<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Microsoft Sentinel Ideas Ideas</title>
    <link>https://techcommunity.microsoft.com/t5/microsoft-sentinel-ideas/idb-p/microsoft-sentinel-ideas</link>
    <description>Microsoft Sentinel Ideas Ideas</description>
    <pubDate>Mon, 31 Aug 2026 14:23:52 GMT</pubDate>
    <dc:creator>microsoft-sentinel-ideas</dc:creator>
    <dc:date>2026-08-31T14:23:52Z</dc:date>
    <item>
      <title>Make system-generated LogARepublisher Threat Intelligence updates non-billable (_IsBillable = false)</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-sentinel-ideas/make-system-generated-logarepublisher-threat-intelligence/idi-p/4551632</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Problem Statement:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Currently, Microsoft Sentinel regularly reruns an internal background process called LogARepublisher. This process periodically republishes existing Threat Intelligence data into the ThreatIntelIndicators table on an ongoing 7-to-10 day cycle to maintain freshness.&lt;/P&gt;&lt;P&gt;Because these system-generated updates write new records into the workspace, they are flagged as &lt;STRONG&gt;_IsBillable = true&lt;/STRONG&gt;. This results in organizations paying multiple times for the exact same threat indicators over their lifecycle. In general, this is a small amount of data but can form a larger percentage of ingest/analytic cost for customers with low ingestion volumes, and becomes noticeable at scale when managing many Azure tenants.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;Why This Matters:&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;Unintended Cost Allocation:&lt;/STRONG&gt; Customers are being billed for automated, backend data-maintenance cycles triggered by Microsoft, rather than true new log ingestion or external feed consumption.&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;Artificial Volume Inflation:&lt;/STRONG&gt; Large TI datasets can exponentially inflate monthly data volume metrics solely due to repeating republication, making budget forecasting unpredictable.&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;No Added Analytical Value: &lt;/STRONG&gt;Rerunning the exact same indicators does not offer new security value or unique logs; it simply updates the timestamp metadata on a new row.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Proposed Solution:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Modify the backend pipeline so that when a record is ingested via LastUpdateMethod == "LogARepublisher", the system-generated metadata property _IsBillable is automatically set to false.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Customers should only be billed for the initial ingestion of a threat indicator, not for the automated system maintenance required to keep it fresh within the Sentinel ecosystem.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2026 00:26:47 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-sentinel-ideas/make-system-generated-logarepublisher-threat-intelligence/idi-p/4551632</guid>
      <dc:creator>mtwexp</dc:creator>
      <dc:date>2026-08-31T00:26:47Z</dc:date>
    </item>
  </channel>
</rss>

