Forum Discussion
CyrilChu
Jun 06, 2022Copper Contributor
Pricing Calculator for Microsoft Sentinel
Hi everyone, I am using the Pricing Calculator for Microsoft Sentinel. I can see the pricing split into two parts - Azure Monitor and Microsoft Sentinel. In my understanding, Microsoft Sentinel wil...
- Jun 06, 2022
Hello CyrilChu,
The pricing is split into two parts - Azure Monitor and Microsoft Sentinel because:
Azure Monitor is considered to be the "Ingestion" part (GB of logs that are ingested into Log Analytics Workspace) and Microsoft Sentinel is the SIEM system itself that operates logs, queries, workbooks, connectors etc.
CyrilChu
Jun 06, 2022Copper Contributor
Hello mikhailf,
Can I simply understand it as Azure Monitor = Log Analytics Workspace (log data storage)?
Can I simply understand it as Azure Monitor = Log Analytics Workspace (log data storage)?
mikhailf
Jun 06, 2022Steel Contributor
I understand it like this: Azure Monitor = Log Analytics Workspace (log data ingestion).
Not storage. For Storage, Microsoft has another part in its calculator 🙂
- CyrilChuJun 06, 2022Copper Contributormikhailf
Thanks a lot, I have one more question.
If I use Microsoft lighthouse to share the resource group (Microsoft Sentinel and Log Analytics Workspace) with another tenant, will it charge two Sentinel costs?- shanksrainaDec 13, 2022Copper ContributorAzure Lighthouse does not incur any charges, it is just used to view multiple resources in a single pane of glass.
- mikhailfJun 06, 2022Steel ContributorAs far as I know, if you have 2 subscriptions and 2 Sentinels and use LightHouse to connect one Sentinel to another, you will still have to pay for both of them.
Because these are two separate Sentinels.
For example, you are a SOC company and have a customer who has Sentinel. And you want to connect your customer's Sentinel to your to see and manage data in your own system. The customer will have to pay for his Sentinel.- CyrilChuJun 07, 2022Copper Contributormikhailf,
I am not sure it have 2 Sentinels, the current situation is Customer Company use belows link to share his Resource group (Include Log Analytics Workspace and Already add Microsoft Sentinel to the workspace) to SOC Company.
https://github.com/Azure/Azure-Lighthouse-samples
As far as I know, we need to add Microsoft Sentinel to a workspace after you create a Log Analytics Workspace. SOC Company itself did not add Microsoft Sentinel to any workspaces before. SOC Company can connect to customer's Sentinel via lighthouse directly. We don't need to add Microsoft Sentinel to customer's workspace.
For this situation, it still count as two separate Sentinels?