Skip to content

Commit 0b6894f

Browse files
Merge pull request #209655 from cwatson-cat/patch-4
Sentinel plan billing upd - free data sources
2 parents dcb955c + d6b7916 commit 0b6894f

File tree

1 file changed

+18
-28
lines changed

1 file changed

+18
-28
lines changed

articles/sentinel/billing.md

Lines changed: 18 additions & 28 deletions
Original file line numberDiff line numberDiff line change
@@ -180,37 +180,27 @@ The following data sources are free with Microsoft Sentinel:
180180

181181
Although alerts are free, the raw logs for some Microsoft 365 Defender, Defender for Cloud Apps, Azure Active Directory (Azure AD), and Azure Information Protection (AIP) data types are paid.
182182

183-
The following table lists the free data sources you can enable in Microsoft Sentinel. Some of the data connectors, such as Microsoft 365 Defender and Defender for Cloud Apps, include both free and paid data types.
184-
185-
| Microsoft Sentinel Data Connector | Data type | Free or paid |
186-
|-------------------------------------|--------------------------------|------------------|
187-
| **Azure Activity Logs** | AzureActivity | Free |
188-
| **Azure AD Identity Protection** | SecurityAlert (IPC) | Free |
189-
| **Office 365** | OfficeActivity (SharePoint) | Free|
190-
|| OfficeActivity (Exchange)|Free|
191-
|| OfficeActivity (Teams) | Free|
192-
| **Microsoft Defender for Cloud** | SecurityAlert (Defender for Cloud) | Free |
193-
| **Microsoft Defender for IoT** | SecurityAlert (Defender for IoT) | Free |
194-
| **Microsoft 365 Defender** | SecurityIncident | Free|
195-
||SecurityAlert| Free|
196-
||DeviceEvents | Paid|
197-
||DeviceFileEvents | Paid|
198-
||DeviceImageLoadEvents | Paid|
199-
||DeviceInfo | Paid|
200-
||DeviceLogonEvents | Paid|
201-
||DeviceNetworkEvents | Paid|
202-
||DeviceNetworkInfo | Paid|
203-
||DeviceProcessEvents | Paid|
204-
||DeviceRegistryEvents | Paid|
205-
||DeviceFileCertificateInfo | Paid|
206-
| **Microsoft Defender for Endpoint** | SecurityAlert (MDATP) | Free |
207-
| **Microsoft Defender for Identity** | SecurityAlert (AATP) | Free |
208-
| **Microsoft Defender for Cloud Apps** | SecurityAlert (Defender for Cloud Apps) | Free |
209-
||MCASShadowITReporting | Paid|
183+
The following table lists the free data sources you can enable in Microsoft Sentinel.
184+
185+
| Microsoft Sentinel data connector | Free data type |
186+
|-------------------------------------|--------------------------------|
187+
| **Azure Activity Logs** | AzureActivity |
188+
| **Azure AD Identity Protection** | SecurityAlert (IPC) |
189+
| **Office 365** | OfficeActivity (SharePoint) |
190+
|| OfficeActivity (Exchange)|
191+
|| OfficeActivity (Teams) |
192+
| **Microsoft Defender for Cloud** | SecurityAlert (Defender for Cloud) |
193+
| **Microsoft Defender for IoT** | SecurityAlert (Defender for IoT) |
194+
| **Microsoft 365 Defender** | SecurityIncident |
195+
||SecurityAlert|
196+
| **Microsoft Defender for Endpoint** | SecurityAlert (MDATP) |
197+
| **Microsoft Defender for Identity** | SecurityAlert (AATP) |
198+
| **Microsoft Defender for Cloud Apps** | SecurityAlert (Defender for Cloud Apps) |
199+
210200

211201
For data connectors that include both free and paid data types, you can select which data types you want to enable.
212202

213-
:::image type="content" source="media/billing/data-types.png" alt-text="Screenshot of the Data connector page for Defender for Cloud Apps, with the free security alerts selected and the paid M C A S Shadow I T Reporting not selected." lightbox="media/billing/data-types.png":::
203+
:::image type="content" source="media/billing/data-types.png" alt-text="Screenshot of the Data connector page for Defender for Cloud Apps, with the free security alerts selected and the paid MCAS Shadow IT Reporting not selected." lightbox="media/billing/data-types.png":::
214204

215205
Learn more about how to [connect data sources](connect-data-sources.md), including free and paid data sources.
216206

0 commit comments

Comments
 (0)