Since around 12:00 UTC today, data has been arriving very late in a Microsoft Sentinel workspace hosted in UK South. Nothing appears to be failing outright, but checking with `ingestion_time()` instead of `TimeGenerated` shows roughly 160 minutes of average delay, with the worst cases reaching about 183 minutes. Ingestion then stopped for around an hour, briefly resumed for some tables, and stalled again. The issue appears to affect all tables, with no recent configuration changes and no obvious problems reported in the workspace health checks. Is anyone else seeing similar Sentinel or AMA ingestion delays?
4 Answers
I’ve had heartbeat alerts fail across three separate tenants at different times today. They’re still failing, even though nothing obvious is showing in the Azure status information.
This doesn’t seem isolated to one workspace. Other administrators are reporting ingestion problems across multiple customers, including delays involving AMA-based collection. XDR data is also arriving several hours late in some cases.
We’re seeing the same thing in UK South. Sentinel ingestion has been delayed since roughly 15:30, but Microsoft indicated that the data hasn’t been lost and should catch up overnight.
The `ingestion_time()` versus `TimeGenerated` comparison is the right way to confirm whether this is latency rather than data loss. The Workspace Usage Report may help identify whether one connector or data type is backing up, although reports of every table being affected point more toward a broader service-side issue.

It’s affecting all tables in this workspace, not just one connector. I’ve raised it with Microsoft and will share an update when they provide more information.