Forum Discussion
burasathi
May 31, 2023Copper Contributor
Sentinel log ingestion
Hello,
I have one question regarding log ingestion.
If we already have logs in the log analytic workspace and later if we enable sentinel in the same workspace, then will that sentinel be able to read those logs or do we need to ingest those logs again through sentinel data connectors?
Thank you
- cyb3rmik3Iron Contributor
- Clive_WatsonBronze ContributorLogs are only ingested once, Sentinel reads them, so they will be available to you *after* you enable Sentinel
- burasathiCopper ContributorClive_Watson.
Hello, Thank you for the confirmation,. Will there be extra cost if sentinel reads the logs.- Clive_WatsonBronze Contributor
Microsoft Sentinel has a similar billing, model to Log Analytics, please look up "Sentinel" in Pricing Calculator | Microsoft Azure
The total monthly price is for the Ingestion + Sentinel to analyse those same logs
"Microsoft Sentinel is billed for the volume of data stored in an Azure Monitor Log Analytics workspace and analyzed in Microsoft Sentinel."