An Azure data analytics service for real-time analysis on large volumes of data streaming from sources including applications, websites, and internet of things devices.
Hello Janel Cabile
The 10‑azuremonitoragent‑omfwd.conf file controls the rsyslog forwarding queue, not the Azure Monitor Agent’s own internal spool. While rsyslog can be configured to buffer more data on disk, AMA itself maintains a separate, internal offline buffer (under /var/lib/azuremonitoragent) whose size is not configurable.
Values such as “10 GB” referenced in rsyslog configs do not represent a supported or guaranteed AMA retention limit.
References:
Syslog & CEF ingestion using AMA https://learn.microsoft.com/azure/sentinel/connect-cef-syslog-ama
AMA Linux troubleshooting (rsyslog focus) Troubleshoot syslog issues with Azure Monitor Agent on Linux - Azure Monitor | Microsoft Learn
CEF & Syslog AMA troubleshooting Troubleshoot CEF and Syslog via AMA connectors in Microsoft Sentinel | Microsoft Learn