Oct 28 2020 02:07 AM
Hello!
I have been trying to find out an approximate overview for pricing for different connectors in Sentinel(if they are free, discounted, if the use a lot of data or not).
My organization has also requested i find out pricing for this connector
Seeing as this is raw data i suspect it is going to generate a lot of data making it expensive, however this is data that has already been "generated" and as far as i have understood sentinel doesn't duplicate data, making this connector almost free(?)
Any clarification is much appreciated
Oct 28 2020 03:45 AM
There are a few lists like this one, to see which primary tables are free or billable (after Ingestion you can confirm with my Workbook or KQL https://docs.microsoft.com/en-us/azure/azure-monitor/platform/manage-cost-storage).
"If they use a lot of data or not" - is a 'it depends' answer, Azure Sentinel is based on "Azure Sentinel is billed based on the volume of data ingested for analysis in Azure Sentinel and stored in the Azure Monitor Log Analytics workspace. "
Source: https://azure.microsoft.com/en-us/pricing/details/azure-sentinel/
Your usage pattern maybe very different from others. I saw this recently with a company with a single firewall that was sending the same data volume as a customer with ~60 of the same appliances.