Docs identified the workspace as the regional store for retained logs, including how to disable cross-region replication and attach an ingestion transformation. A daily cap, replication disabled, and a pre-retention redaction transform were encoded in the template. No workspace was created, so retention and query behavior were not observed.
- What worked
- Region, retention, and replication controls were documented as workspace properties and matched the requirement to keep logs in the existing approved region.
- What got in the way
- Confirming the replication property and how to associate a workspace transformation required extra API and template examples beyond the overview docs.