Optimize Microsoft Sentinel Pricing

Поділитися
Вставка
  • Опубліковано 10 гру 2024
  • In this video I will explain how you can optimise the #pricing of #Microsoft #Sentinel. I will show you how the pricing is built up and what settings you can change to optimise the pricing of your Sentinel workspace
    ▼ Medium Post Koos Goossens:
    / optimize-microsoft-sen...
    ▼ Microsoft docs related to pricing
    learn.microsof...
    ▼ Social Jeroen Niesen
    Twitter: / jeroenniesen​​​
    ▼ Social AzureVlog
    Twitter: / azurevlog

КОМЕНТАРІ • 4

  • @t.b9735
    @t.b9735 2 роки тому

    Best Azure Channel!

  • @edemfromeden5432
    @edemfromeden5432 Рік тому

    Question. You mention to not enable the Defender 365 tables if not using them within analytic rules. What about ingesting them for long term retention? The MDE advanced hunting data is available just for 30 days of KQL query capabilities, then it is just 180 days but limited to the timeline feature (not practical for forensic investigation). With the Sentinel connector we could keep the raw logs for much longer than the default 30 days. If not the Sentinel connector someone could write script to ingest the raw logs through the Defender API to just a log analytics, but Sentinel seams to be a quick win here (especially if you have E5 licensed users - you get the 5MB/day allowance that includes the advanced hunting tables as well).

  • @henriettagallaway6858
    @henriettagallaway6858 2 роки тому

    𝖕𝖗𝖔𝖒𝖔𝖘𝖒 👊