Apr 07 2020
- last edited on
Apr 08 2022
Guys, is their a delay/latency in say the export of sign-in logs from AzureAD into a log analytics workspace? My security team have asked for real-time alerts on certain account sign ins. Should I look at Event hubs?
Apr 08 2020 01:57 AM
This lists the latency details.
You can measure it with the queries in the link or via my Usage Workbook, which has a whole Tab (page) for latency https://techcommunity.microsoft.com/t5/azure-sentinel/usage-reporting-for-azure-sentinel/ba-p/126738...
Other solutions may decrease latency, but you need to weigh that against complexity and costs etc...