Forum Discussion

burasathi's avatar
burasathi
Copper Contributor
May 31, 2023

Sentinel log ingestion

@macd in Microsoft Sentinel

Hello, 

 

I have one question regarding log ingestion.

If we already have logs in the log analytic workspace and later if we enable sentinel in the same workspace, then will that sentinel be able to read those logs or do we need to ingest those logs again through sentinel data connectors?

 

Thank you

  • Clive_Watson's avatar
    Clive_Watson
    Bronze Contributor
    Logs are only ingested once, Sentinel reads them, so they will be available to you *after* you enable Sentinel
    • burasathi's avatar
      burasathi
      Copper Contributor
      Clive_Watson.
      Hello, Thank you for the confirmation,. Will there be extra cost if sentinel reads the logs.
      • Clive_Watson's avatar
        Clive_Watson
        Bronze Contributor

        burasathi 

         

        Microsoft Sentinel has a similar billing, model to Log Analytics, please look up "Sentinel" in Pricing Calculator | Microsoft Azure

        The total monthly price is for the Ingestion + Sentinel to analyse those same logs 

        "Microsoft Sentinel is billed for the volume of data stored in an Azure Monitor Log Analytics workspace and analyzed in Microsoft Sentinel."

         

Share

Resources