Aug 09 2022 11:35 PM
Hi,
I landed up in the situation where I need to set up azure sentinel for my organization. I have to collect logs from all the resources and push it into azure sentinel.
here is the hurdles
there are tons of data and if I push all of it in azure sentinel it will cost me huge amount. that is why I have to make some queries so that I can take limit amount of data(based on queries) which I can use in azure sentinel.
I have gone through multiple article but unable to find which is best in this situation.
what I am thinking, all data push to event hub then through event hub it will push to azure data explorer here i will create queries to take limited amount of data then that data I will push to azure sentinel, kindle let me know if something needs to improve or if you have better solution.
Thanks
Aug 10 2022 01:19 AM
Hello @Gyaneshwar28,
Look at Custom data ingestion and transformation in Microsoft Sentinel (preview) | Microsoft Docs.
It is still in preview mode, but I am sure it can help you to filter the incoming logs.
Aug 10 2022 01:29 AM