Microsoft Defender for Cloud
Cloud and workloads

Use the data ingestion benefit in Microsoft Defender for Cloud

In brief

The documentation now links to the DeviceCustomFileEvents and DeviceCustomRegistryEvents Azure Monitor table references and includes updated authoring metadata.

What Defender admins need to know

Administrators can more easily find reference information for these tables when reviewing data ingestion documentation. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

title: Use the data ingestion benefit in Microsoft Defender for Cloud description: Defender for Servers Plan 2 includes 500 MB of free daily data ingestion per node to Log Analytics. Learn how the benefit is calculated and applied. ms.topic: how-to ms.custom: msecd-doc-authoring-1013 #customer intent: As a security admin, I want to understand how the data ingestion benefit is applied so that I can estimate eligible Log Analytics coverage and avoid unexpected charges. ms.date: 07/12/2026 ai-usage: ai-assisted