March 30, 2026—Microsoft Defender for Endpoint Log Collection version 1.0.74 introduces
a redesigned ingestion architecture that improves performance and supports larger
log entries.
ImportantThis release includes a breaking change. The Table Storage ingestion pipeline has
been removed and replaced with an event-driven Blob Storage pipeline. Existing data
in Table Storage will not be carried over to the new architecture. This is by design,
as TrendAI Vision One™ focuses on real-time threat alerting rather than historical log retention.
|
-
Cloud platform: Azure
-
Release date: March 30, 2026
-
Deployment method: Terraform
-
Enhancements:
-
Redesigned ingestion architecture from Table Storage to an event-driven Blob Storage pipeline, improving scalability and reliability.
-
Increased support for log entries larger than 64 KB, enabling processing of more comprehensive security event data.
-
-
Breaking change:
-
The Table Storage ingestion pipeline has been completely removed. Existing data stored in Table Storage will not be migrated to the new Blob Storage architecture.
-
