Sentinel Cost Estimation

%3CLINGO-SUB%20id%3D%22lingo-sub-1582359%22%20slang%3D%22en-US%22%3ESentinel%20Cost%20Estimation%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1582359%22%20slang%3D%22en-US%22%3E%3CP%3EGood%20evening%20community%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20need%20some%20help%20understanding%20the%20costing%20for%20Sentinel.%20I'm%20trying%20to%20build%20a%20case%20for%20Sentinel%20as%20a%20compete%20to%20an%20existing%20solution.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20environment%20has%20around%201000%20server%2C%20400%20endpoints%2C%20and%2050%20network%20devices.%3C%2FP%3E%3CP%3EThey%20have%20a%20big%20investment%20in%20Microsoft%20security%20services%20(ATA%2C%20ATP%2C%20Defender%2C%20MDM%2C%20etc.)%20with%20O365%20E5.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBut%20I%20digress...%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAm%20I%20correct%20that%20they%20will%20not%20be%20charged%20for%20any%20log%20ingestion%20from%20ATP%2C%20ASC%2C%20O365%2C%20and%20MCAS%20into%20Sentinel%20when%20connecting%20to%20these%20sources%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20will%20they%20be%20charged%20for%20then%3F%20Only%20the%20storage%20costs%20associated%20with%20the%20Log%20Analytics%20workspace%3F%20When%20doing%20the%20costing%2C%20do%20I%20include%20only%20those%20sources%20not%20explicitly%20mentioned%20as%20free%20connectors%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1582405%22%20slang%3D%22en-US%22%3ERe%3A%20Sentinel%20Cost%20Estimation%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1582405%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F513150%22%20target%3D%22_blank%22%3E%40SebastiaanR%3C%2FA%3E%26nbsp%3BYou%20will%20not%20get%20charged%20for%20O365%20data%20and%20the%20ALERTS%20coming%20from%20the%20other%20Azure%20security%20products%2C%20like%20MCAS%20and%20ATP%2C%20and%20the%20Azure%20Activity%20logs.%26nbsp%3B%20Go%20to%20this%20page%20and%20at%20the%20bottom%20of%20the%20page%20is%20a%20FAQ%20that%20lists%20this%20out.%26nbsp%3B%20Also%2C%20note%20that%20the%20total%20cost%20for%20Azure%20Sentinel%20is%3A%3C%2FP%3E%3CP%3E1)%20Azure%20Sentinel%20ingestion%20(which%20the%20URL%20below%20is%20for)%3C%2FP%3E%3CP%3E2)%20Log%20Analytics%20ingestion%3C%2FP%3E%3CP%3E3)%20Data%20retention%20after%2090%20days%20(first%2090%20days%20is%20free%20no%20matter%20where%20the%20data%20come%20from)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E-ERR%3AREF-NOT-FOUND-%3CA%20href%3D%22https%3A%2F%2Fazure.microsoft.com%2Fen-us%2Fpricing%2Fdetails%2Fazure-sentinel%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fazure.microsoft.com%2Fen-us%2Fpricing%2Fdetails%2Fazure-sentinel%2F%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYou%20can%20also%20go%20to%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fsiemsizingcalculator.logpoint.com%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsiemsizingcalculator.logpoint.com%2F%3C%2FA%3E%26nbsp%3Bto%20get%20an%20idea%20of%20how%20much%20data%20you%20will%20be%20ingesting%20from%20your%20environment.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1582505%22%20slang%3D%22en-US%22%3ERe%3A%20Sentinel%20Cost%20Estimation%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1582505%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F513150%22%20target%3D%22_blank%22%3E%40SebastiaanR%3C%2FA%3E%26nbsp%3B%20to%20add%20to%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F46875%22%20target%3D%22_blank%22%3E%40Gary%20Bushey%3C%2FA%3E%20points%2C%20you%20can%20use%20this%20workbook%20if%20you%20choose%20take%20Sentinel%20for%20a%20test%20drive%2C%20this%20will%20give%20you%20an%20insight%20on%20the%20volume%20of%20logs%20you%20are%20receiving%2C%20pricing%20and%20other%20useful%20things.%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fusage-reporting-for-azure-sentinel%2Fba-p%2F1267383%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fusage-reporting-for-azure-sentinel%2Fba-p%2F1267383%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%20are%20interested%20in%20some%20more%20info%20drop%20me%20a%20line%2C%20I've%20deployed%20a%20few%20Sentinel%20solutions.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EKind%20regards%3C%2FP%3E%3CP%3EDiego%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1582587%22%20slang%3D%22en-US%22%3ERe%3A%20Sentinel%20Cost%20Estimation%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1582587%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F46875%22%20target%3D%22_blank%22%3E%40Gary%20Bushey%3C%2FA%3E%26nbsp%3B.%20I%20actually%20used%20that%20to%20determine%20the%20log%20sizes%20earlier%20today%2C%20thanks%20%3A)%3C%2Fimg%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3CP%3EPardon%20my%20ignorance%2C%3CBR%20%2F%3E%3CBR%20%2F%3ELet's%20assume%20I%20have%20my%20LA%20workspace%20with%20Sentinel%20on%20top%20of%20it.%20I%20have%20a%20server%20connected%20to%20this%20same%20workspace%20generating%2050GB%20of%20logs%20per%20month.%20The%20same%20workspace%20is%20covered%20under%20Azure%20Security%20Center%20standard%20and%20as%20such%20this%20server%20is%20covered%20by%20Defender%20ATP.%3C%2FP%3E%3CP%3EAm%20I%20correct%20that%20Sentinel%20still%20sees%20the%2050GB%20as%20ingested%20log%20volumes%2C%20and%20that%20is%20what%20will%20be%20counted%20against%20the%20consumption%3F%3CBR%20%2F%3E%3CBR%20%2F%3EThanks%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1582789%22%20slang%3D%22en-US%22%3ERe%3A%20Sentinel%20Cost%20Estimation%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1582789%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F513150%22%20target%3D%22_blank%22%3E%40SebastiaanR%3C%2FA%3E%26nbsp%3BThat%20is%20correct.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1592539%22%20slang%3D%22en-US%22%3ERe%3A%20Sentinel%20Cost%20Estimation%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1592539%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F46875%22%20target%3D%22_blank%22%3E%40Gary%20Bushey%3C%2FA%3E%26nbsp%3B%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F513150%22%20target%3D%22_blank%22%3E%40SebastiaanR%3C%2FA%3E%26nbsp%3B%3A%20To%20clarify%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E-%20The%20free%20sources%20Gary%20mentions%20above%20are%20free%20for%20both%20the%20Sentinel%20cost%20and%20the%20Log%20Analytics%20ingestion%20cost.%20Only%20Log%20Analytics%20retention%20beyond%2090%20days%20is%20charged.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E-%20The%20500MB%2Fd%20free%20consumption%20allocation%20for%20Security%20Events%20for%20systems%20licensed%20for%20ASC%20standard%20applies%20but%20only%20to%20the%20Log%20Anaytics%20ingestion%20cost%20and%20not%20to%20the%20Sentinel%20cost.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

Good evening community,

 

I need some help understanding the costing for Sentinel. I'm trying to build a case for Sentinel as a compete to an existing solution.

 

The environment has around 1000 server, 400 endpoints, and 50 network devices.

They have a big investment in Microsoft security services (ATA, ATP, Defender, MDM, etc.) with O365 E5.

 

But I digress...

 

Am I correct that they will not be charged for any log ingestion from ATP, ASC, O365, and MCAS into Sentinel when connecting to these sources?

 

What will they be charged for then? Only the storage costs associated with the Log Analytics workspace? When doing the costing, do I include only those sources not explicitly mentioned as free connectors?

5 Replies

@SebastiaanR You will not get charged for O365 data and the ALERTS coming from the other Azure security products, like MCAS and ATP, and the Azure Activity logs.  Go to this page and at the bottom of the page is a FAQ that lists this out.  Also, note that the total cost for Azure Sentinel is:

1) Azure Sentinel ingestion (which the URL below is for)

2) Log Analytics ingestion

3) Data retention after 90 days (first 90 days is free no matter where the data come from)

 

https://azure.microsoft.com/en-us/pricing/details/azure-sentinel/

 

You can also go to https://siemsizingcalculator.logpoint.com/ to get an idea of how much data you will be ingesting from your environment.

Hi @SebastiaanR  to add to @Gary Bushey points, you can use this workbook if you choose take Sentinel for a test drive, this will give you an insight on the volume of logs you are receiving, pricing and other useful things.

https://techcommunity.microsoft.com/t5/azure-sentinel/usage-reporting-for-azure-sentinel/ba-p/126738...

 

If you are interested in some more info drop me a line, I've deployed a few Sentinel solutions.

 

Kind regards

Diego

Thanks @Gary Bushey . I actually used that to determine the log sizes earlier today, thanks :)

Pardon my ignorance,

Let's assume I have my LA workspace with Sentinel on top of it. I have a server connected to this same workspace generating 50GB of logs per month. The same workspace is covered under Azure Security Center standard and as such this server is covered by Defender ATP.

Am I correct that Sentinel still sees the 50GB as ingested log volumes, and that is what will be counted against the consumption?

Thanks

 

 

 

 

 

@SebastiaanR That is correct.  

@Gary Bushey , @SebastiaanR : To clarify:

 

- The free sources Gary mentions above are free for both the Sentinel cost and the Log Analytics ingestion cost. Only Log Analytics retention beyond 90 days is charged.

 

- The 500MB/d free consumption allocation for Security Events for systems licensed for ASC standard applies but only to the Log Anaytics ingestion cost and not to the Sentinel cost.