Optimize Microsoft Sentinel Pricing

Поділитися
Вставка
  • Опубліковано 22 жов 2024

КОМЕНТАРІ • 4

  • @edemfromeden5432
    @edemfromeden5432 Рік тому

    Question. You mention to not enable the Defender 365 tables if not using them within analytic rules. What about ingesting them for long term retention? The MDE advanced hunting data is available just for 30 days of KQL query capabilities, then it is just 180 days but limited to the timeline feature (not practical for forensic investigation). With the Sentinel connector we could keep the raw logs for much longer than the default 30 days. If not the Sentinel connector someone could write script to ingest the raw logs through the Defender API to just a log analytics, but Sentinel seams to be a quick win here (especially if you have E5 licensed users - you get the 5MB/day allowance that includes the advanced hunting tables as well).

  • @t.b9735
    @t.b9735 Рік тому

    Best Azure Channel!

  • @henriettagallaway6858
    @henriettagallaway6858 Рік тому

    𝖕𝖗𝖔𝖒𝖔𝖘𝖒 👊