feature impact first.
-
Don't leave troubleshooting-level collection enabled indefinitely.
-
Don't tune a shared workspace without confirming which other workloads use it.
-
Don't change production monitoring without documenting the current settings and a rollback plan.
-
Don't use ingestion reduction as a substitute for right-sizing the monitoring design.
-
Identify the top billable tables and data types.
-
Confirm which host pools send data to the workspace.
-
Review the current performance counters in Nerdio Manager.
-
Identify counters collected at 30-second intervals.
-
Confirm which counters dashboards, alerts, or reports use.
-
Move non-critical baseline counters to a longer sample interval.
-
Keep troubleshooting counters available, but scoped and temporary.
-
Review retention, and reduce it only if business requirements allow.
-
Validate dashboards, alerts, and reports.
-
Compare ingestion after 24 to 72 hours.
-
Document the monthly savings estimate.
|
Scenario |
Standard |
|---|---|
|
Normal operations |
Use baseline counter collection and a lower sample frequency for trend-only counters, and review ingestion monthly or quarterly. |
|
Troubleshooting |
Temporarily increase the sample frequency, scope the change narrowly, document the reason, revert after the incident, and compare ingestion before and after. |
Raise a support ticket for this item.
Comments (0 comments)