Forum Discussion
Daily quota for Sentinel
- Feb 07, 2022
You wouldn't want to be in a situation where you stopped logging during an attack, so whilst cost is a consideration, coverage is as well. The text above is correct, key sources will ignore the daily cap.
You can of course Alert when you are near the cap and then make a more informed decision to tune or switch off a data connector e.g. https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/ingestion-cost-spike-detection-playbook/ba-p/2591301
See the link (and warning box) here for more details:
Manage usage and costs for Azure Monitor Logs - Azure Monitor | Microsoft Docs
You wouldn't want to be in a situation where you stopped logging during an attack, so whilst cost is a consideration, coverage is as well. The text above is correct, key sources will ignore the daily cap.
You can of course Alert when you are near the cap and then make a more informed decision to tune or switch off a data connector e.g. https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/ingestion-cost-spike-detection-playbook/ba-p/2591301
See the link (and warning box) here for more details:
Manage usage and costs for Azure Monitor Logs - Azure Monitor | Microsoft Docs