Forum Discussion

FahadAhmed's avatar
FahadAhmed
Brass Contributor
Jul 28, 2023

Best practice to deal with Excessive Logoff and Logon events

Hi,

Currently we are facing a situation where there are excessive Logon and Logoff events in Microsoft sentinel in the SecurityEvent table, causing high monthly costs.

 

Can you please let me know whats the best practice to deal with them, we dont want to drop them entirely as they may be used in Analytical rules or are required for forensics. 

 

Another option that I saw was to use API tranformation to split the logs and store analytica data in analytical table and forward the other data to basic table. First, if I send the data directly to basic table then it wont be used in Analytical rules (Correct me if I am wrong?). Secondly, I dont know if we can do this through DCR, since I dont know where and how to run that API transformation.

 

Any help will be appreciated.

 

Thanks

Resources