You had most of it, you just needed _BilledSize e.g.
SecurityEvent
| where TimeGenerated > ago(4h)
| where EventID == "4688"
| summarize bytes_=sum(_BilledSize), GBytes=sum(_BilledSize)/(1024*1024*1024)
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
In azure sentinel I can calculate data ingestion for whole table but is there any way through which I can calculate specific size of data.
Ex : In azure table how much data ingested in last 1 hour.
Something like
Search criteria & then calculation of displayed data in terms of ingestion.
You had most of it, you just needed _BilledSize e.g.
SecurityEvent
| where TimeGenerated > ago(4h)
| where EventID == "4688"
| summarize bytes_=sum(_BilledSize), GBytes=sum(_BilledSize)/(1024*1024*1024)
@94554605 Thank you for reaching out to us, As I understand you are looking for data ingestion for Specific data/ specific time period data in table.
As far i am aware this can achieved by KQL using ingestion_time() and Timegenerated function.
Came across this query (not tested) see if this helps
SecurityEvent
| where TimeGenerated >= ago(1h) // Filter events from the last hour
| extend IngestionDelay = ingestion_time() - TimeGenerated // Calculate ingestion delay
| summarize TotalEvents = count() by TableName, IngestionDelay // Count events per table and delay
| project TableName, TotalEvents, IngestionDelay
Let me know if you have any further questions, feel free to post back.