Q: Your AKS cluster generates 800 GB of stdout/stderr logs daily, resulting in an astronomical Azure Log Analytics ingestion invoice ($2.30/GB). Developers mostly generate noisy debug logs that are never queried. How do you re-architect Container Insights using Data Collection Rules (DCR) and ContainerLogV2 to slash ingestion volume by over 60%?
Step-by-step engineering runbook for reducing Azure Log Analytics ingestion costs by 65% using Data Collection Rules (DCR), custom log filtering, and ContainerLogV2 schema transformation.
Want to master this scenario in a live sandbox? Stephane Maarek's AWS Certified DevOps Engineer Professional Masterclass on Udemy covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Enable ContainerLogV2 High-Performance Schema
Switch from legacy ContainerLog schema to the modern, compact ContainerLogV2 format:
- ConfigMap Update: Deployed
container-azm-ms-agentconfigConfigMap inkube-systemsetting[log_collection_settings.schema] containerlog_schema_version = 'v2'. - Storage Efficiency: ContainerLogV2 consolidates pod and container metadata into a single structured record, reducing ingestion bytes by approximately 15% out of the box.
Create Data Collection Rule (DCR) with Ingestion-Time KQL Transformations
Filter out irrelevant namespaces and discard low-value debug log entries before they hit billing storage:
- Create DCR: Defined an Azure Monitor Data Collection Rule with an ingestion-time KQL stream transformation.
- Transformation KQL:
source | where PodNamespace !in ('kube-system', 'gatekeeper-system', 'datadog') | where LogSeverity !in ('DEBUG', 'TRACE'). - Link DCR to AKS: Associated DCR with cluster:
az monitor data-collection-rule association create --name aks-dcr-assoc --rule-id $DCR_ID --resource $AKS_CLUSTER_ID.
Configure Table Plan: Analytics vs Basic Log Tier
Shift high-volume, low-criticality logs to the Basic Logs pricing tier ($0.50/GB vs $2.30/GB):
- Basic Plan Migration: Configured
ContainerLogV2table plan toBasicfor non-production environments viaaz monitor log-analytics workspace table update -g rg-ops -w prod-laws -n ContainerLogV2 --plan Basic. - Retention Policy: Set interactive retention to 30 days and archived historical logs to Azure Storage Archive tier for compliance.
Audit Ingestion Volume Reductions & Query Latency
Measure and verify the exact reduction in daily GB ingestion:
- Audit Query: Executed KQL query on
Usage | where DataType == 'ContainerLogV2' | summarize sum(Quantity) by bin(TimeGenerated, 1d). - Results: Daily ingestion dropped from 820 GB/day to 275 GB/day, reducing monthly monitoring expenditure by over $37,000.
- Migrate from legacy ContainerLog to the optimized ContainerLogV2 schema.
- Deploy Data Collection Rules (DCR) with KQL transformations to filter out system and debug logs at ingestion.
- Transition non-production log workspaces to the cost-effective Basic Logs plan.
- Achieve an immediate 65% reduction in monthly Log Analytics ingestion expenses.