Forum Discussion

abon13's avatar
abon13
Brass Contributor
Sep 13, 2024
Solved

MDE logs backup suggestions

Hi All,   Given MDE stores logs for 30 days only, I am in search of ideas on where to store these logs beyond 30 days. We do not want to export the logs to Sentinel due to cost factor. Thinking of ...
  • cyb3rmik3's avatar
    Sep 15, 2024

    Hey abon13,

     

    I think what you need to consider, is how you would you like to access the logs after 30 days. 

    1. You can indeed incorporate a Sentinel instance as mentioned by jbmartin6 and there you can take advantage of the free 90 days retention and add an archiving plan for as long as you want. This is probably the easiest way to deploy and the most flexible in terms of what you would like in hot and archived storage. It has the highest cost between all solutions.
    2. You can leverage Azure Event Hub to stream your data to ADX. While this would require some extra effort to deploy, is of medium cost and is very easy to access your data and perform queries. There is a detailed guide here.
    3. You can also stream your data to a storage account but while this is a simple to setup solution and very cheap, it is highly complex query the data stored. You can review the guide here.

     

    I hope the following information helps as well (as per my experience):

     

    Sentinel/Log Analytics Workspace

    Cost: High

    Setup: Very easy

    Data access: Easy (only because of the Searches in case you choose accessing archived data)

     

    Event Hub to ADX

    Cost: Medium

    Setup: Medium

    Data access: Very easy

     

    Event Hub to Storage Account

    Cost: Low

    Setup: Easy

    Data access: Very hard

     

    If I have answered your question, please mark your post as Solved

    If you like my response, please consider giving it a like

Resources