Skip to content

Commit 1c22432

Browse files
authored
Merge pull request #313958 from MicrosoftDocs/release-rsa-sentinel-platform-2
release-rsa-sentinel-platform-2 -> main -- 04/01 - 01:00 AM (PDT)
2 parents 2a93f2c + e5c1081 commit 1c22432

77 files changed

Lines changed: 5161 additions & 76 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

articles/sentinel/TOC.yml

Lines changed: 41 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -598,11 +598,37 @@
598598
- name: Microsoft Sentinel data lake overview
599599
href: datalake/sentinel-lake-overview.md
600600
displayName: data lake
601-
- name: Microsoft Sentinel graph overview
602-
href: datalake/sentinel-graph-overview.md
603-
- name: Compare KQL jobs, summary rules, and search jobs
604-
href: datalake/kql-jobs-summary-rules-search-jobs.md
605-
displayName: data lake
601+
- name: Data federation in the Microsoft Sentinel data lake
602+
items:
603+
- name: Overview
604+
href: datalake/data-federation-overview.md
605+
displayName: data lake
606+
- name: Set up federated tables
607+
href: datalake/data-federation-setup.md
608+
displayName: data lake
609+
- name: Using federated tables
610+
href: datalake/using-data-federation.md
611+
displayName: data lake
612+
- name: Microsoft Sentinel graph
613+
items:
614+
- name: Microsoft Sentinel graph overview
615+
href: datalake/sentinel-graph-overview.md
616+
- name: Graph visualization
617+
href: datalake/graph-visualization.md
618+
- name: Microsoft Sentinel custom graphs
619+
items:
620+
- name: Custom graphs overview
621+
href: datalake/custom-graphs-overview.md
622+
- name: Create custom graphs
623+
href: datalake/create-custom-graphs.md
624+
- name: Microsoft Sentinel graph provider reference
625+
href: datalake/sentinel-graph-provider-reference.md
626+
- name: Create custom graph using AI
627+
href: datalake/create-graphs-with-ai.md
628+
- name: GQL reference for Sentinel custom graph
629+
href: datalake/gql-reference-for-sentinel-custom-graph.md
630+
- name: Graph REST API
631+
href: datalake/graph-rest-api.md
606632
- name: Microsoft Sentinel MCP server
607633
items:
608634
- name: Microsoft Sentinel MCP server overview
@@ -661,9 +687,15 @@
661687
- name: Manage KQL jobs
662688
href: datalake/kql-manage-jobs.md
663689
displayName: data lake
690+
- name: Compare KQL jobs, summary rules, and search jobs
691+
href: datalake/kql-jobs-summary-rules-search-jobs.md
692+
displayName: data lake
664693
- name: Troubleshoot KQL for the lake
665694
href: datalake/kql-troubleshoot.md
666695
displayName: data lake
696+
- name: Workbooks for Microsoft Sentinel data lake
697+
href: datalake/workbooks-for-data-lake.md
698+
displayName: data lake
667699
- name: Notebooks for data lake exploration
668700
items:
669701
- name: Overview
@@ -682,7 +714,6 @@
682714
href: datalake/notebook-examples.md
683715
- name: Microsoft Sentinel data lake service limits
684716
href: datalake/sentinel-lake-service-limits.md
685-
686717
- name: Collect and manage data
687718
items:
688719
- name: Overview
@@ -820,6 +851,8 @@
820851
- name: Manage tables, tiers, and retention
821852
href: manage-table-tiers-retention.md
822853
displayName: table management, tiers, retention, tables
854+
- name: Data transformation using filter and split
855+
href: transformation-filter-split.md
823856

824857
- name: SOC optimizations
825858
items:
@@ -964,6 +997,8 @@
964997
href: ../role-based-access-control/built-in-roles.md
965998
- name: Microsoft Sentinel roles
966999
href: ../role-based-access-control/built-in-roles.md#security
1000+
- name: Configure Microsoft Sentinel scoping (row-level RBAC)
1001+
href: scoping.md
9671002
- name: Advanced Security Information Model (ASIM)
9681003
items:
9691004
- name: ASIM content

articles/sentinel/billing-monitor-costs.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -60,7 +60,7 @@ You could also apply further controls. For example, to view only the costs assoc
6060

6161
Microsoft Sentinel analytics tier data ingestion volumes appear under **Security Insights** in some portal Usage Charts.
6262

63-
The Microsoft Sentinel classic pricing tiers don't include Log Analytics charges, so you might see those charges billed separately. Microsoft Sentinel simplified pricing combines the two costs into one set of tiers. To learn more about Microsoft Sentinel's simplified pricing tiers, see [Simplified pricing tiers](billing.md#simplified-pricing-tiers).
63+
The Microsoft Sentinel classic pricing tiers don't include Log Analytics charges, so you might see those charges billed separately. Microsoft Sentinel simplified pricing combines the two costs into one set of tiers. To learn more about Microsoft Sentinel's pricing tiers, see [Understand the full billing model for Microsoft Sentinel](billing.md#understand-the-full-billing-model-for-microsoft-sentinel).
6464

6565
For more information on reducing costs, see [Create budgets](#create-budgets) and [Reduce costs in Microsoft Sentinel](billing-monitor-costs.md).
6666

articles/sentinel/billing-reduce-costs.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Learn how to reduce costs for Microsoft Sentinel by using different
44
author: EdB-MSFT
55
ms.author: edbaynash
66
ms.custom: subject-cost-optimization
7-
ms.topic: how-to
7+
ms.topic: conceptual
88
ms.date: 06/14/2025
99
appliesto:
1010
- Microsoft Sentinel in the Microsoft Defender portal
@@ -23,6 +23,7 @@ Costs for Microsoft Sentinel are only a portion of the monthly costs in your Azu
2323
[!INCLUDE [unified-soc-preview](includes/unified-soc-preview.md)]
2424

2525
## Set or change pricing tier
26+
2627
To optimize for highest savings, monitor your ingestion volume to ensure you have the commitment tier that aligns most closely with your ingestion volume patterns. Consider increasing or decreasing your commitment tier to align with changing data volumes.
2728

2829
You can increase your commitment tier anytime, which restarts the 31-day commitment period. However, to move back to pay-as-you-go or to a lower commitment tier, you must wait until after the 31-day commitment period finishes. Billing for commitment tiers is on a daily basis.
@@ -35,7 +36,7 @@ To change your pricing tier commitment, select one of the other tiers on the pri
3536

3637
To learn more about how to monitor your costs, see [Manage and monitor costs for Microsoft Sentinel](billing-monitor-costs.md).
3738

38-
For workspaces still using classic pricing tiers, the Microsoft Sentinel pricing tiers don't include Log Analytics charges. For more information, see [Simplified pricing tiers](billing.md#simplified-pricing-tiers).
39+
For workspaces still using classic pricing tiers, the Microsoft Sentinel pricing tiers don't include Log Analytics charges. For more information, see [Understand the full billing model for Microsoft Sentinel](billing.md#understand-the-full-billing-model-for-microsoft-sentinel).
3940

4041
## Buy a pre-purchase plan
4142

articles/sentinel/billing.md

Lines changed: 13 additions & 34 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ description: Learn how to plan your Microsoft Sentinel costs, and understand pri
55
author: EdB-MSFT
66
ms.author: edbaynash
77
ms.topic: concept-article
8-
ms.date: 09/11/2025
8+
ms.date: 03/11/2026
99
ms.collection: usx-security
1010
appliesto:
1111
- Microsoft Sentinel in the Microsoft Defender portal
@@ -16,13 +16,10 @@ ms.custom:
1616

1717

1818
#Customer intent: As a SOC manager, I want to understand Microsoft Sentinel's pricing and billing models so that I can optimize costs and accurately forecast expenses.
19-
2019
---
2120

2221
# Plan costs and understand Microsoft Sentinel pricing and billing
2322

24-
As you plan your Microsoft Sentinel deployment, you typically want to understand its pricing and billing models to optimize your costs. Microsoft Sentinel's security analytics data is stored in an Azure Monitor Log Analytics workspace. Billing is based on the volume of data *analyzed* in Microsoft Sentinel and *stored* in the Log Analytics workspace. The cost of both is combined in a simplified pricing tier. Learn more about the [simplified pricing tiers](#simplified-pricing-tiers) or learn more about [Microsoft Sentinel pricing](https://azure.microsoft.com/pricing/details/microsoft-sentinel/) in general.
25-
2623
To help estimate your Microsoft Sentinel expected costs, [contact a Security sales specialist](https://info.microsoft.com/ww-landing-microsoft-defender-contact-me.html) for more information on pricing or to request a quote.
2724

2825
Costs for Microsoft Sentinel are only a portion of the monthly costs in your Azure bill. Although this article explains how to plan costs and understand the billing for Microsoft Sentinel, you're billed for all Azure services and resources your Azure subscription uses, including Partner services.
@@ -61,52 +58,37 @@ There are two ways to pay for the analytics tier: **pay-as-you-go** and **commit
6158

6259
Increase your Commitment tier anytime to optimize costs as your data volume increases. Lowering the Commitment tier is only allowed every 31 days. To see your current Microsoft Sentinel pricing tier, select **Settings** in Microsoft Sentinel, and then select the **Pricing** tab. Your current pricing tier is marked as **Current tier**.
6360

64-
To set and change your Commitment tier, see [Set or change pricing tier](billing-reduce-costs.md#set-or-change-pricing-tier). Switch any workspaces older than July 2023 to the simplified pricing tiers experience to unify billing meters. Or, continue to use the classic pricing tiers that separate out the Log Analytics pricing from the classic Microsoft Sentinel classic pricing. For more information, see [simplified pricing tiers](#simplified-pricing-tiers).
61+
To set and change your Commitment tier, see [Set or change pricing tier](billing-reduce-costs.md#set-or-change-pricing-tier). Switch any workspaces older than July 2023 to the simplified pricing tiers experience to unify billing meters. Or, continue to use the classic pricing tiers that separate out the Log Analytics pricing from the classic Microsoft Sentinel classic pricing.
6562

6663
<a name=auxiliary-logs-and-basic-logs></a>
6764

6865
#### Data lake tier
6966

7067
To learn more about the Microsoft Sentinel data lake, see [Microsoft Sentinel data lake](datalake/sentinel-lake-overview.md).
7168

72-
The data lake tier incurs charges based on usage of various data lake capabilities.
69+
The data lake tier incurs charges based on usage of various data lake capabilities.
70+
7371
- **Data lake ingestion** is charged per GB for all data ingested into tables with retention set to data lake tier only. Data lake ingestion charges don't apply when data is ingested into tables with retention set to include both analytic and data lake tiers.
7472
- **Data processing** is charged per GB for data ingested into tables with retention set to data lake tier only. It supports transformations like redaction, splitting, filtering, and normalization. Data processing charges don't apply when data is ingested into tables with retention set to include both analytic and data lake tiers.
7573
- **Data lake storage** charges are applied per GB per month for any data that remains in the data lake tier after the analytic tier retention period ends. Charges are based on a simple and uniform data compression rate of 6:1. For example, if you retain 600 GB of raw data, it's billed as 100 GB of compressed data.
76-
- **Data lake query** charges apply per GB of uncompressed data analyzed using Kusto Query Language (KQL) queries or KQL jobs.
77-
- **Advanced data insights** charges apply per compute hour used when using data lake exploration notebook sessions or running data lake exploration notebook jobs. Compute hours are calculated by multiplying the number of cores in the pool selected for the notebook with the amount of time a session was active or a job was running. Data lake notebook sessions and jobs are available in pools of four, eight, and 16 cores.
74+
- **Data lake query** charges apply per compute hour used when using within notebook sessions, running notebook jobs, or building nodes and edges for custom graphs. Compute hours are calculated by multiplying the number of cores in the pool selected for the notebook with the amount of time a session was active or a job was running. Data lake notebook sessions and jobs are available in pools of four12, 32, and 80 vCores.
7875

7976
Once onboarded, usage from Microsoft Sentinel workspaces begins to be billed through the previously described meters rather than existing long-term retention (formerly known as Archive), search, or auxiliary logs ingestion meters.
8077

81-
> [!IMPORTANT]
82-
> Existing Microsoft Sentinel customers currently using and billed for auxiliary logs ingestion, long-term retention, and search will see charges transition to the new data lake ingestion, data lake storage, and data lake query meters respectively, once they onboard to Microsoft Sentinel data lake. Pricing from previous meters doesn't carry over. For more information on pricing, see [Microsoft Sentinel pricing](https://azure.microsoft.com/pricing/details/microsoft-sentinel/).
83-
84-
For customers that haven't onboarded to Microsoft Sentinel data lake and are currently using auxiliary or basic logs, see [Manage data retention in a Log Analytics workspace](/azure/azure-monitor/logs/data-retention-archive) and [Azure Monitor pricing](https://azure.microsoft.com/pricing/details/monitor/) for relevant information.
85-
86-
### Simplified pricing tiers
87-
88-
Simplified pricing tiers combine the data analysis costs for Microsoft Sentinel and ingestion storage costs of Log Analytics into a single pricing tier. The following screenshot shows the simplified pricing tier that all new workspaces use.
89-
90-
:::image type="content" source="media/billing/simplified-pricing-tier.png" alt-text="Screenshot shows simplified pricing tier." lightbox="media/billing/simplified-pricing-tier.png":::
91-
92-
Switch any workspace configured with classic pricing tiers to the simplified pricing tiers. For more information on how to **Switch to new pricing**, see [Enroll in a simplified pricing tier](enroll-simplified-pricing-tier.md).
93-
94-
Combining the pricing tiers offers a simplification to the overall billing and cost management experience. This includes visualization in the pricing page, and fewer steps estimating costs in the Azure calculator. To add further value to the new simplified tiers, the current Microsoft Defender for Servers P2 benefit granting 500 MB of security data ingestion into Log Analytics is extended to the simplified pricing tiers. This change greatly increases the financial benefit of bringing eligible data ingested into Microsoft Sentinel for each virtual machine (VM) protected in this manner. For more information, see [FAQ - Microsoft Defender for Servers P2 benefit granting 500 MB](/azure/defender-for-cloud/faq-defender-for-servers#is-the-500-mb-of-free-data-ingestion-allowance-applied-per-workspace-or-per-machine-).
95-
9678
### Understand your Microsoft Sentinel bill
9779

9880
Billable meters are the individual components of your service that appear on your bill and are shown in Microsoft Cost Management. At the end of your billing cycle, the charges for each meter are summed. Your bill or invoice shows a section for all Microsoft Sentinel costs. There's a separate line item for each meter.
9981

10082
To see your Azure bill, select **Cost Analysis** in the left navigation of **Cost Management**. On the **Cost analysis** screen, find and select the **Invoice details** from **All views**. To understand the access level required to view billing information, see [Manage access to billing information for Azure](/azure/cost-management-billing/manage/manage-billing-access).
10183

102-
The costs shown in the following image are for example purposes only. They're not intended to reflect actual costs. Starting July 1, 2023, legacy pricing tiers are prefixed with **Classic**.
84+
The costs shown in the following image are for example purposes only. They're not intended to reflect actual costs. Starting July 1, 2023, legacy pricing tiers are prefixed with **Classic**.
10385

10486
:::image type="content" source="media/billing/sample-bill-classic.png" alt-text="Screenshot showing the Microsoft Sentinel section of a sample Azure bill, to help you estimate costs." lightbox="media/billing/sample-bill-classic.png":::
10587

106-
Microsoft Sentinel and Log Analytics charges might appear on your Azure bill as separate line items based on your selected pricing plan. Simplified pricing tiers are represented as a single `sentinel` line item for the pricing tier. Ingestion and analysis are billed on a daily basis. If your workspace exceeds its Commitment tier usage allocation in any given day, the Azure bill shows one line item for the Commitment tier with its associated fixed cost, and a separate line item for the cost beyond the Commitment tier, billed at the same effective Commitment tier rate.
88+
Microsoft Sentinel and Log Analytics charges might appear on your Azure bill as separate line items based on your selected pricing plan. Simplified pricing tiers are represented as a single `sentinel` line item for the pricing tier. Ingestion and analysis are billed on a daily basis. If your workspace exceeds its Commitment tier usage allocation in any given day, the Azure bill shows one line item for the Commitment tier with its associated fixed cost, and a separate line item for the cost beyond the Commitment tier, billed at the same effective Commitment tier rate.
10789

10890
# [Simplified](#tab/simplified)
109-
The following tabs show how Microsoft Sentinel costs appear in the **Service name** and **Meter** columns of your Azure bill depending on your simplified pricing tier.
91+
The following tabs show how Microsoft Sentinel costs appear in the **Service name** and **Meter** columns of your Azure bill depending on your simplified pricing tier.
11092

11193
# [Classic](#tab/classic)
11294
The following tabs show how Microsoft Sentinel and Log Analytics costs appear in the **Service name** and **Meter** columns of your Azure bill depending on your classic pricing tier.
@@ -198,11 +180,11 @@ Any other services you use might have associated costs.
198180

199181
## Interactive and total data retention costs
200182

201-
After you enable Microsoft Sentinel on a Log Analytics workspace, consider these configuration options:
183+
After you enable Microsoft Sentinel on a Log Analytics workspace, consider these configuration options:
202184

203185
- Retain all data ingested into the workspace at no charge for the first 90 days. Retention beyond 90 days is charged per the standard [Log Analytics retention prices](https://azure.microsoft.com/pricing/details/monitor/).
204-
- Specify different retention settings for individual data types. Learn about [retention by data type](/azure/azure-monitor/logs/data-retention-configure#configure-table-level-retention).
205-
- Extend retention of data with total retention so you have access to historical logs. The Microsoft Sentinel data lake is a low-cost retention state for the preservation of data for such things as regulatory compliance. It's charged based on the volume of data stored and scanned. Use **Data management > Tables** to adjust the Analytics and Total retention period and learn more in [What is Microsoft Sentinel data lake?](datalake/sentinel-lake-overview.md)
186+
- Specify different retention settings for individual data types. Learn about [retention by data type](/azure/azure-monitor/logs/data-retention-configure#configure-table-level-retention).
187+
- Extend retention of data with total retention so you have access to historical logs. The Microsoft Sentinel data lake is a low-cost retention state for the preservation of data for such things as regulatory compliance. It's charged based on the volume of data stored and scanned. Use **Data management > Tables** to adjust the Analytics and Total retention period and learn more in [What is Microsoft Sentinel data lake?](datalake/sentinel-lake-overview.md)
206188
- Switch tables that contain secondary security data to **Lake tier**. This enables you to store high-volume, low-value logs at a low price, with querying capabilities built in. Use **Data management > Tables** to switch tables from **Analytics** to **Lake** tier.
207189

208190
## Other CEF ingestion costs
@@ -220,7 +202,7 @@ Removing Microsoft Sentinel doesn't remove the Log Analytics workspace Microsoft
220202
The following data sources are free with Microsoft Sentinel:
221203

222204
- Azure Activity Logs
223-
- Microsoft Sentinel Health
205+
- Microsoft Sentinel Health
224206
- Office 365 Audit Logs, including all SharePoint activity, Exchange admin activity, and Teams
225207
- Security alerts, including alerts from the following sources:
226208
- Microsoft Defender XDR
@@ -275,7 +257,4 @@ Learn more about how to [connect data sources](connect-data-sources.md), includi
275257

276258
## Next steps
277259

278-
In this article, you learned how to plan costs and understand the billing for Microsoft Sentinel.
279-
280-
> [!div class="nextstepaction"]
281-
> >[Deploy Microsoft Sentinel](deploy-overview.md)
260+
[Deploy Microsoft Sentinel](deploy-overview.md)

0 commit comments

Comments
 (0)