Plan log storage by data state, table plan, and tier. Analytics retention supports interactive queries, alerts, hunting, and workbooks. Long-term retention lowers storage cost and is accessed through search jobs, restore, or lake jobs.
| Plan / tier | Best for | Key limitation |
|---|
| Analytics plan / tier | Continuous monitoring, detections, joins, hunting, and workbooks. | Higher ingestion and retention cost. |
| Basic plan | Occasional troubleshooting with single-table queries. | Restricted KQL; no join, union, or summarize in the lesson. |
| Auxiliary plan | Verbose, low-touch audit or compliance data. | Unoptimized single-table access. |
| Data lake tier | Low-cost secondary and long-term data. | No real-time analytics or threat hunting; use KQL/Spark jobs and summaries. |
| XDR default tier | Defender XDR hunting data included for 30 days. | Not stored in Sentinel tiers unless supported retention is extended. |
Analytics retention can be 30 days to two years; total lake retention can extend to 12 years where supported. Moving a table out of analytics can stop alerts, advanced hunting, analytics rules, and custom detections that depend on it.
Official lessonTable plans, tiers, and retention