You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/basic-logs-use-cases.md
+2-3Lines changed: 2 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -19,9 +19,8 @@ ms.collection: usx-security
19
19
This article highlights log sources to consider configuring as data lake tier only when enabling a connector. Before choosing a tier for which to configure a given table, check which tier is most appropriate for your use case. For more information about data categories and data tiers, see [Log retention plans in Microsoft Sentinel](log-plans.md).
>The Microsoft Sentinel data lake is currently in preview. See [Supplemental Terms of Use for Microsoft Azure Previews](/support/legal/preview-supplemental-terms) for additional legal terms that apply to Azure features that are in preview or otherwise not yet released into general availability.
Copy file name to clipboardExpand all lines: articles/sentinel/best-practices.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -23,7 +23,7 @@ Start with the [deployment guide for Microsoft Sentinel](deploy-overview.md). Th
23
23
24
24
## Adopt a single-platform architecture
25
25
26
-
Microsoft Sentinel is now integrated with a modern data lake that offers affordable, long-term storage enabling teams to simplify data management, optimize costs, and accelerate the adoption of AI. Microsoft Sentinel data lake (Preview) enables a single-platform architecture for security data and empowers analysts with a unified query experience while leveraging Microsoft Sentinel’s rich connector ecosystem. For more information, see [Microsoft Sentinel data lake (Preview)](graph/sentinel-lake-overview.md).
26
+
Microsoft Sentinel is integrated with a modern data lake that offers affordable, long-term storage enabling teams to simplify data management, optimize costs, and accelerate the adoption of AI. The Microsoft Sentinel data lake (preview) enables a single-platform architecture for security data and empowers analysts with a unified query experience while leveraging Microsoft Sentinel’s rich connector ecosystem. For more information, see [Microsoft Sentinel data lake (preview)](graph/sentinel-lake-overview.md).
Copy file name to clipboardExpand all lines: articles/sentinel/billing-reduce-costs.md
+1-2Lines changed: 1 addition & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -53,8 +53,7 @@ Microsoft Sentinel analyzes all the data ingested into Microsoft Sentinel-enable
53
53
54
54
While the analytics tier is most appropriate for continuous, real-time threat detection, the Microsoft Sentinel data lake is well-suited for query and analytics of secondary security data that is not needed for real time threat detection. Microsoft Sentinel data lake offers ingestion and storage at a significantly reduced cost. For more information, see [Microsoft Sentinel Pricing](https://azure.microsoft.com/pricing/details/microsoft-sentinel/).
55
55
56
-
>[!NOTE]
57
-
>The Microsoft Sentinel data lake is currently in Public Preview.
Copy file name to clipboardExpand all lines: articles/sentinel/billing.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -33,7 +33,7 @@ This article is part of the [Deployment guide for Microsoft Sentinel](deploy-ove
33
33
34
34
Enable Microsoft Sentinel on an Azure Monitor Log Analytics workspace and the first 10 GB/day ingested using the Analytics logs plan is free for 31 days. The cost for both Log Analytics data ingestion and Microsoft Sentinel analysis charges up to the 10 GB/day limit, are waived during the 31-day trial period. This free trial is subject to a 20 workspace limit per Azure tenant.
35
35
36
-
See [Microsoft Sentinel pricing](https://azure.microsoft.com/pricing/details/azure-sentinel) page for information on how usage beyond these limits is charged. Charges related to extra capabilities for [automation](automation.md) and [bring your own machine learning](bring-your-own-ml.md) are still applicable during the free trial, as well as any Microsoft Sentinel data lake related charges.
36
+
See the [Microsoft Sentinel pricing](https://azure.microsoft.com/pricing/details/azure-sentinel) page for information on how usage beyond these limits is charged. Charges related to extra capabilities for [automation](automation.md) and [bring your own machine learning](bring-your-own-ml.md) are still applicable during the free trial, as well as any Microsoft Sentinel data lake related charges.
37
37
38
38
During your free trial, find resources for cost management, training, and more on the [**News & guides > Free trial**](https://portal.azure.com/#view/Microsoft_Azure_Security_Insights/MainMenuBlade/~/NewsAndGuides) tab in Microsoft Sentinel on the Azure portal. This tab also displays details about the dates of your free trial, and how many days left until the trial expires.
39
39
@@ -78,7 +78,7 @@ The data lake tier incurs charges based on usage of various data like capabiliti
78
78
Once onboarded, usage from Microsoft Sentinel workspaces begins to be billed through the above described meters rather than existing long-term retention (formerly known as Archive), search or auxiliary logs ingestion meters.
79
79
80
80
>[!IMPORTANT]
81
-
>While in Public Preview, once onboarded to the Microsoft Sentinel data lake, billing through new meters will be billed at the respective meters' list rate. Pricing from previous meters doesn't carry over. For more details on pricing, see [Microsoft Sentinel pricing](https://azure.microsoft.com/pricing/details/microsoft-sentinel/).
81
+
>While in preview, once onboarded to the Microsoft Sentinel data lake, billing through new meters is billed at the respective meters' list rate. Pricing from previous meters doesn't carry over. For more details on pricing, see [Microsoft Sentinel pricing](https://azure.microsoft.com/pricing/details/microsoft-sentinel/).
82
82
>Existing customers that are currently billed for Auxiliary logs ingestion, long-term retention and search, will see charges transition to the new data lake ingestion, data lake storage and data lake query meters respectively.
83
83
84
84
For customers that haven't onboarded to the Microsoft Sentinel data lake and are currently using Auxiliary or Basic logs, see [Manage data retention in a Log Analytics workspace](/azure/azure-monitor/logs/data-retention-archive) and [Azure Monitor pricing](https://azure.microsoft.com/pricing/details/monitor/) for relevant information.
Copy file name to clipboardExpand all lines: articles/sentinel/configure-data-connector.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -17,7 +17,7 @@ ms.collection: usx-security
17
17
18
18
# Connect data sources to Microsoft Sentinel by using data connectors
19
19
20
-
Connect data sources to Microsoft Sentinel by installing and configuring data connectors. This article generally explains how to install data connectors available in the Microsoft Sentinel **Content hub** to ingest and analyze data for improved threat detection.
20
+
To connect data sources to Microsoft Sentinel, you need to install and configure data connectors. This article generally explains how to install data connectors available in the Microsoft Sentinel **Content hub** to ingest and analyze data for improved threat detection.
21
21
22
22
-[Microsoft Sentinel data connectors](connect-data-sources.md)
23
23
-[Find your Microsoft Sentinel data connector](data-connectors-reference.md)
@@ -58,7 +58,7 @@ After you or someone in your organization installs the solution that includes th
58
58
-[Connect Microsoft Sentinel to Azure, Windows, Microsoft, and Amazon services](connect-azure-windows-microsoft-services.md)
If you have onboarded to the Microsoft Sentinel data lake (preview), you can configure data retention and tiering for the data connector. The data lake consists of an analytics tier - your current Microsoft Sentinel workspaces, and a data lake tier where you can store data for up to 12 years. For more information on onboarding, see [Onboarding to Microsoft Sentinel data lake](graph/sentinel-lake-onboarding.md).
Copy file name to clipboardExpand all lines: articles/sentinel/graph/kql-jobs.md
+6-7Lines changed: 6 additions & 7 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -6,7 +6,7 @@ author: EdB-MSFT
6
6
ms.service: microsoft-sentinel
7
7
ms.topic: conceptual
8
8
ms.subservice: sentinel-graph
9
-
ms.date: 07/09/2025
9
+
ms.date: 07/15/2025
10
10
ms.author: edbaynash
11
11
12
12
ms.collection: ms-security
@@ -19,7 +19,7 @@ ms.collection: ms-security
19
19
# Create KQL jobs in the Microsoft Sentinel data lake (preview)
20
20
21
21
22
-
A job is a one-time or scheduled task that runs a KQL (Kusto Query Language) query against the data in the lake tier to promote the results to the analytics tier. Once in the analytics tier, use the advanced hunting KQL editor to query the data. Promoting data to the analytics tier has the following benefits:
22
+
A job is a one-time or repeatedly scheduled task that runs a KQL (Kusto Query Language) query against the data in the data lake tier to promote the results to the analytics tier. Once in the analytics tier, use the advanced hunting KQL editor to query the data. Promoting data to the analytics tier has the following benefits:
23
23
24
24
+ Combine current and historical data in the analytics tier to run advanced analytics and machine learning models on your data.
25
25
@@ -32,9 +32,6 @@ A job is a one-time or scheduled task that runs a KQL (Kusto Query Language) que
32
32
33
33
When promoting data to the analytics tier, make sure that the destination workspace is visible in the advanced hunting query editor. You can only query connected workspaces in the advanced hunting query editor. You will not be able to see data promoted to workspaces that aren't connected or to the default workspace in advance hunting. For more information on connected workspaces, see [Connect a workspace](/defender-xdr/advanced-hunting-microsoft-defender#connect-a-workspace). You can promote data to a new table or append the results to an existing table in the analytics tier. When creating a new table, the table name is suffixed with *_KQL_CL* to indicate that the table was created by a KQL job.
34
34
35
-
36
-
You can create a job by selecting the **Create job** button a KQL query tab or directly from the **Jobs** management page or by. For more information on the Jobs management page, see [Manage jobs in the Microsoft Sentinel data lake](kql-manage-jobs.md).
37
-
38
35
## Prerequisites
39
36
40
37
The following prerequisites are required to create and manage KQL jobs in the Microsoft Sentinel data lake.
@@ -85,7 +82,7 @@ You can create and manage jobs from the **Jobs** management page under **Data la
85
82
1. To append to an existing table, select **Add to an existing table** and select the table name form the drop-down list. When adding to an existing table, the query results must match the schema of the existing table.
86
83
87
84
1. Select **Next**.
88
-
:::image type="content" source="media/kql-jobs/enter-job-name-details.png" alt-text="A screenshot showing the new job details page." lightbox="media/kql-jobs/enter-job-name-details.png":::
85
+
:::image type="content" source="media/kql-jobs/enter-job-details.png" alt-text="A screenshot showing the new job details page." lightbox="media/kql-jobs/enter-job-details.png":::
89
86
90
87
1. Review or write your query in the Review the query panel. Check that the time picker is set to the required time range for the job if the date range isn't specified in the query.
91
88
1. Select the workspace to run the query against from the **Selected workspace** drop-down.
@@ -96,7 +93,7 @@ You can create and manage jobs from the **Jobs** management page under **Data la
In the **Schedule the query job** panel, select whether you want to run the job once or on a schedule. If you select **One time**, the job runs as soon as the job definition is complete. If you select **Schedule**, you can specify a date and time for the job to run, or run the job on a recurring schedule.
96
+
In the **Schedule the query job** panel, select whether you want to run the job once or on a schedule. If you select **One time**, the job runs as soon as the job definition is complete. If you select **Schedule**, you can specify a date and time for the job to run, or run the job on a recurring schedule.
100
97
101
98
1. Select **One time** or **Scheduled job**.
102
99
>[!NOTE]
@@ -150,6 +147,8 @@ For service limits, see [Microsoft Sentinel data lake (preview) service limits](
150
147
> [!NOTE]
151
148
> Partial results may be promoted if the job's query exceeds the one hour limit.
152
149
150
+
[!INCLUDE [limitations for KQL jobs](../includes/service-limits-kql-jobs.md)]
151
+
153
152
For troubleshooting tips and error messages, see [Troubleshooting KQL queries for the Microsoft Sentinel data lake (preview)](kql-troubleshoot.md).
Select the **Destination table** link to open the table in the KQL query editor in Advanced hunting. The query can be copied by selecting **Copy query**.
51
+
To see a job's details, select the job from the table.
Select the **Destination table** link to open the table in the KQL query editor in Advanced hunting.
56
+
The query can be copied by selecting **Copy query**.
73
57
74
58
### Edit a job
75
59
@@ -102,7 +86,7 @@ To delete a job, select **Delete** in the job details panel. A confirmation dia
102
86
103
87
## Considerations and limitations
104
88
105
-
For information on considerations and limitations when managing KQL jobs in the Microsoft Sentinel data lake, see [KQL jobs](kql-jobs.md#considerations-and-limitations).
89
+
For information on considerations and limitations when managing KQL jobs in the Microsoft Sentinel data lake, see [KQL jobs](kql-jobs.md#considerations-and-limitations).
0 commit comments