Your Azure Monitor Bill is Probably Wrong — Here is How to Tune It Down 30-60%
Log Analytics ingestion is the quietest line item to overshoot. A handful of well-targeted changes — table tiers, retention, sampling, daily caps — can cut the bill 30-60% without losing the signal you need.
Of every line on an Azure bill, the one most teams under-tune is Log Analytics + Application Insights. Compute and storage get scrutinized constantly; monitoring just keeps growing because nobody ever set up a budget for it. Six months in, you find out your ingestion bill quietly went from $300/mo to $1,800/mo.
Cutting Azure Monitor cost without losing your observability comes down to four levers. Most teams have not touched any of them.
1. Move high-volume tables to Basic or Auxiliary
Log Analytics now offers per-table billing tiers:
- Analytics (default) — full KQL, full retention. Most expensive.
- Basic — KQL queries limited to lookups (no aggregations), 30-day retention max. ~70% cheaper.
- Auxiliary — bulk dump with no online query, archived for compliance. Cheapest.
The biggest ingestion volume in most workspaces comes from a handful of tables: AzureDiagnostics, AzureMetrics, ContainerLogV2, AppTraces. Look at which of these you actually query day-to-day. ContainerLogV2 you probably need on Analytics. AzureDiagnostics — much of it is policy / activity stuff you never write a KQL query against. Move it to Basic. Compliance archives that you have to keep but never read live: Auxiliary.
2. Cut retention to what you actually need
Default Log Analytics retention is 30 days included; anything past that costs per GB-month. Most teams set retention to 90 days because someone in compliance said "at least 90" once and nobody re-checked.
Audit the actual queries your team runs over the last month. If 95% of queries hit data less than 14 days old, your Analytics retention should be 14 days. Compliance data can sit in archive-only retention separately (cheaper per GB) and be re-hydrated when needed.
3. Adaptive sampling on Application Insights
Application Insights bills per GB ingested. By default the SDK sends every request, every dependency call, every trace. On a busy app this is millions of events per day.
Adaptive sampling, configured in the SDK, picks a representative subset (typically 5-25% of events) and scales the volume back. The retained traces still tell the story; failure-rate and latency percentiles stay accurate. Set the sampling target to keep telemetry under 1 GB/day per environment as a sanity check.
Also use telemetry processors to drop noise: health-check pings, expected 404s, polling endpoints that produce nothing actionable. These can easily be 20-40% of the volume.
4. Daily ingestion cap as the safety net
For every Log Analytics workspace and every App Insights resource, set a daily ingestion cap in the resource's Usage and estimated costs blade. Even if a misconfigured app starts hammering the workspace, the cap prevents a 24-hour incident from costing you $5,000.
Set the cap to roughly 1.5× your normal ingestion. The day someone trips it, the alert tells you something is broken instead of the bill telling you next month.
5. Commitment tiers, if you ingest a lot
Over ~100 GB/day of ingestion, switching to a Commitment Tier locks in roughly 30% savings vs. pay-as-you-go. Tiers are at 100, 200, 300, 400, 500, 1000, 2000, 5000 GB/day. The bet: you keep that volume or grow into it. The risk: you over-commit during a quiet quarter. For steady workloads this is a clean win.
A realistic before/after
A mid-size Azure workload spending $1,800/mo on monitoring typically lands here after a tune-up:
- Move AzureDiagnostics (~40% of volume) to Basic plan: ~$450/mo saved.
- Cut retention from 90 to 14 days on Analytics tier, with archive-only retention for compliance: ~$200/mo saved.
- Enable adaptive sampling on App Insights + drop health-check telemetry: ~$300/mo saved.
- Daily cap as safety net: $0 saved on the happy path, $1,000+ saved the day something breaks.
That is $950/mo (~53%) off the monitoring bill, without losing the signal you actually use to operate.
Where CloudRift fits
CloudRift's explainer for Log Analytics workspaces and App Insights resources surfaces the exact lever — table plan, retention, sampling, cap — not the generic "review your tier" message most cost tools give. The detail panel tells you which lever applies to your ingestion mix, and the recommendation engine sorts opportunities by realized dollar impact. We do not say "could save $X" — we say "this table on this workspace is driving 38% of your ingestion and is on the wrong plan."
See your own wasted cloud spend in minutes
Connect read-only, run a free scan, and get a prioritized list of savings with dollars attached.