Share via

Failed to save analytics rule query.

3PI 20 Reputation points
2024-05-03T04:18:08.0833333+00:00

I can create any active analytics rule query in Microsoft Sentinel.
While trying to create a new one a error occurs: "Failed to save the analytics rule query. Log Analytics workspace 'xxx' could not be found."
It started when the previous workspace (with whole resource group) was destroyed in terraform, which I use as IaaC tool). Then new workspace was created with the same name as the previous one.
Now both Log Analytics Workspace and Microsoft Sentinel are displayed as connected in Azure Platform.
I successfully test queries for analytics rule against current configuration, but it fails while creating active rule.
Workspace id displayed in the error message matches id of the destroyed workspace.
Is there any way to fix this, so the new rules will be assigned to the correct workspace?

Azure | Azure Startups
Azure | Azure Startups

Startups: Companies that are in their initial stages of business and typically developing a business model and seeking financing.

Microsoft Security | Microsoft Sentinel
0 comments No comments

Answer accepted by question author

Akshay Kaushik 18,026 Reputation points Microsoft Employee Moderator
2024-05-07T08:55:52.2066667+00:00

@3PI

Thank you for posting your query on Microsoft Q&A.

From above description I could understand that you had an old workspace which was deleted, later on you created a new workspace with same name but now when you are querying your workspace it still getting redirected to old ones with old Workspace id getting displayed in the message "Failed to save the analytics rule query. Log Analytics workspace 'xxx' could not be found."

Please do correct me if this is not the case by responding in the comments section.

As per Remove Microsoft Sentinel from your workspace It can take up to 48 hours for Microsoft Sentinel to be removed from the Log Analytics workspace. Data connector configuration and Microsoft Sentinel tables are deleted. Other resources and data are retained for a limited time and this limited period could be upto 30 days.

User's image

Your subscription continues to be registered with the Microsoft Sentinel resource provider. But, you can remove it manually.

The recommendation here would be to have a workspace with different name.

If you don't have any further queries and the suggestion works as per your business need. Please "Accept the answer (Yes)" and "share your feedback ". This will help us and others in the community as well.

Thanks,

Akshay Kaushik

Was this answer helpful?

1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.