Skip to content

Commit f529909

Browse files
authored
Merge pull request #302743 from EdB-MSFT/lake-updates-batami-review
updates
2 parents 289a46a + 16d4866 commit f529909

26 files changed

+159
-176
lines changed

articles/sentinel/TOC.yml

Lines changed: 38 additions & 40 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@
55
items:
66
- name: What is Microsoft Sentinel?
77
href: overview.md
8-
- name: What is Microsoft Sentinel data lake (Preview)?
8+
- name: Microsoft Sentinel data lake overview
99
href: graph/sentinel-lake-overview.md
1010
displayName: data lake
1111
- name: What's new
@@ -14,46 +14,44 @@
1414
href: best-practices.md
1515
- name: Experience in Defender portal
1616
href: microsoft-sentinel-defender-portal.md
17-
- name: Microsoft Sentinel data lake (Preview)
17+
- name: Data lake exploration
1818
items:
19-
- name: Data lake exploration
19+
- name: KQL for the Microsoft Sentinel data lake
2020
items:
21-
- name: KQL for the Microsoft Sentinel data lake (Preview)
22-
items:
23-
- name: Overview
24-
href: graph/kql-overview.md
25-
displayName: data lake
26-
- name: Run KQL queries (Preview)
27-
href: graph/kql-queries.md
28-
displayName: data lake
29-
- name: Sample data lake queries (Preview)
30-
href: graph/kql-samples.md
31-
displayName: data lake
32-
- name: Create KQL jobs (Preview)
33-
href: graph/kql-jobs.md
34-
displayName: data lake
35-
- name: Manage KQL jobs (Preview)
36-
href: graph/kql-manage-jobs.md
37-
displayName: data lake
38-
- name: Troubleshoot KQL for the lake (Preview)
39-
href: graph/kql-troubleshoot.md
40-
displayName: data lake
41-
- name: Notebooks for data lake exploration (Preview)
42-
items:
43-
- name: Overview
44-
href: graph/notebooks-overview.md
45-
displayName: data lake
46-
- name: Run notebooks (Preview)
47-
href: graph/notebooks.md
48-
displayName: data lake
49-
- name: Microsoft Sentinel provider class reference (Preview)
50-
href: graph/sentinel-provider-class-reference.md
51-
displayName: data lake
52-
- name: Create and manage notebook jobs (Preview)
53-
href: graph/notebook-jobs.md
54-
displayName: data lake
55-
- name: Notebook examples for data lake exploration (Preview)
56-
href: graph/notebook-examples.md
21+
- name: Overview
22+
href: graph/kql-overview.md
23+
displayName: data lake
24+
- name: Run KQL queries
25+
href: graph/kql-queries.md
26+
displayName: data lake
27+
- name: Sample data lake queries
28+
href: graph/kql-samples.md
29+
displayName: data lake
30+
- name: Create KQL jobs
31+
href: graph/kql-jobs.md
32+
displayName: data lake
33+
- name: Manage KQL jobs
34+
href: graph/kql-manage-jobs.md
35+
displayName: data lake
36+
- name: Troubleshoot KQL for the lake
37+
href: graph/kql-troubleshoot.md
38+
displayName: data lake
39+
- name: Notebooks for data lake exploration
40+
items:
41+
- name: Overview
42+
href: graph/notebooks-overview.md
43+
displayName: data lake
44+
- name: Run notebooks
45+
href: graph/notebooks.md
46+
displayName: data lake
47+
- name: Microsoft Sentinel provider class reference
48+
href: graph/sentinel-provider-class-reference.md
49+
displayName: data lake
50+
- name: Create and manage notebook jobs
51+
href: graph/notebook-jobs.md
52+
displayName: data lake
53+
- name: Notebook examples for data lake exploration
54+
href: graph/notebook-examples.md
5755
- name: Plan
5856
items:
5957
- name: Deployment planning guide
@@ -97,7 +95,7 @@
9795
href: quickstart-onboard.md
9896
- name: Connect Microsoft Sentinel to the Defender portal
9997
href: /unified-secops-platform/microsoft-sentinel-onboard?toc=/azure/sentinel/TOC.json&bc=/azure/sentinel/breadcrumb/toc.json
100-
- name: Onboard to Microsoft Sentinel data lake (Preview)
98+
- name: Onboard to Microsoft Sentinel data lake
10199
href: graph/sentinel-lake-onboarding.md
102100
displayName: data lake
103101
- name: Set up connectors for the Microsoft Sentinel data lake

articles/sentinel/basic-logs-use-cases.md

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,10 @@
11
---
2-
title: When to use data lake in Microsoft Sentinel
3-
description: Learn what log sources might be appropriate for the Microsoft Sentinel data lake and what attributes to look for, to decide about other sources.
2+
title: When to use the Microsoft Sentinel data lake
3+
description: Learn what log sources might be appropriate for the Microsoft Sentinel data lake and what attributes to look for, to decide about other sources.
44
author: EdB-MSFT
55
ms.author: edbaynash
66
ms.topic: conceptual
7-
ms.date: 07/07/2025
7+
ms.date: 07/15/2025
88
appliesto:
99
- Microsoft Sentinel in the Microsoft Defender portal
1010
- Microsoft Sentinel in the Azure portal
@@ -16,11 +16,11 @@ ms.collection: usx-security
1616
---
1717
# Log sources to use for the Microsoft Sentinel data lake
1818

19-
This article highlights log sources to consider configuring as data lake tier only when enabling a connector. Before choosing a tier for which to configure a given table, do the research to see which is most appropriate. For more information about data categories and data tiers, see [Data tiers in Microsoft Sentinel](log-plans.md).
19+
This article highlights log sources to consider configuring as data lake tier only when enabling a connector. Before choosing a tier for which to configure a given table, check which tier is most appropriate for your use case. For more information about data categories and data tiers, see [Log retention plans in Microsoft Sentinel](log-plans.md).
2020

2121
[!INCLUDE [unified-soc-preview](includes/unified-soc-preview.md)]
22-
>[!NOTE]
23-
>The Microsoft Sentinel data lake is currently in Public Preview.
22+
23+
[!INCLUDE [sentinel-lake-preview](includes/sentinel-lake-preview.md)]
2424

2525
## Storage access logs for cloud providers
2626

articles/sentinel/best-practices.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ Start with the [deployment guide for Microsoft Sentinel](deploy-overview.md). Th
2323

2424
## Adopt a single-platform architecture
2525

26-
Microsoft Sentinel is now integrated with a modern data lake that offers affordable, long-term storage enabling teams to simplify data management, optimize costs, and accelerate the adoption of AI. Microsoft Sentinel data lake (Preview) enables a single-platform architecture for security data and empowers analysts with a unified query experience while leveraging Microsoft Sentinel’s rich connector ecosystem. For more information, see [Microsoft Sentinel data lake (Preview)](graph/sentinel-lake-overview.md).
26+
Microsoft Sentinel is integrated with a modern data lake that offers affordable, long-term storage enabling teams to simplify data management, optimize costs, and accelerate the adoption of AI. The Microsoft Sentinel data lake (preview) enables a single-platform architecture for security data and empowers analysts with a unified query experience while leveraging Microsoft Sentinel’s rich connector ecosystem. For more information, see [Microsoft Sentinel data lake (preview)](graph/sentinel-lake-overview.md).
2727

2828
## Microsoft security service integrations
2929

articles/sentinel/billing-reduce-costs.md

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -53,8 +53,7 @@ Microsoft Sentinel analyzes all the data ingested into Microsoft Sentinel-enable
5353

5454
While the analytics tier is most appropriate for continuous, real-time threat detection, the Microsoft Sentinel data lake is well-suited for query and analytics of secondary security data that is not needed for real time threat detection. Microsoft Sentinel data lake offers ingestion and storage at a significantly reduced cost. For more information, see [Microsoft Sentinel Pricing](https://azure.microsoft.com/pricing/details/microsoft-sentinel/).
5555

56-
>[!NOTE]
57-
>The Microsoft Sentinel data lake is currently in Public Preview.
56+
[!INCLUDE [sentinel-lake-preview](includes/sentinel-lake-preview.md)]
5857

5958
## Optimize Log Analytics costs with dedicated clusters
6059

articles/sentinel/billing.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,7 @@ This article is part of the [Deployment guide for Microsoft Sentinel](deploy-ove
3333

3434
Enable Microsoft Sentinel on an Azure Monitor Log Analytics workspace and the first 10 GB/day ingested using the Analytics logs plan is free for 31 days. The cost for both Log Analytics data ingestion and Microsoft Sentinel analysis charges up to the 10 GB/day limit, are waived during the 31-day trial period. This free trial is subject to a 20 workspace limit per Azure tenant.
3535

36-
See [Microsoft Sentinel pricing](https://azure.microsoft.com/pricing/details/azure-sentinel) page for information on how usage beyond these limits is charged. Charges related to extra capabilities for [automation](automation.md) and [bring your own machine learning](bring-your-own-ml.md) are still applicable during the free trial, as well as any Microsoft Sentinel data lake related charges.
36+
See the [Microsoft Sentinel pricing](https://azure.microsoft.com/pricing/details/azure-sentinel) page for information on how usage beyond these limits is charged. Charges related to extra capabilities for [automation](automation.md) and [bring your own machine learning](bring-your-own-ml.md) are still applicable during the free trial, as well as any Microsoft Sentinel data lake related charges.
3737

3838
During your free trial, find resources for cost management, training, and more on the [**News & guides > Free trial**](https://portal.azure.com/#view/Microsoft_Azure_Security_Insights/MainMenuBlade/~/NewsAndGuides) tab in Microsoft Sentinel on the Azure portal. This tab also displays details about the dates of your free trial, and how many days left until the trial expires.
3939

@@ -78,7 +78,7 @@ The data lake tier incurs charges based on usage of various data like capabiliti
7878
Once onboarded, usage from Microsoft Sentinel workspaces begins to be billed through the above described meters rather than existing long-term retention (formerly known as Archive), search or auxiliary logs ingestion meters.
7979

8080
>[!IMPORTANT]
81-
>While in Public Preview, once onboarded to the Microsoft Sentinel data lake, billing through new meters will be billed at the respective meters' list rate. Pricing from previous meters doesn't carry over. For more details on pricing, see [Microsoft Sentinel pricing](https://azure.microsoft.com/pricing/details/microsoft-sentinel/).
81+
>While in preview, once onboarded to the Microsoft Sentinel data lake, billing through new meters is billed at the respective meters' list rate. Pricing from previous meters doesn't carry over. For more details on pricing, see [Microsoft Sentinel pricing](https://azure.microsoft.com/pricing/details/microsoft-sentinel/).
8282
>Existing customers that are currently billed for Auxiliary logs ingestion, long-term retention and search, will see charges transition to the new data lake ingestion, data lake storage and data lake query meters respectively.
8383
8484
For customers that haven't onboarded to the Microsoft Sentinel data lake and are currently using Auxiliary or Basic logs, see [Manage data retention in a Log Analytics workspace](/azure/azure-monitor/logs/data-retention-archive) and [Azure Monitor pricing](https://azure.microsoft.com/pricing/details/monitor/) for relevant information.

articles/sentinel/configure-data-connector.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ ms.collection: usx-security
1717

1818
# Connect data sources to Microsoft Sentinel by using data connectors
1919

20-
Connect data sources to Microsoft Sentinel by installing and configuring data connectors. This article generally explains how to install data connectors available in the Microsoft Sentinel **Content hub** to ingest and analyze data for improved threat detection.
20+
To connect data sources to Microsoft Sentinel, you need to install and configure data connectors. This article generally explains how to install data connectors available in the Microsoft Sentinel **Content hub** to ingest and analyze data for improved threat detection.
2121

2222
- [Microsoft Sentinel data connectors](connect-data-sources.md)
2323
- [Find your Microsoft Sentinel data connector](data-connectors-reference.md)
@@ -58,7 +58,7 @@ After you or someone in your organization installs the solution that includes th
5858
- [Connect Microsoft Sentinel to Azure, Windows, Microsoft, and Amazon services](connect-azure-windows-microsoft-services.md)
5959
- [Data connector prerequisites](data-connectors-reference.md#windows-security-events-via-ama)
6060

61-
### Configure data retention and tiering.
61+
### Configure data retention and tiering
6262

6363
If you have onboarded to the Microsoft Sentinel data lake (preview), you can configure data retention and tiering for the data connector. The data lake consists of an analytics tier - your current Microsoft Sentinel workspaces, and a data lake tier where you can store data for up to 12 years. For more information on onboarding, see [Onboarding to Microsoft Sentinel data lake](graph/sentinel-lake-onboarding.md).
6464

articles/sentinel/graph/kql-jobs.md

Lines changed: 6 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ author: EdB-MSFT
66
ms.service: microsoft-sentinel
77
ms.topic: conceptual
88
ms.subservice: sentinel-graph
9-
ms.date: 07/09/2025
9+
ms.date: 07/15/2025
1010
ms.author: edbaynash
1111

1212
ms.collection: ms-security
@@ -19,7 +19,7 @@ ms.collection: ms-security
1919
# Create KQL jobs in the Microsoft Sentinel data lake (preview)
2020

2121

22-
A job is a one-time or scheduled task that runs a KQL (Kusto Query Language) query against the data in the lake tier to promote the results to the analytics tier. Once in the analytics tier, use the advanced hunting KQL editor to query the data. Promoting data to the analytics tier has the following benefits:
22+
A job is a one-time or repeatedly scheduled task that runs a KQL (Kusto Query Language) query against the data in the data lake tier to promote the results to the analytics tier. Once in the analytics tier, use the advanced hunting KQL editor to query the data. Promoting data to the analytics tier has the following benefits:
2323

2424
+ Combine current and historical data in the analytics tier to run advanced analytics and machine learning models on your data.
2525

@@ -32,9 +32,6 @@ A job is a one-time or scheduled task that runs a KQL (Kusto Query Language) que
3232
3333
When promoting data to the analytics tier, make sure that the destination workspace is visible in the advanced hunting query editor. You can only query connected workspaces in the advanced hunting query editor. You will not be able to see data promoted to workspaces that aren't connected or to the default workspace in advance hunting. For more information on connected workspaces, see [Connect a workspace](/defender-xdr/advanced-hunting-microsoft-defender#connect-a-workspace). You can promote data to a new table or append the results to an existing table in the analytics tier. When creating a new table, the table name is suffixed with *_KQL_CL* to indicate that the table was created by a KQL job.
3434

35-
36-
You can create a job by selecting the **Create job** button a KQL query tab or directly from the **Jobs** management page or by. For more information on the Jobs management page, see [Manage jobs in the Microsoft Sentinel data lake](kql-manage-jobs.md).
37-
3835
## Prerequisites
3936

4037
The following prerequisites are required to create and manage KQL jobs in the Microsoft Sentinel data lake.
@@ -85,7 +82,7 @@ You can create and manage jobs from the **Jobs** management page under **Data la
8582
1. To append to an existing table, select **Add to an existing table** and select the table name form the drop-down list. When adding to an existing table, the query results must match the schema of the existing table.
8683

8784
1. Select **Next**.
88-
:::image type="content" source="media/kql-jobs/enter-job-name-details.png" alt-text="A screenshot showing the new job details page." lightbox="media/kql-jobs/enter-job-name-details.png":::
85+
:::image type="content" source="media/kql-jobs/enter-job-details.png" alt-text="A screenshot showing the new job details page." lightbox="media/kql-jobs/enter-job-details.png":::
8986

9087
1. Review or write your query in the Review the query panel. Check that the time picker is set to the required time range for the job if the date range isn't specified in the query.
9188
1. Select the workspace to run the query against from the **Selected workspace** drop-down.
@@ -96,7 +93,7 @@ You can create and manage jobs from the **Jobs** management page under **Data la
9693

9794
:::image type="content" source="media/kql-jobs/review-query.png" alt-text="A screenshot showing the review query panel." lightbox="media/kql-jobs/review-query.png":::
9895

99-
In the **Schedule the query job** panel, select whether you want to run the job once or on a schedule. If you select **One time**, the job runs as soon as the job definition is complete. If you select **Schedule**, you can specify a date and time for the job to run, or run the job on a recurring schedule.
96+
In the **Schedule the query job** panel, select whether you want to run the job once or on a schedule. If you select **One time**, the job runs as soon as the job definition is complete. If you select **Schedule**, you can specify a date and time for the job to run, or run the job on a recurring schedule.
10097

10198
1. Select **One time** or **Scheduled job**.
10299
>[!NOTE]
@@ -150,6 +147,8 @@ For service limits, see [Microsoft Sentinel data lake (preview) service limits](
150147
> [!NOTE]
151148
> Partial results may be promoted if the job's query exceeds the one hour limit.
152149
150+
[!INCLUDE [limitations for KQL jobs](../includes/service-limits-kql-jobs.md)]
151+
153152
For troubleshooting tips and error messages, see [Troubleshooting KQL queries for the Microsoft Sentinel data lake (preview)](kql-troubleshoot.md).
154153

155154

articles/sentinel/graph/kql-manage-jobs.md

Lines changed: 7 additions & 23 deletions
Original file line numberDiff line numberDiff line change
@@ -48,28 +48,12 @@ To create a job, select **Create new job**. For more information on creating job
4848

4949
### Job details
5050

51-
To see a job's details, select a job. The job detail panel opens, showing the following information:
52-
53-
- **Job name**: The name of the job.
54-
- **Job description**: A description of the job, providing context and purpose.
55-
- **Job type**: The type of job, either a KQL query job or a notebook job.
56-
- **Job status**: The status of the job, either enabled or disabled.
57-
- **Run status**: The status of the last run of the job. Status values are:
58-
- `Succeeded`
59-
- `Failed`
60-
- `In progress`
61-
- `Queued` - The job is queued and waiting to run when resources are available.
62-
- **Repeat frequency**: The frequency at which the job runs, such as daily, weekly, or monthly.
63-
- **Destination table**: The table in the analytics tier where the job results are written to.
64-
<!-- **Destination workspace**: The workspace in the analytics tier where the job results are written to -->
65-
- **Job start on (UTC)**: The date and time in UTC when the job is first scheduled to start.
66-
- **Target tier**: The destination tier of the job's results, such as data lake or analytics tier.
67-
- **Date range**: The date range set for the query.
68-
- **KQL query**: The KQL query that the job runs.
69-
70-
:::image type="content" source="media/kql-manage-jobs/manage-job-details.png" alt-text="A screenshot showing the job details page." lightbox="media/kql-manage-jobs/manage-job-details.png":::
71-
72-
Select the **Destination table** link to open the table in the KQL query editor in Advanced hunting. The query can be copied by selecting **Copy query**.
51+
To see a job's details, select the job from the table.
52+
53+
:::image type="content" source="media/kql-manage-jobs/manage-job-details.png" alt-text="A screenshot showing the job details page." lightbox="media/kql-manage-jobs/manage-job-details.png":::
54+
55+
Select the **Destination table** link to open the table in the KQL query editor in Advanced hunting.
56+
The query can be copied by selecting **Copy query**.
7357

7458
### Edit a job
7559

@@ -102,7 +86,7 @@ To delete a job, select **Delete** in the job details panel. A confirmation dia
10286

10387
## Considerations and limitations
10488

105-
For information on considerations and limitations when managing KQL jobs in the Microsoft Sentinel data lake, see [KQL jobs](kql-jobs.md#considerations-and-limitations).
89+
For information on considerations and limitations when managing KQL jobs in the Microsoft Sentinel data lake, see [KQL jobs](kql-jobs.md#considerations-and-limitations).
10690

10791
## Next steps
10892

0 commit comments

Comments
 (0)