Case Study: Finding the Logging Pattern Behind Rising Azure Cost

At a glance

  • Client type: Enterprise Azure environment
  • Problem: Cloud cost was increasing and the cause was not clear from the top-level bill.
  • Finding: Approximately 80% of the cost issue traced back to logging and telemetry design.
  • Outcome: Five-figure annual saving opportunity identified with practical remediation options.
  • Related service: Cloud cost optimisation / FinOps

Problem

An enterprise Azure environment had rising monthly cost across a mix of application and platform services. The first view of the bill showed spend spread across API management, app hosting, functions, messaging, private endpoints, firewall, and Log Analytics.

That made the problem look broad. In practice, the cost was being amplified by how telemetry was collected, retained, and routed.

Context

A large government agency was delivering a complex Azure-based integration solution under tight timelines.

The environment supported real workloads, so the answer could not be a blunt reduction in monitoring. Logging was needed for support, operations, and security visibility.

The issue was that the volume and retention pattern did not match the actual value of the data being kept. Without resource-level and service-level analysis, the organisation could keep optimising around the edges while missing the main driver.

That decision made sense during active investigation. The problem was that the logging was not reviewed or reduced after the issue was resolved.

This is a common cloud delivery issue. During project pressure, teams enable additional diagnostics to solve immediate problems. That is often necessary. But without a clear process to review and reset logging afterwards, temporary troubleshooting settings can become permanent cost waste.

What was accomplished

Our team reviewed the cost composition, checked the services contributing to the increase, and narrowed the pattern to telemetry volume and retention behaviour.

AreaWhat we checked
Service mixCompared spend across API management, app hosting, functions, messaging, private endpoints, firewall, and Log Analytics.
Logging volumeChecked which components were generating the highest telemetry volume.
RetentionReviewed whether retained logs still supported a real operational, security, or compliance requirement.
Usage patternSeparated normal workload cost from monitoring cost created by the workload.
RemediationProvided practical changes that reduced unnecessary spend without removing useful visibility.

Key decisions and trade-offs

The trade-off was visibility versus cost. Removing logs would have reduced spend quickly, but it could have created operational risk. Keeping every log at the same level and retention period was also not sensible.

The better approach was to tune what was collected, where it was sent, and how long it was kept.

Result

The analysis showed that approximately 80% of the cost issue was linked to logging and telemetry design. That gave the organisation a clear remediation path and a five-figure annual saving opportunity.

More importantly, it changed the discussion from general cloud cost pressure to a specific engineering decision: keep useful logs, remove low-value noise, and set retention based on real need.

The biggest value was not just the saving. It was proving that the cost was not an unavoidable business expense. It was a configuration and governance issue that could be corrected.

Conclusion

Logging is useful. Unchecked logging can quietly become one of the most expensive parts of a workload.

When a solution is complex, it is easy for high costs to be accepted as normal. This is especially true when third-party teams, delivery partners, or contractors are involved and the internal team does not have full visibility into every configuration decision.

A practical Azure cost optimisation review should look beyond the headline service cost and check the telemetry pattern behind it.

Book a discovery call

If anything sounds familiar, book a quick call and have a chat with one of our FinOps-certified senior consultants and subject matter experts with 20+ years of IT experience.

This is a space where you will not hit first-line support or people without relevant enterprise experience.

Save time in the process of saving money.