Skip to content

Commit 36999b2

Browse files
authored
Revert "release-rsa-sentinel-platform -> main"
1 parent 13f4c0c commit 36999b2

77 files changed

Lines changed: 76 additions & 5161 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

articles/sentinel/TOC.yml

Lines changed: 6 additions & 41 deletions
Original file line numberDiff line numberDiff line change
@@ -598,37 +598,11 @@
598598
- name: Microsoft Sentinel data lake overview
599599
href: datalake/sentinel-lake-overview.md
600600
displayName: data lake
601-
- name: Data federation in the Microsoft Sentinel data lake
602-
items:
603-
- name: Overview
604-
href: datalake/data-federation-overview.md
605-
displayName: data lake
606-
- name: Set up federated tables
607-
href: datalake/data-federation-setup.md
608-
displayName: data lake
609-
- name: Using federated tables
610-
href: datalake/using-data-federation.md
611-
displayName: data lake
612-
- name: Microsoft Sentinel graph
613-
items:
614-
- name: Microsoft Sentinel graph overview
615-
href: datalake/sentinel-graph-overview.md
616-
- name: Graph visualization
617-
href: datalake/graph-visualization.md
618-
- name: Microsoft Sentinel custom graphs
619-
items:
620-
- name: Custom graphs overview
621-
href: datalake/custom-graphs-overview.md
622-
- name: Create custom graphs
623-
href: datalake/create-custom-graphs.md
624-
- name: Microsoft Sentinel graph provider reference
625-
href: datalake/sentinel-graph-provider-reference.md
626-
- name: Create custom graph using AI
627-
href: datalake/create-graphs-with-ai.md
628-
- name: GQL reference for Sentinel custom graph
629-
href: datalake/gql-reference-for-sentinel-custom-graph.md
630-
- name: Graph REST API
631-
href: datalake/graph-rest-api.md
601+
- name: Microsoft Sentinel graph overview
602+
href: datalake/sentinel-graph-overview.md
603+
- name: Compare KQL jobs, summary rules, and search jobs
604+
href: datalake/kql-jobs-summary-rules-search-jobs.md
605+
displayName: data lake
632606
- name: Microsoft Sentinel MCP server
633607
items:
634608
- name: Microsoft Sentinel MCP server overview
@@ -687,15 +661,9 @@
687661
- name: Manage KQL jobs
688662
href: datalake/kql-manage-jobs.md
689663
displayName: data lake
690-
- name: Compare KQL jobs, summary rules, and search jobs
691-
href: datalake/kql-jobs-summary-rules-search-jobs.md
692-
displayName: data lake
693664
- name: Troubleshoot KQL for the lake
694665
href: datalake/kql-troubleshoot.md
695666
displayName: data lake
696-
- name: Workbooks for Microsoft Sentinel data lake
697-
href: datalake/workbooks-for-data-lake.md
698-
displayName: data lake
699667
- name: Notebooks for data lake exploration
700668
items:
701669
- name: Overview
@@ -714,6 +682,7 @@
714682
href: datalake/notebook-examples.md
715683
- name: Microsoft Sentinel data lake service limits
716684
href: datalake/sentinel-lake-service-limits.md
685+
717686
- name: Collect and manage data
718687
items:
719688
- name: Overview
@@ -851,8 +820,6 @@
851820
- name: Manage tables, tiers, and retention
852821
href: manage-table-tiers-retention.md
853822
displayName: table management, tiers, retention, tables
854-
- name: Data transformation using filter and split
855-
href: transformation-filter-split.md
856823

857824
- name: SOC optimizations
858825
items:
@@ -997,8 +964,6 @@
997964
href: ../role-based-access-control/built-in-roles.md
998965
- name: Microsoft Sentinel roles
999966
href: ../role-based-access-control/built-in-roles.md#security
1000-
- name: Configure Microsoft Sentinel scoping (row-level RBAC)
1001-
href: scoping.md
1002967
- name: Advanced Security Information Model (ASIM)
1003968
items:
1004969
- name: ASIM content

articles/sentinel/billing-monitor-costs.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -60,7 +60,7 @@ You could also apply further controls. For example, to view only the costs assoc
6060

6161
Microsoft Sentinel analytics tier data ingestion volumes appear under **Security Insights** in some portal Usage Charts.
6262

63-
The Microsoft Sentinel classic pricing tiers don't include Log Analytics charges, so you might see those charges billed separately. Microsoft Sentinel simplified pricing combines the two costs into one set of tiers. To learn more about Microsoft Sentinel's pricing tiers, see [Understand the full billing model for Microsoft Sentinel](billing.md#understand-the-full-billing-model-for-microsoft-sentinel).
63+
The Microsoft Sentinel classic pricing tiers don't include Log Analytics charges, so you might see those charges billed separately. Microsoft Sentinel simplified pricing combines the two costs into one set of tiers. To learn more about Microsoft Sentinel's simplified pricing tiers, see [Simplified pricing tiers](billing.md#simplified-pricing-tiers).
6464

6565
For more information on reducing costs, see [Create budgets](#create-budgets) and [Reduce costs in Microsoft Sentinel](billing-monitor-costs.md).
6666

articles/sentinel/billing-reduce-costs.md

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Learn how to reduce costs for Microsoft Sentinel by using different
44
author: EdB-MSFT
55
ms.author: edbaynash
66
ms.custom: subject-cost-optimization
7-
ms.topic: conceptual
7+
ms.topic: how-to
88
ms.date: 06/14/2025
99
appliesto:
1010
- Microsoft Sentinel in the Microsoft Defender portal
@@ -23,7 +23,6 @@ Costs for Microsoft Sentinel are only a portion of the monthly costs in your Azu
2323
[!INCLUDE [unified-soc-preview](includes/unified-soc-preview.md)]
2424

2525
## Set or change pricing tier
26-
2726
To optimize for highest savings, monitor your ingestion volume to ensure you have the commitment tier that aligns most closely with your ingestion volume patterns. Consider increasing or decreasing your commitment tier to align with changing data volumes.
2827

2928
You can increase your commitment tier anytime, which restarts the 31-day commitment period. However, to move back to pay-as-you-go or to a lower commitment tier, you must wait until after the 31-day commitment period finishes. Billing for commitment tiers is on a daily basis.
@@ -36,7 +35,7 @@ To change your pricing tier commitment, select one of the other tiers on the pri
3635

3736
To learn more about how to monitor your costs, see [Manage and monitor costs for Microsoft Sentinel](billing-monitor-costs.md).
3837

39-
For workspaces still using classic pricing tiers, the Microsoft Sentinel pricing tiers don't include Log Analytics charges. For more information, see [Understand the full billing model for Microsoft Sentinel](billing.md#understand-the-full-billing-model-for-microsoft-sentinel).
38+
For workspaces still using classic pricing tiers, the Microsoft Sentinel pricing tiers don't include Log Analytics charges. For more information, see [Simplified pricing tiers](billing.md#simplified-pricing-tiers).
4039

4140
## Buy a pre-purchase plan
4241

articles/sentinel/billing.md

Lines changed: 34 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ description: Learn how to plan your Microsoft Sentinel costs, and understand pri
55
author: EdB-MSFT
66
ms.author: edbaynash
77
ms.topic: concept-article
8-
ms.date: 03/11/2026
8+
ms.date: 09/11/2025
99
ms.collection: usx-security
1010
appliesto:
1111
- Microsoft Sentinel in the Microsoft Defender portal
@@ -16,10 +16,13 @@ ms.custom:
1616

1717

1818
#Customer intent: As a SOC manager, I want to understand Microsoft Sentinel's pricing and billing models so that I can optimize costs and accurately forecast expenses.
19+
1920
---
2021

2122
# Plan costs and understand Microsoft Sentinel pricing and billing
2223

24+
As you plan your Microsoft Sentinel deployment, you typically want to understand its pricing and billing models to optimize your costs. Microsoft Sentinel's security analytics data is stored in an Azure Monitor Log Analytics workspace. Billing is based on the volume of data *analyzed* in Microsoft Sentinel and *stored* in the Log Analytics workspace. The cost of both is combined in a simplified pricing tier. Learn more about the [simplified pricing tiers](#simplified-pricing-tiers) or learn more about [Microsoft Sentinel pricing](https://azure.microsoft.com/pricing/details/microsoft-sentinel/) in general.
25+
2326
To help estimate your Microsoft Sentinel expected costs, [contact a Security sales specialist](https://info.microsoft.com/ww-landing-microsoft-defender-contact-me.html) for more information on pricing or to request a quote.
2427

2528
Costs for Microsoft Sentinel are only a portion of the monthly costs in your Azure bill. Although this article explains how to plan costs and understand the billing for Microsoft Sentinel, you're billed for all Azure services and resources your Azure subscription uses, including Partner services.
@@ -58,37 +61,52 @@ There are two ways to pay for the analytics tier: **pay-as-you-go** and **commit
5861

5962
Increase your Commitment tier anytime to optimize costs as your data volume increases. Lowering the Commitment tier is only allowed every 31 days. To see your current Microsoft Sentinel pricing tier, select **Settings** in Microsoft Sentinel, and then select the **Pricing** tab. Your current pricing tier is marked as **Current tier**.
6063

61-
To set and change your Commitment tier, see [Set or change pricing tier](billing-reduce-costs.md#set-or-change-pricing-tier). Switch any workspaces older than July 2023 to the simplified pricing tiers experience to unify billing meters. Or, continue to use the classic pricing tiers that separate out the Log Analytics pricing from the classic Microsoft Sentinel classic pricing.
64+
To set and change your Commitment tier, see [Set or change pricing tier](billing-reduce-costs.md#set-or-change-pricing-tier). Switch any workspaces older than July 2023 to the simplified pricing tiers experience to unify billing meters. Or, continue to use the classic pricing tiers that separate out the Log Analytics pricing from the classic Microsoft Sentinel classic pricing. For more information, see [simplified pricing tiers](#simplified-pricing-tiers).
6265

6366
<a name=auxiliary-logs-and-basic-logs></a>
6467

6568
#### Data lake tier
6669

6770
To learn more about the Microsoft Sentinel data lake, see [Microsoft Sentinel data lake](datalake/sentinel-lake-overview.md).
6871

69-
The data lake tier incurs charges based on usage of various data lake capabilities.
70-
72+
The data lake tier incurs charges based on usage of various data lake capabilities.
7173
- **Data lake ingestion** is charged per GB for all data ingested into tables with retention set to data lake tier only. Data lake ingestion charges don't apply when data is ingested into tables with retention set to include both analytic and data lake tiers.
7274
- **Data processing** is charged per GB for data ingested into tables with retention set to data lake tier only. It supports transformations like redaction, splitting, filtering, and normalization. Data processing charges don't apply when data is ingested into tables with retention set to include both analytic and data lake tiers.
7375
- **Data lake storage** charges are applied per GB per month for any data that remains in the data lake tier after the analytic tier retention period ends. Charges are based on a simple and uniform data compression rate of 6:1. For example, if you retain 600 GB of raw data, it's billed as 100 GB of compressed data.
74-
- **Data lake query** charges apply per compute hour used when using within notebook sessions, running notebook jobs, or building nodes and edges for custom graphs. Compute hours are calculated by multiplying the number of cores in the pool selected for the notebook with the amount of time a session was active or a job was running. Data lake notebook sessions and jobs are available in pools of four12, 32, and 80 vCores.
76+
- **Data lake query** charges apply per GB of uncompressed data analyzed using Kusto Query Language (KQL) queries or KQL jobs.
77+
- **Advanced data insights** charges apply per compute hour used when using data lake exploration notebook sessions or running data lake exploration notebook jobs. Compute hours are calculated by multiplying the number of cores in the pool selected for the notebook with the amount of time a session was active or a job was running. Data lake notebook sessions and jobs are available in pools of four, eight, and 16 cores.
7578

7679
Once onboarded, usage from Microsoft Sentinel workspaces begins to be billed through the previously described meters rather than existing long-term retention (formerly known as Archive), search, or auxiliary logs ingestion meters.
7780

81+
> [!IMPORTANT]
82+
> Existing Microsoft Sentinel customers currently using and billed for auxiliary logs ingestion, long-term retention, and search will see charges transition to the new data lake ingestion, data lake storage, and data lake query meters respectively, once they onboard to Microsoft Sentinel data lake. Pricing from previous meters doesn't carry over. For more information on pricing, see [Microsoft Sentinel pricing](https://azure.microsoft.com/pricing/details/microsoft-sentinel/).
83+
84+
For customers that haven't onboarded to Microsoft Sentinel data lake and are currently using auxiliary or basic logs, see [Manage data retention in a Log Analytics workspace](/azure/azure-monitor/logs/data-retention-archive) and [Azure Monitor pricing](https://azure.microsoft.com/pricing/details/monitor/) for relevant information.
85+
86+
### Simplified pricing tiers
87+
88+
Simplified pricing tiers combine the data analysis costs for Microsoft Sentinel and ingestion storage costs of Log Analytics into a single pricing tier. The following screenshot shows the simplified pricing tier that all new workspaces use.
89+
90+
:::image type="content" source="media/billing/simplified-pricing-tier.png" alt-text="Screenshot shows simplified pricing tier." lightbox="media/billing/simplified-pricing-tier.png":::
91+
92+
Switch any workspace configured with classic pricing tiers to the simplified pricing tiers. For more information on how to **Switch to new pricing**, see [Enroll in a simplified pricing tier](enroll-simplified-pricing-tier.md).
93+
94+
Combining the pricing tiers offers a simplification to the overall billing and cost management experience. This includes visualization in the pricing page, and fewer steps estimating costs in the Azure calculator. To add further value to the new simplified tiers, the current Microsoft Defender for Servers P2 benefit granting 500 MB of security data ingestion into Log Analytics is extended to the simplified pricing tiers. This change greatly increases the financial benefit of bringing eligible data ingested into Microsoft Sentinel for each virtual machine (VM) protected in this manner. For more information, see [FAQ - Microsoft Defender for Servers P2 benefit granting 500 MB](/azure/defender-for-cloud/faq-defender-for-servers#is-the-500-mb-of-free-data-ingestion-allowance-applied-per-workspace-or-per-machine-).
95+
7896
### Understand your Microsoft Sentinel bill
7997

8098
Billable meters are the individual components of your service that appear on your bill and are shown in Microsoft Cost Management. At the end of your billing cycle, the charges for each meter are summed. Your bill or invoice shows a section for all Microsoft Sentinel costs. There's a separate line item for each meter.
8199

82100
To see your Azure bill, select **Cost Analysis** in the left navigation of **Cost Management**. On the **Cost analysis** screen, find and select the **Invoice details** from **All views**. To understand the access level required to view billing information, see [Manage access to billing information for Azure](/azure/cost-management-billing/manage/manage-billing-access).
83101

84-
The costs shown in the following image are for example purposes only. They're not intended to reflect actual costs. Starting July 1, 2023, legacy pricing tiers are prefixed with **Classic**.
102+
The costs shown in the following image are for example purposes only. They're not intended to reflect actual costs. Starting July 1, 2023, legacy pricing tiers are prefixed with **Classic**.
85103

86104
:::image type="content" source="media/billing/sample-bill-classic.png" alt-text="Screenshot showing the Microsoft Sentinel section of a sample Azure bill, to help you estimate costs." lightbox="media/billing/sample-bill-classic.png":::
87105

88-
Microsoft Sentinel and Log Analytics charges might appear on your Azure bill as separate line items based on your selected pricing plan. Simplified pricing tiers are represented as a single `sentinel` line item for the pricing tier. Ingestion and analysis are billed on a daily basis. If your workspace exceeds its Commitment tier usage allocation in any given day, the Azure bill shows one line item for the Commitment tier with its associated fixed cost, and a separate line item for the cost beyond the Commitment tier, billed at the same effective Commitment tier rate.
106+
Microsoft Sentinel and Log Analytics charges might appear on your Azure bill as separate line items based on your selected pricing plan. Simplified pricing tiers are represented as a single `sentinel` line item for the pricing tier. Ingestion and analysis are billed on a daily basis. If your workspace exceeds its Commitment tier usage allocation in any given day, the Azure bill shows one line item for the Commitment tier with its associated fixed cost, and a separate line item for the cost beyond the Commitment tier, billed at the same effective Commitment tier rate.
89107

90108
# [Simplified](#tab/simplified)
91-
The following tabs show how Microsoft Sentinel costs appear in the **Service name** and **Meter** columns of your Azure bill depending on your simplified pricing tier.
109+
The following tabs show how Microsoft Sentinel costs appear in the **Service name** and **Meter** columns of your Azure bill depending on your simplified pricing tier.
92110

93111
# [Classic](#tab/classic)
94112
The following tabs show how Microsoft Sentinel and Log Analytics costs appear in the **Service name** and **Meter** columns of your Azure bill depending on your classic pricing tier.
@@ -180,11 +198,11 @@ Any other services you use might have associated costs.
180198

181199
## Interactive and total data retention costs
182200

183-
After you enable Microsoft Sentinel on a Log Analytics workspace, consider these configuration options:
201+
After you enable Microsoft Sentinel on a Log Analytics workspace, consider these configuration options:
184202

185203
- Retain all data ingested into the workspace at no charge for the first 90 days. Retention beyond 90 days is charged per the standard [Log Analytics retention prices](https://azure.microsoft.com/pricing/details/monitor/).
186-
- Specify different retention settings for individual data types. Learn about [retention by data type](/azure/azure-monitor/logs/data-retention-configure#configure-table-level-retention).
187-
- Extend retention of data with total retention so you have access to historical logs. The Microsoft Sentinel data lake is a low-cost retention state for the preservation of data for such things as regulatory compliance. It's charged based on the volume of data stored and scanned. Use **Data management > Tables** to adjust the Analytics and Total retention period and learn more in [What is Microsoft Sentinel data lake?](datalake/sentinel-lake-overview.md)
204+
- Specify different retention settings for individual data types. Learn about [retention by data type](/azure/azure-monitor/logs/data-retention-configure#configure-table-level-retention).
205+
- Extend retention of data with total retention so you have access to historical logs. The Microsoft Sentinel data lake is a low-cost retention state for the preservation of data for such things as regulatory compliance. It's charged based on the volume of data stored and scanned. Use **Data management > Tables** to adjust the Analytics and Total retention period and learn more in [What is Microsoft Sentinel data lake?](datalake/sentinel-lake-overview.md)
188206
- Switch tables that contain secondary security data to **Lake tier**. This enables you to store high-volume, low-value logs at a low price, with querying capabilities built in. Use **Data management > Tables** to switch tables from **Analytics** to **Lake** tier.
189207

190208
## Other CEF ingestion costs
@@ -202,7 +220,7 @@ Removing Microsoft Sentinel doesn't remove the Log Analytics workspace Microsoft
202220
The following data sources are free with Microsoft Sentinel:
203221

204222
- Azure Activity Logs
205-
- Microsoft Sentinel Health
223+
- Microsoft Sentinel Health
206224
- Office 365 Audit Logs, including all SharePoint activity, Exchange admin activity, and Teams
207225
- Security alerts, including alerts from the following sources:
208226
- Microsoft Defender XDR
@@ -257,4 +275,7 @@ Learn more about how to [connect data sources](connect-data-sources.md), includi
257275

258276
## Next steps
259277

260-
[Deploy Microsoft Sentinel](deploy-overview.md)
278+
In this article, you learned how to plan costs and understand the billing for Microsoft Sentinel.
279+
280+
> [!div class="nextstepaction"]
281+
> >[Deploy Microsoft Sentinel](deploy-overview.md)

0 commit comments

Comments
 (0)