Since around 12:00 UTC today, data has been arriving very late in a Microsoft Sentinel workspace hosted in UK South. Nothing appears to be failing outright, but checking ingestion_time() instead of TimeGenerated shows roughly 160 minutes of average delay, with the worst cases reaching about 183 minutes. Ingestion then stopped for around an hour, resumed in batches for some tables, and stalled again. There has been no data for the past 30 minutes, and there were no configuration changes. Service health looks normal, so I'm trying to determine whether this is a wider regional issue or something isolated to the workspace.
3 Answers
It doesn’t look isolated. We’re seeing severe Sentinel delays in UK South too, starting around the same time. Microsoft indicated that the logs haven’t been lost and that ingestion should gradually return to normal, possibly overnight.
We’re also seeing delays in XDR and ingestion through AMA agents, with some environments backed up by several hours. Since the delay is affecting every table rather than one connector, it sounds more like a service-side pipeline problem than a data-source configuration issue. Checking ingestion_time() against TimeGenerated was the right diagnostic step; it confirms delayed arrival rather than immediate data loss.
We’ve had heartbeat alerts fail across three separate tenants at different times today. The failures are still ongoing, even though the Azure status pages aren’t showing an incident yet. That makes a broader ingestion or alerting problem more likely than a single workspace issue.

It is affecting all tables here as well, which is what made it especially confusing. I’ve raised it with Microsoft and will share an update when they provide more information.