You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/plan-defender-for-servers-data-workspace.md
+17-16Lines changed: 17 additions & 16 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,7 +4,7 @@ description: Review data residency and workspace design for Microsoft Defender f
4
4
ms.topic: conceptual
5
5
ms.author: dacurwin
6
6
author: dcurwin
7
-
ms.date: 11/06/2022
7
+
ms.date: 05/30/2023
8
8
ms.custom: references_regions
9
9
---
10
10
# Plan data residency and workspaces for Defender for Servers
@@ -78,13 +78,13 @@ You can store your server information in the default workspace or you can use a
78
78
79
79
### If I enable Defender for Clouds Servers plan on the subscription level, do I need to enable it on the workspace level?
80
80
81
-
When you enable the Servers plan on the subscription level, Defender for Cloud will enable the Servers plan on your default workspaces automatically. Connect to the default workspace by selecting **Connect Azure VMs to the default workspace(s) created by Defender for Cloud** option and selecting **Apply**.
81
+
When you enable the Servers plan on the subscription level, Defender for Cloud enables the Servers plan on your default workspaces automatically. Connect to the default workspace by selecting **Connect Azure VMs to the default workspace(s) created by Defender for Cloud** option and selecting **Apply**.
82
82
83
83
:::image type="content" source="media/plan-defender-for-servers-data-workspace/connect-workspace.png" alt-text="Screenshot showing how to auto-provision Defender for Cloud to manage your workspaces.":::
84
84
85
-
However, if you're using a custom workspace in place of the default workspace, you'll need to enable the Servers plan on all of your custom workspaces that don't have it enabled.
85
+
However, if you're using a custom workspace in place of the default workspace, you need to enable the Servers plan on all of your custom workspaces that don't have it enabled.
86
86
87
-
If you're using a custom workspace and enable the plan on the subscription level only, the `Microsoft Defender for servers should be enabled on workspaces` recommendation will appear on the Recommendations page. This recommendation will give you the option to enable the servers plan on the workspace level with the Fix button. You're charged for all VMs in the subscription even if the Servers plan isn't enabled for the workspace. The VMs won't benefit from features that depend on the Log Analytics workspace, such as Microsoft Defender for Endpoint, VA solution (MDVM/Qualys), and Just-in-Time VM access.
87
+
If you're using a custom workspace and enable the plan on the subscription level only, the `Microsoft Defender for servers should be enabled on workspaces` recommendation appears on the Recommendations page. This recommendation gives you the option to enable the servers plan on the workspace level with the Fix button. You're charged for all VMs in the subscription even if the Servers plan isn't enabled for the workspace. The VMs won't benefit from features that depend on the Log Analytics workspace, such as Microsoft Defender for Endpoint, VA solution (MDVM/Qualys), and Just-in-Time VM access.
88
88
89
89
Enabling the Servers plan on both the subscription and its connected workspaces, won't incur a double charge. The system will identify each unique VM.
90
90
@@ -104,11 +104,12 @@ Yes. If you configure your Log Analytics agent to send data to two or more diffe
104
104
105
105
### Is the 500-MB free data ingestion calculated for an entire workspace or strictly per machine?
106
106
107
-
You'll get 500-MB free data ingestion per day, for every VM connected to the workspace. Specifically for the [security data types](#what-data-types-are-included-in-the-500-mb-data-daily-allowance)that are directly collected by Defender for Cloud.
107
+
You receive a daily allowance of 500MB of free data ingestion for each virtual machine (VM) connected to the workspace. This allocation specifically applies to the [security data types](#what-data-types-are-included-in-the-500-mb-data-daily-allowance)collected directly by Defender for Cloud.
108
108
109
-
This data is a daily rate averaged across all nodes. Your total daily free limit is equal to **[number of machines] x 500 MB**. So even if some machines send 100 MB and others send 800 MB, if the total doesn't exceed your total daily free limit, you won't be charged extra.
109
+
The data allowance is a daily rate calculated across all connected machines. Your total daily free limit is equal to the **[number of machines] x 500 MB**. So even if on a given day some machines send 100 MB and others send 800 MB, if the total data from all machines doesn't exceed your daily free limit, you won't be charged extra.
110
110
111
111
### What data types are included in the 500-MB data daily allowance?
112
+
112
113
Defender for Cloud's billing is closely tied to the billing for Log Analytics. [Microsoft Defender for Servers](defender-for-servers-introduction.md) provides a 500 MB/node/day allocation for machines against the following subset of [security data types](/azure/azure-monitor/reference/tables/tables-category#security):
@@ -129,7 +130,7 @@ You can view your data usage in two different ways, the Azure portal, or by runn
129
130
130
131
**To view your usage in the Azure portal**:
131
132
132
-
1. Sign in to the [Azure portal](https://portal.azure.com).
133
+
1. Sign in to the [Azure portal](https://portal.azure.com).
133
134
134
135
1. Navigate to **Log Analytics workspaces**.
135
136
@@ -145,7 +146,7 @@ You can also view estimated costs under different pricing tiers by selecting :::
145
146
146
147
**To view your usage by using a script**:
147
148
148
-
1. Sign in to the [Azure portal](https://portal.azure.com).
149
+
1. Sign in to the [Azure portal](https://portal.azure.com).
149
150
150
151
1. Navigate to **Log Analytics workspaces** > **Logs**.
151
152
@@ -178,7 +179,7 @@ You may want to manage your costs and limit the amount of data collected for a s
178
179
> Solution targeting has been deprecated because the Log Analytics agent is being replaced with the Azure Monitor agent and solutions in Azure Monitor are being replaced with insights. You can continue to use solution targeting if you already have it configured, but it is not available in new regions.
179
180
> The feature will not be supported after August 31, 2024.
180
181
> Regions that support solution targeting until the deprecation date are:
181
-
>
182
+
>
182
183
> | Region code | Region name |
183
184
> | :--- | :---------- |
184
185
> | CCAN | canadacentral |
@@ -209,13 +210,13 @@ You may want to manage your costs and limit the amount of data collected for a s
209
210
>
210
211
> | Air-gapped clouds | Region code | Region name |
0 commit comments