what is the difference between azure log analytics search job and restore job?

Manoj Kumar Reddy Gummalla 0 Reputation points
2023-02-06T21:54:33.5633333+00:00

Hi,

I have been going through the Azure log analytics documentation, and couldn't find the major differences between the search job and the restore job.
The below snapshots show both works on archived logs and both are could be used when a query likely to run longer than 10 mins.

hopes someone could help me with this.

Thank you

Screen Shot 2023-02-06 at 4.51.25 PM

Screen Shot 2023-02-06 at 4.51.45 PM

Azure Synapse Analytics
Azure Synapse Analytics
An Azure analytics service that brings together data integration, enterprise data warehousing, and big data analytics. Previously known as Azure SQL Data Warehouse.
4,422 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. David Broggy 5,681 Reputation points MVP
    2023-02-06T23:51:42.8533333+00:00

    Hi Manoj,

    From my experience, the main differences are:

    • cost - you are charged for archive queries
    • speed - since you're querying the archive data the latency will be much slower
    • availability of data - the data you are querying is only the archived data, not the data in the log analytics workspace.

    Also you would not use archived logs for anything in Sentinel except ad-hoc kql queries.

    References:
    https://azure.microsoft.com/en-us/pricing/details/monitor/

    https://learn.microsoft.com/en-us/azure/azure-monitor/logs/data-retention-archive?tabs=portal-1%2Cportal-2#pricing-model

    https://learn.microsoft.com/en-us/azure/azure-monitor/logs/data-retention-archive?tabs=portal-1%2Cportal-2

    https://learn.microsoft.com/en-us/azure/azure-monitor/logs/restore?tabs=api-1