You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/billing-reduce-costs.md
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -5,7 +5,7 @@ author: cwatson-cat
5
5
ms.author: cwatson
6
6
ms.custom: subject-cost-optimization
7
7
ms.topic: how-to
8
-
ms.date: 01/26/2022
8
+
ms.date: 02/18/2022
9
9
---
10
10
11
11
# Reduce costs for Microsoft Sentinel
@@ -36,7 +36,7 @@ When hunting or investigating threats in Microsoft Sentinel, you might need to a
36
36
37
37
## Turn on basic logs data ingestion for data that's high-volume low security value (preview)
38
38
39
-
Unlike analytics logs, [basic logs](../azure-monitor/logs/azure-monitor-basic-logs.md) are typically verbose. They contains a mix of high volume and low security value data, that isn't frequently used or accessed on demand for ad-hoc querying, investigations and search. Enable basic log data ingestion at a significantly reduced cost for eligible data tables. For more information, see [Microsoft Sentinel Pricing](https://azure.microsoft.com/pricing/details/microsoft-sentinel/).
39
+
Unlike analytics logs, [basic logs](../azure-monitor/logs/basic-logs-configure.md) are typically verbose. They contains a mix of high volume and low security value data, that isn't frequently used or accessed on demand for ad-hoc querying, investigations and search. Enable basic log data ingestion at a significantly reduced cost for eligible data tables. For more information, see [Microsoft Sentinel Pricing](https://azure.microsoft.com/pricing/details/microsoft-sentinel/).
40
40
41
41
## Optimize Log Analytics costs with dedicated clusters
42
42
@@ -68,7 +68,7 @@ Microsoft Sentinel data retention is free for the first 90 days. To adjust the d
68
68
69
69
Microsoft Sentinel security data might lose some of its value after a few months. Security operations center (SOC) users might not need to access older data as frequently as newer data, but still might need to access the data for sporadic investigations or audit purposes.
70
70
71
-
To help you reduce Microsoft Sentinel data retention costs, Azure Monitor now offers archived logs. Archived logs store log data for very long periods of time, up to 7 years, at a reduced cost with limitations on its usage. Archived logs are in public preview.
71
+
To help you reduce Microsoft Sentinel data retention costs, Azure Monitor now offers archived logs. Archived logs store log data for very long periods of time, up to 7 years, at a reduced cost with limitations on its usage. Archived logs are in public preview. For more information, see [Configure data retention and archive policies in Azure Monitor Logs](../azure-monitor/logs/data-retention-archive.md).
72
72
73
73
Alternatively, you can use Azure Data Explorer for long-term data retention at lower cost. Azure Data Explorer provides the right balance of cost and usability for aged data that no longer needs Microsoft Sentinel security intelligence.
Copy file name to clipboardExpand all lines: articles/sentinel/billing.md
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -5,7 +5,7 @@ author: cwatson-cat
5
5
ms.author: cwatson
6
6
ms.custom: subject-cost-optimization
7
7
ms.topic: how-to
8
-
ms.date: 01/26/2022
8
+
ms.date: 02/18/2022
9
9
---
10
10
11
11
# Plan costs for Microsoft Sentinel
@@ -85,7 +85,7 @@ Basic logs have a reduced price and are charged at a flat rate per GB. They have
85
85
- Eight-day retention
86
86
- No support for scheduled alerts
87
87
88
-
Basic logs are best suited for use in playbook automation, ad-hoc querying, investigations, and search. For more information, see [Azure Monitor basic logs](../azure-monitor/logs/azure-monitor-basic-logs.md).
88
+
Basic logs are best suited for use in playbook automation, ad-hoc querying, investigations, and search. For more information, see [Configure Basic Logs in Azure Monitor](../azure-monitor/logs/basic-logs-configure.md).
89
89
90
90
### Understand your Microsoft Sentinel bill
91
91
@@ -157,7 +157,7 @@ Any other services you use could have associated costs.
157
157
158
158
After you enable Microsoft Sentinel on a Log Analytics workspace, you can retain all data ingested into the workspace at no charge for the first 90 days. Retention beyond 90 days is charged per the standard [Log Analytics retention prices](https://azure.microsoft.com/pricing/details/monitor/).
159
159
160
-
You can specify different retention settings for individual data types. For more information, see [Retention by data type](../azure-monitor/logs/manage-cost-storage.md#retention-by-data-type). You can also enable long-term retention for your data and have access to historical logs by enabling archived logs. Data archive is a low-cost retention layer for archival storage. It's charged based on the volume of data stored and scanned. For more information, see [Azure Monitor archived logs](../azure-monitor/logs/azure-monitor-archived-logs.md). Archived logs are in public preview.
160
+
You can specify different retention settings for individual data types. For more information, see [Retention by data type](../azure-monitor/logs/manage-cost-storage.md#retention-by-data-type). You can also enable long-term retention for your data and have access to historical logs by enabling archived logs. Data archive is a low-cost retention layer for archival storage. It's charged based on the volume of data stored and scanned. For more information, see [Configure data retention and archive policies in Azure Monitor Logs](../azure-monitor/logs/data-retention-archive.md). Archived logs are in public preview.
161
161
162
162
The 90 day retention doesn't apply to basic logs. If you want to extend data retention for basic logs beyond eight days, you can store that data in archived logs for up to seven years.
0 commit comments