You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/datalake/enable-data-connectors.md
+9-11Lines changed: 9 additions & 11 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -6,34 +6,32 @@ author: mberdugo
6
6
ms.service: microsoft-sentinel
7
7
ms.topic: conceptual
8
8
ms.custom: sentinel-graph
9
-
ms.date: 06/11/2025
9
+
ms.date: 10/05/2025
10
10
ms.author: monaberdugo
11
11
12
12
ms.collection: ms-security
13
13
14
-
#Customer intent: As a Microsoft Sentinel user, I want to enable and manage data connectors in the Microsoft Sentinel data lake so that I can ingest and analyze security-related data from various sources.
14
+
#Customer intent: As a Microsoft Sentinel user, I want to understand the ingestion of asset data and analysis of security-related data from various sources.
15
15
---
16
16
17
-
# Enable asset data ingestion in the Microsoft Sentinel data lake
18
-
19
-
Asset data refers to structured information about digital or physical entities, such as devices, services, applications, or infrastructure components, that are relevant to an organization’s operations, security, or analytics. This article explains how to enable and manage asset data in Microsoft Sentinel's data lake.
17
+
# Asset data ingestion in the Microsoft Sentinel data lake
20
18
21
19
Asset data in cybersecurity refers to an organization’s physical and digital entities such as computers, identities, software, cloud services, and networks. It shows what exists so you know what must be protected. Microsoft Sentinel’s data lake adds powerful value by storing this asset data in a scalable, cost-efficient way that supports long-term retention, advanced analytics, and AI-driven threat detection. With unified visibility across systems and flexible data management, Sentinel lake helps security teams understand their environment, spot unusual activity, and respond to threats.
22
20
23
-
## Considerations for enabling asset data in Sentinel data lake
21
+
## How is asset data ingestion enabled in Sentinel data lake?
24
22
25
-
* When you onboard to Sentinel lake, asset data is automatically ingested if you have appropriate permissions (see[Required permissions for asset sources](#required-permissions-for-asset-sources)).
23
+
* When you onboard to Sentinel lake, asset data is automatically ingested if you have appropriate permissions. For more information, see[Required permissions for asset sources](#required-permissions-for-asset-sources).
26
24
27
-
* If you have insufficient permissions, asset tables are created but they will be empty. To ingest data, you need to enable connectors. To manually enable asset data ingestion:
25
+
* If you don't have sufficient permissions, asset tables are created but no data is ingested. Manually enable asset data ingestion as follows:
28
26
29
27
1. Go to the Microsoft Sentinel workspace in the Azure portal.
30
-
1. Navigate to the "Data connectors" page.
28
+
1. Navigate to the **Data connectors** page.
31
29
1. Find the relevant asset data source connector.
32
30
1. Select the connector and follow the prompts to enable ingestion.
33
31
34
-
* Asset data is ingested into the Microsoft Sentinel data lake tier only. After onboarding, asset dataIt can take up to 24 hours to arrive in the lake.
32
+
* Asset data is ingested into the Microsoft Sentinel data lake tier only. After onboarding, asset data, it can take up to 24 hours to arrive in the lake.
35
33
36
-
* Asset data is retained for 30 days by default. Retention can be expanded for up to 12 years.
34
+
* Asset data is retained for 30 days by default. Retention can be expanded for up to 12 years. For more information on managing table retention, see [Table Management documentation](../manage-table-tiers-retention.md).
Copy file name to clipboardExpand all lines: articles/sentinel/manage-table-tiers-retention.md
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,5 +1,5 @@
1
1
---
2
-
title: Configure table settings in Microsoft Sentinel (preview)
2
+
title: Configure table settings in Microsoft Sentinel
3
3
description: Configure Microsoft Sentinel and Defender XDR table settings in Microsoft Defender Portal to optimize security operations and cost efficiency.
4
4
ms.reviewer: dzatakovi
5
5
ms.author: guywild
@@ -9,7 +9,7 @@ ms.date: 07/13/2025
9
9
# Customer intent: As an IT administrator or subscription owner, I want to manage Microsoft Sentinel and Defender XDR table tiers and retention settings in Microsoft Defender Portal to optimize security operations needs and cost efficiency.
10
10
---
11
11
12
-
# Configure table settings in Microsoft Sentinel (preview)
12
+
# Configure table settings in Microsoft Sentinel
13
13
14
14
The Microsoft Defender portal provides a centralized experience for configuring table-level data retention and tier settings across Microsoft Sentinel and Microsoft Defender XDR. You can view and manage retention settings, switch between analytics and data lake tiers, and optimize data storage based on operational and cost requirements.
15
15
@@ -71,7 +71,7 @@ To view and manage table settings in the Microsoft Defender portal:
71
71
> [!NOTE]
72
72
> Tier changes aren't available for all tables. For example, XDR and Microsoft Sentinel solution tables must be available in the analytics tier because Microsoft security services require the data in these tables for near-real-time analytics.
73
73
74
-
For more information about retention and tier settings work, see [Manage data tiers and retention in Microsoft Sentinel (preview)](manage-data-overview.md).
74
+
For more information about retention and tier settings work, see [Manage data tiers and retention in Microsoft Sentinel](manage-data-overview.md).
75
75
76
76
1. Review warnings and messages. These messages help you understand important implications of changing table settings.
0 commit comments