A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Hi, I suspect this is an edge case. You do get 90days included with Sentinel, so you'd always set workspace retention to 90days (not 60d).
I suspect this error is more aligned to Azure Monitor/Log Analytics usage and the 30days that's included there (without Microsoft Sentinel being assigned to the Workspace).
I've seen many not set the workspace retention to 90d, and then forget to make the individual table retention changes (often found after an incident, where that data could have been crucial) - so I'd advise workspace to 90days and then at least you get 90days for existing and future Tables that are added. Then adjust specific Tables after that.