Oct 25 2022 08:41 AM
Hey all,
I currently have Sentinel and it's configured with data only stored in Log Analytics for 90 days. This has always been more than enough. However, I am now getting a new corporate directive to hold data for 1 year. I started researching the best methods and it appears I have 2 options - Azure Data Explorer or Archive. I know that ADX provides data querying ability where the Archive won't. So, in today's Sentinel, which of these is the preferred option?
TIA
~DGM~
Oct 26 2022 12:09 PM
Oct 27 2022 08:15 AM
@Clive_Watson Thank you for your response.
When you say that ADX has "ongoing management" requirements what do you mean?
Oct 27 2022 02:23 PM
Solution@DGMalcolm this isn't major, simply like many other Azure services you need to deploy it and run it. Unlike log analytics where Microsoft run the underlying service, with ADX you manage the cluster and also the Eventhub service that sends the data to ADX.
Oct 28 2022 06:28 AM