%3CLINGO-SUB%20id%3D%22lingo-sub-2072539%22%20slang%3D%22en-US%22%3EWhat%E2%80%99s%20new%3A%20Dedicated%20clusters%20for%20Azure%20Sentinel%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2072539%22%20slang%3D%22en-US%22%3E%3CP%3EIf%20you%20ingest%20over%201Tb%20per%20day%20into%20your%20Azure%20Sentinel%20workspace%20and%2For%20have%20multiple%20Azure%20Sentinel%20workspaces%20in%20your%20Azure%20enrolment%2C%20you%20may%20want%20to%20consider%20migrating%20to%20a%20dedicated%20cluster%2C%20a%20recent%20addition%20to%20the%20deployment%20options%20for%20Azure%20Sentinel.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CFONT%20color%3D%22%23FF0000%22%3ENOTE%3A%20Although%20this%20blog%20refers%20to%20a%20%E2%80%9Cdedicated%20cluster%20for%20Azure%20Sentinel%E2%80%9D%2C%20the%20dedicated%20cluster%20being%20referred%20to%20is%20for%20Log%20Analytics%2C%20the%20underlying%20data%20store%20for%20Azure%20Sentinel.%20You%20may%20find%20that%20linked%20official%20documents%20refer%20to%20Azure%20Monitor%3B%20Log%20Analytics%20is%20part%20of%20the%20wider%20Azure%20Monitor%20platform.%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId--551062693%22%20id%3D%22toc-hId--551062688%22%3E%3CSTRONG%3EOverview%3C%2FSTRONG%3E%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EA%20dedicated%20cluster%20in%20Azure%20Sentinel%20does%20exactly%20what%20it%20says%3A%20you%20are%20given%20dedicated%20hardware%20in%20an%20Azure%20data%20center%20to%20run%20your%20Azure%20Sentinel%20instance.%20This%20enables%20several%20scenarios%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CSTRONG%3ECustomer-managed%20Keys%3C%2FSTRONG%3E%20-%20Encrypt%20the%20cluster%20data%20using%20keys%20that%20are%20provided%20and%20controlled%20by%20the%20customer.%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3ELockbox%3C%2FSTRONG%3E%20-%20Customers%20can%20control%20Microsoft%20support%20engineers%20access%20requests%20for%20data.%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3EDouble%20encryption%3C%2FSTRONG%3E%20protects%20against%20a%20scenario%20where%20one%20of%20the%20encryption%20algorithms%20or%20keys%20may%20be%20compromised.%20In%20this%20case%2C%20the%20additional%20layer%20of%20encryption%20continues%20to%20protect%20your%20data.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAdditionally%2C%20multiple%20Azure%20Sentinel%20workspaces%20can%20be%20added%20to%20a%20dedicated%20cluster.%20There%20are%20several%20advantages%20to%20using%20a%20dedicated%20cluster%20from%20a%20Sentinel%20perspective%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3ECross-workspace%20queries%20will%20run%20faster%20if%20all%20the%20workspaces%20involved%20in%20the%20query%20are%20added%20to%20the%20dedicated%20cluster.%20%3CSTRONG%3E%3CEM%3ENB%3A%20It%20is%20still%20recommended%20to%20have%20as%20few%20workspaces%20as%20possible%20in%20your%20environment.%26nbsp%3B%3C%2FEM%3E%3C%2FSTRONG%3E%3CEM%3EA%20dedicated%20cluster%20still%20retains%20the%20%3C%2FEM%3E%3CEM%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Flog-query%2Fcross-workspace-query%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Elimit%20of%20100%20workspaces%3C%2FA%3E%26nbsp%3Bthat%20can%20be%20included%20in%20a%20single%20cross-workspace%20query.%26nbsp%3B%3C%2FEM%3E%3C%2FLI%3E%0A%3CLI%3EAll%20workspaces%20on%20the%20dedicated%20cluster%20share%20the%20Log%20Analytics%20capacity%20reservation%20set%20on%20the%20cluster%20(not%20the%20Sentinel%20capacity%20reservation)%2C%20rather%20than%20having%20to%20have%20one%20Log%20Analytics%20capacity%20reservation%20per%20workspace%20which%20can%20allow%20for%20cost%20savings%20and%20efficiencies.%20%3CSTRONG%3E%3CEM%3ENB%3A%20By%20enabling%20a%20dedicated%20cluster%20you%20commit%20to%20a%20minimum%20capacity%20reservation%20in%20Log%20Analytics%20of%201Tb%20per%20day%20ingestion.%3C%2FEM%3E%3C%2FSTRONG%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%222021-01-19_11-58-24.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F247350iF7694EB0B0637E05%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%222021-01-19_11-58-24.png%22%20alt%3D%222021-01-19_11-58-24.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-1936450140%22%20id%3D%22toc-hId-1936450145%22%3E%26nbsp%3B%3C%2FH2%3E%0A%3CH2%20id%3D%22toc-hId-128995677%22%20id%3D%22toc-hId-128995682%22%3E%3CSTRONG%3ECon%3C%2FSTRONG%3E%3CSTRONG%3Esidering%20migrating%20to%20a%20dedicated%20cluster%3F%3C%2FSTRONG%3E%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThere%20are%20some%20considerations%20and%20limitations%20for%20using%20dedicated%20clusters%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CP%3EThe%20max%20number%20of%20clusters%20per%20region%20and%20subscription%20is%202.%3C%2FP%3E%0A%3C%2FLI%3E%0A%3CLI%3EAll%20workspaces%20linked%20to%20a%20cluster%20must%20be%20in%20the%20same%20region.%3C%2FLI%3E%0A%3CLI%3E%3CP%3EThe%20maximum%20of%20linked%20workspaces%20to%20cluster%20is%201000.%3C%2FP%3E%0A%3C%2FLI%3E%0A%3CLI%3E%3CP%3EYou%20can%20link%20a%20workspace%20to%20your%20cluster%20and%20then%20unlink%20it.%20The%20number%20of%20workspace%20link%20operations%20on%20particular%20workspace%20is%20limited%20to%202%20in%20a%20period%20of%2030%20days.%3C%2FP%3E%0A%3C%2FLI%3E%0A%3CLI%3EYou%20cannot%20move%20an%20existing%20workspace%20to%20a%20CMK%20cluster.%20You%20need%20to%20create%20it%20in%20the%20cluster.%3C%2FLI%3E%0A%3CLI%3E%3CP%3ECluster%20move%20to%20another%20resource%20group%20or%20subscription%20isn't%20supported%20at%20the%20time%20of%20writing%20this%20article.%3C%2FP%3E%0A%3C%2FLI%3E%0A%3CLI%3E%3CP%3EWorkspace%20link%20to%20cluster%20will%20fail%20if%20it%20is%20linked%20to%20another%20cluster.%3C%2FP%3E%0A%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20great%20news%20is%20that%20you%20can%20retrospectively%20migrate%20to%20a%20dedicated%20cluster%2C%20so%20if%20this%20feature%20looks%20like%20it%20would%20be%20useful%20to%20your%20organization%2C%20you%20can%20find%20more%20information%20and%20migration%20steps%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Flog-query%2Flogs-dedicated-clusters%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehere%3C%2FA%3E.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CEM%3EWith%20thanks%20to%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F293879%22%20target%3D%22_blank%22%3E%40Ofer_Shezaf%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F66621%22%20target%3D%22_blank%22%3E%40Javier%20Soriano%3C%2FA%3E%26nbsp%3Band%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F84435%22%20target%3D%22_blank%22%3E%40Meir%20Mendelovich%3C%2FA%3E%26nbsp%3Bfor%20their%20input%20into%20this%20blog%20post.%3C%2FEM%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-2072539%22%20slang%3D%22en-US%22%3E%3CP%3EIf%20you%20ingest%20over%201Tb%20per%20day%20into%20your%20Azure%20Sentinel%20workspace%20and%2For%20have%20multiple%20Azure%20Sentinel%20workspaces%20in%20your%20Azure%20enrolment%2C%20you%20may%20want%20to%20consider%20migrating%20to%20a%20dedicated%20cluster%2C%20a%20recent%20addition%20to%20the%20deployment%20options%20for%20Azure%20Sentinel.%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2072539%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20Sentinel%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EDetection%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EHunting%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EInvestigation%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Esecurity%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWhat's%20new%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Microsoft

If you ingest over 1Tb per day into your Azure Sentinel workspace and/or have multiple Azure Sentinel workspaces in your Azure enrolment, you may want to consider migrating to a dedicated cluster, a recent addition to the deployment options for Azure Sentinel.

 

NOTE: Although this blog refers to a “dedicated cluster for Azure Sentinel”, the dedicated cluster being referred to is for Log Analytics, the underlying data store for Azure Sentinel. You may find that linked official documents refer to Azure Monitor; Log Analytics is part of the wider Azure Monitor platform.

 

Overview

 

A dedicated cluster in Azure Sentinel does exactly what it says: you are given dedicated hardware in an Azure data center to run your Azure Sentinel instance. This enables several scenarios:

 

  • Customer-managed Keys - Encrypt the cluster data using keys that are provided and controlled by the customer.
  • Lockbox - Customers can control Microsoft support engineers access requests for data.
  • Double encryption protects against a scenario where one of the encryption algorithms or keys may be compromised. In this case, the additional layer of encryption continues to protect your data.

 

Additionally, multiple Azure Sentinel workspaces can be added to a dedicated cluster. There are several advantages to using a dedicated cluster from a Sentinel perspective:

 

  • Cross-workspace queries will run faster if all the workspaces involved in the query are added to the dedicated cluster. NB: It is still recommended to have as few workspaces as possible in your environment. A dedicated cluster still retains the limit of 100 workspaces that can be included in a single cross-workspace query. 
  • All workspaces on the dedicated cluster share the Log Analytics capacity reservation set on the cluster (not the Sentinel capacity reservation), rather than having to have one Log Analytics capacity reservation per workspace which can allow for cost savings and efficiencies. NB: By enabling a dedicated cluster you commit to a minimum capacity reservation in Log Analytics of 1Tb per day ingestion.

 

2021-01-19_11-58-24.png

 

 

Considering migrating to a dedicated cluster?

 

There are some considerations and limitations for using dedicated clusters:

 

  • The max number of clusters per region and subscription is 2.

  • All workspaces linked to a cluster must be in the same region.
  • The maximum of linked workspaces to cluster is 1000.

  • You can link a workspace to your cluster and then unlink it. The number of workspace link operations on particular workspace is limited to 2 in a period of 30 days.

  • You cannot move an existing workspace to a CMK cluster. You need to create it in the cluster.
  • Cluster move to another resource group or subscription isn't supported at the time of writing this article.

  • Workspace link to cluster will fail if it is linked to another cluster.

 

The great news is that you can retrospectively migrate to a dedicated cluster, so if this feature looks like it would be useful to your organization, you can find more information and migration steps here

 

 

With thanks to @Ofer_Shezaf@Javier Soriano and @Meir Mendelovich for their input into this blog post.