You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/graph/sentinel-lake-onboarding.md
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,5 +1,5 @@
1
1
---
2
-
title: Onboarding to Microsoft Sentinel data lake (Preview)
2
+
title: Onboarding to Microsoft Sentinel data lake (preview)
3
3
titleSuffix: Microsoft Security
4
4
description: This article describes how to onboard to the Microsoft Sentinel data lake
5
5
author: EdB-MSFT
@@ -13,7 +13,7 @@ ms.subservice: sentinel-graph
13
13
---
14
14
15
15
16
-
# Onboarding to Microsoft Sentinel data lake (Preview)
16
+
# Onboarding to Microsoft Sentinel data lake (preview)
17
17
18
18
19
19
The Microsoft Sentinel data lake (Preview), available in the Microsoft Defender portal, is a tenant-wide, centralized repository designed to store and manage vast amounts of security-related data from various sources. It enables your organization to collect, ingest, and analyze security data in a unified manner, providing a comprehensive view of your security landscape. Leveraging advanced analytics, machine learning, and artificial intelligence, the Microsoft Sentinel data lake helps in detecting threats, investigate and responding to incidents, and improving overall security posture.
@@ -98,7 +98,7 @@ Use the following steps to onboard to the Microsoft Sentinel data lake from the
98
98
> If you accidentally close the banner, you can initiate onboarding by navigating to the data lake settings page under **System Settings**, **Microsoft Sentinel**.
99
99
100
100
101
-
1. If you don't have the correct roles to set up the data lake, a side panel appears indicating that you don't have the required permissions. Request that your administrator complete the onboarding process.
101
+
1. If you don't have the correct roles to set up the data lake, a side panel appears indicating that you don't have the required permissions. Request that your administrator completes the onboarding process.
102
102
103
103
:::image type="content" source="./media/sentinel-lake-onboarding/permissions-required.png" lightbox="./media/sentinel-lake-onboarding/permissions-required.png" alt-text="A screenshot showing the permissions required page in the Defender portal.":::
104
104
@@ -136,6 +136,6 @@ If you encounter any issues during the setup process, see the following troubles
136
136
## Related content
137
137
138
138
-[Microsoft Sentinel data lake overview (Preview)](https://aka.ms/sentinel-lake-overview)
139
-
-[Microsoft Sentinel data lake roles and permissions](https://aka.ms/sentinel-data-lake-roles)<!---(../roles.md#roles-and-permissions-for-the-microsoft-sentinel-data-lake-preview) --->
139
+
-[Microsoft Sentinel data lake roles and permissions](https://aka.ms/sentinel-data-lake-roles)
140
140
-[Microsoft Sentinel data lake billing](../billing.md)
141
141
-[Create custom roles with Microsoft Defender XDR Unified role-based access control (RBAC)](/defender-xdr/create-custom-rbac-roles)
Copy file name to clipboardExpand all lines: articles/sentinel/graph/sentinel-lake-overview.md
+9-10Lines changed: 9 additions & 10 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,5 +1,5 @@
1
1
---
2
-
title: Microsoft Sentinel data lake overview(Preview).
2
+
title: Microsoft Sentinel data lake overview(preview).
3
3
titleSuffix: Microsoft Security
4
4
description: An overview of Microsoft Sentinel data lake, a cloud-native platform that extends Microsoft Sentinel with highly scalable, cost-effective long-term storage, advanced analytics, and AI-driven security operations.
5
5
author: EdB-MSFT
@@ -13,7 +13,7 @@ ms.collection: ms-security
13
13
---
14
14
15
15
16
-
# What is Microsoft Sentinel data lake (Preview) ?
16
+
# What is Microsoft Sentinel data lake (preview)?
17
17
18
18
Microsoft Sentinel data lake is a purpose-built, cloud-native security data lake that transforms how organizations manage and analyze security data. Architected as a true data lake, it is designed to ingest, store, and analyze large volumes of diverse security data at scale. By centralizing all your security data into a single, open, and extensible platform, it delivers deep visibility, long-term retention, and advanced analytics.
19
19
@@ -44,7 +44,7 @@ The Microsoft Sentinel data lake technical architecture includes the following k
44
44
The Microsoft Sentinel data lake is designed with two distinct storage tiers to optimize cost and performance:
45
45
46
46
+ Analytics tier: The existing Microsoft Sentinel data tier enabling advanced querying, visualization, and alerting capabilities to help you proactively identify and resolve issues across your infrastructure and applications.
47
-
+ Data lake tier: A centralized security data lake offering long-term data storage for querying and python-based advanced analytics. The data lake tier is designed for cost-effective storage of large volumes of security data, enabling you to retain data for up to 12 years. For more information on data tiers and retention, see [Manage data tiers and retention in Microsoft Defender Portal (Preview)](https://aka.ms/manage-data-defender-portal-overview)<!---(/unified-secops-platform/manage-data-defender-portal-overview).--->
47
+
+ Data lake tier: A centralized security data lake offering long-term data storage for querying and python-based advanced analytics. The data lake tier is designed for cost-effective storage of large volumes of security data, enabling you to retain data for up to 12 years. For more information on data tiers and retention, see [Manage data tiers and retention in Microsoft Defender Portal (preview)](https://aka.ms/manage-data-defender-portal-overview).
48
48
49
49
50
50
### Integration
@@ -78,13 +78,13 @@ KQL queries offer the following key features:
78
78
+ Full support for KQL: Use the full range of KQL capabilities, including machine learning functions and advanced analytics.
79
79
+ Job Creation: Create one-time or scheduled jobs to promote data from the lake to the analytics tier.
80
80
81
-
For more information, see [KQL and the Microsoft Sentinel data lake (Preview)](https://aka.ms/kql-overview)
81
+
For more information, see [KQL and the Microsoft Sentinel data lake (preview)](https://aka.ms/kql-overview)
82
82
83
83
### Powerful analytics using Jupyter notebooks
84
84
85
85
Jupyter notebooks in the Microsoft Sentinel data lake provide a powerful environment for data analysis and machine learning. Use Python libraries to build and run machine learning models, conduct advanced analytics, and visualize your data. The notebooks support rich visualizations, enabling you to gain insights from your security data. Schedule notebooks to summarize data, run machine learning models, and promote data from the lake tier to the analytics tier.
86
86
87
-
For more information, see [Jupyter notebooks in the Microsoft Sentinel data lake (Preview)](https://aka.ms/notebooks-overview).
87
+
For more information, see [Jupyter notebooks in the Microsoft Sentinel data lake (preview)](https://aka.ms/notebooks-overview).
88
88
89
89
:::image type="content" source="media/sentinel-lake-overview/notebook.png" lightbox="media/sentinel-lake-overview/notebook.png" alt-text="A screenshot showing a Jupyter notebook.":::
90
90
@@ -104,8 +104,7 @@ For more information on audited data lake activities, see [Search the audit log
104
104
105
105
To get started with Microsoft Sentinel data lake, follow these steps in the [onboarding guide](https://aka.ms/sentinel-lake-onboarding).
106
106
For more information on using the Microsoft Sentinel data lake, see the following articles:
107
-
+[Jupyter notebooks in the Microsoft Sentinel data lake (Preview)](https://aka.ms/notebooks-overview).
108
-
+[KQL and the Microsoft Sentinel data lake (Preview)](https://aka.ms/kql-overview)
109
-
+[Permissions for the Microsoft Sentinel data lake (Preview)](https://aka.ms/sentinel-data-lake-roles)<!---(../roles.md#roles-and-permissions-for-the-microsoft-sentinel-data-lake-preview)--->
110
-
+[Manage data tiers and retention in Microsoft Defender Portal (Preview)](https://aka.ms/manage-data-defender-portal-overview)<!---(/unified-secops-platform/manage-data-defender-portal-overview)--->
111
-
107
+
+[Jupyter notebooks in the Microsoft Sentinel data lake (preview)](https://aka.ms/notebooks-overview).
108
+
+[KQL and the Microsoft Sentinel data lake (preview)](https://aka.ms/kql-overview)
109
+
+[Permissions for the Microsoft Sentinel data lake (preview)](https://aka.ms/sentinel-data-lake-roles)
110
+
+[Manage data tiers and retention in Microsoft Defender Portal (preview)](https://aka.ms/manage-data-defender-portal-overview)
Copy file name to clipboardExpand all lines: articles/sentinel/includes/service-limits-notebooks.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -11,7 +11,7 @@ ms.date: 06/30/2025
11
11
The following section lists the service limits for Microsoft Sentinel data lake (Preview) when using VS Code Notebooks.
12
12
13
13
+ Spark compute session takes about 5-6 minutes to start. You can view the status of the session at the bottom of your VS Code Notebook.
14
-
+ Only [Azure Synapse libraries](https://github.com/microsoft/synapse-spark-runtime/blob/main/Synapse/spark3.4/Official-Spark3.4-Rel-2025-04-16.0-rc.1.md) and the Microsoft Sentinel Provider library for abstracted functions are supported for querying lake. Pip installs or custom libraries aren't supported.
14
+
+ Only [Azure Synapse libraries 3.4](https://github.com/microsoft/synapse-spark-runtime/tree/main#readme) and the Microsoft Sentinel Provider library for abstracted functions are supported for querying lake. Pip installs or custom libraries aren't supported.
0 commit comments