Home

Azure Sentinel pricing question for Azure and O365 sources

%3CLINGO-SUB%20id%3D%22lingo-sub-881813%22%20slang%3D%22en-US%22%3EAzure%20Sentinel%20pricing%20question%20for%20Azure%20and%20O365%20sources%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-881813%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20had%20a%20question%20on%20the%20Azure%20Sentinel%20pricing%20that%20was%20made%20available%20last%20week%20with%20the%20GA.%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fazure.microsoft.com%2Fen-au%2Fpricing%2Fdetails%2Fazure-sentinel%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fazure.microsoft.com%2Fen-au%2Fpricing%2Fdetails%2Fazure-sentinel%2F%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EQuestion%3C%2FSTRONG%3E%3CBR%20%2F%3EWhat%20data%20can%20be%20ingested%20at%20no%20cost%20with%20Azure%20Sentinel%3F%3CBR%20%2F%3E%3CSTRONG%3EAnswer%3C%2FSTRONG%3E%3CBR%20%2F%3EAzure%20Activity%20Logs%2C%20Office%20365%20Audit%20Logs%20and%20alerts%20from%20Microsoft%20Threat%20Protection%20are%20available%20for%20ingestion%20at%20no%20additional%20cost.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EJust%20to%20clarify%2C%20the%20cost%20here%20is%20the%20cost%20of%20ingestion%20in%20log%20analytics%3F%20There%20are%20still%20charges%20for%20-%3C%2FP%3E%3CUL%3E%3CLI%3EAnalysis%20of%20this%20data%20with%20Sentinel%3C%2FLI%3E%3CLI%3ERetention%20of%20these%20ingested%20logs%20beyond%20the%20first%2090%20days%3F%3C%2FLI%3E%3C%2FUL%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-881813%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ESentinel%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-884179%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20Sentinel%20pricing%20question%20for%20Azure%20and%20O365%20sources%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-884179%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F40513%22%20target%3D%22_blank%22%3E%40Sayan%20Ghosh%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ETo%20your%20second%20point%2C%20its%20just%20retention%20charge%20if%20you%20keep%20it%20more%20than%2090%20days.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-909490%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20Sentinel%20pricing%20question%20for%20Azure%20and%20O365%20sources%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-909490%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F2864%22%20target%3D%22_blank%22%3E%40Nicholas%20DiCola%20(SECURITY%20JEDI)%3C%2FA%3E%26nbsp%3BWhat%20about%20the%20first%20part%20of%20the%20question%3F%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20I%20have%201000GB%20of%20data%20being%20ingested%20daily%20with%20200GB%20of%20it%20being%20from%20O365%20am%20I%20paying%20for%3C%2FP%3E%3CP%3EA)%201000GB%20of%20data%20for%20Sentinel%20and%20800GB%20for%20Log%20Analytics%20Ingestion%3C%2FP%3E%3CP%3EB)%20800GB%20for%20Sentinel%20and%201000GB%20for%20Log%20Analytics%20Ingestion%3C%2FP%3E%3CP%3EC)%20800GB%20for%20Sentinel%20and%20800GB%20for%20Log%20Analytics%20Ingestion%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPlus%20the%201000GB%20data%20retention%20after%2090%20days%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-909541%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20Sentinel%20pricing%20question%20for%20Azure%20and%20O365%20sources%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-909541%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F46875%22%20target%3D%22_blank%22%3E%40Gary%20Bushey%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EOption%20C%20is%20your%20answer.%26nbsp%3B%20The%20free%20sources%20is%20for%20both%20LogA%20and%20Azure%20Sentinel.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFor%20retention%2C%20yes%20you%20would%20pay%201000GB.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-958056%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20Sentinel%20pricing%20question%20for%20Azure%20and%20O365%20sources%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-958056%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F40513%22%20target%3D%22_blank%22%3E%40Sayan%20Ghosh%3C%2FA%3E%26nbsp%3Bnot%20sure%20if%20you've%20seen%20this%3F%20Ideally%20you%20can%20set%20different%20retention%20depending%20on%20data%20type%3F%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3CP%3ENew%3A%20Per%20data%20type%20retention%20is%20now%20available%20for%20Azure%20Sentinel%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FAzure-Sentinel%2FNew-Per-data-type-retention-is-now-available-for-Azure-Sentinel%2Fba-p%2F917316%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FAzure-Sentinel%2FNew-Per-data-type-retention-is-now-available-for-Azure-Sentinel%2Fba-p%2F917316%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Sayan Ghosh
Occasional Contributor

We had a question on the Azure Sentinel pricing that was made available last week with the GA.

https://azure.microsoft.com/en-au/pricing/details/azure-sentinel/

 

Question
What data can be ingested at no cost with Azure Sentinel?
Answer
Azure Activity Logs, Office 365 Audit Logs and alerts from Microsoft Threat Protection are available for ingestion at no additional cost.

 

Just to clarify, the cost here is the cost of ingestion in log analytics? There are still charges for -

  • Analysis of this data with Sentinel
  • Retention of these ingested logs beyond the first 90 days?
4 Replies

@Sayan Ghosh 

 

To your second point, its just retention charge if you keep it more than 90 days.

@Nicholas DiCola (SECURITY JEDI) What about the first part of the question? 

If I have 1000GB of data being ingested daily with 200GB of it being from O365 am I paying for

A) 1000GB of data for Sentinel and 800GB for Log Analytics Ingestion

B) 800GB for Sentinel and 1000GB for Log Analytics Ingestion

C) 800GB for Sentinel and 800GB for Log Analytics Ingestion

 

Plus the 1000GB data retention after 90 days

@Gary Bushey 

Option C is your answer.  The free sources is for both LogA and Azure Sentinel. 

 

For retention, yes you would pay 1000GB.

@Sayan Ghosh not sure if you've seen this? Ideally you can set different retention depending on data type?

New: Per data type retention is now available for Azure Sentinel

https://techcommunity.microsoft.com/t5/Azure-Sentinel/New-Per-data-type-retention-is-now-available-f...

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
46 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
30 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies