Skip to content

Commit db9cbe8

Browse files
authored
Clarify billing for entity analyzer tool
Updated the entity analyzer tool section to clarify billing details and removed the mention of the preview status.
1 parent 3ed6355 commit db9cbe8

1 file changed

Lines changed: 3 additions & 3 deletions

File tree

articles/sentinel/datalake/sentinel-mcp-billing.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -27,8 +27,8 @@ This article provides information on pricing, limits, and availability when sett
2727
Microsoft Sentinel pricing is based on the tier that you ingest data into. The **data lake tier** is a cost-effective option for ingesting secondary security data and querying security data over the long term. In this tier, Microsoft Sentinel's unified MCP server interface is offered **at no extra cost**. You pay for invoking tools that search and retrieve data by using Kusto Query Language (KQL) queries from Microsoft Sentinel data lake. With Microsoft Sentinel data lake's billing model, you pay as you go for queries that retrieve data. [Read more about Microsoft Sentinel data lake’s pricing here](../billing.md#data-lake-tier).
2828

2929
### Microsoft Sentinel entity analyzer tool
30-
You pay for the KQL queries the [entity analyzer](sentinel-mcp-data-exploration-tool.md#entity-analyzer-preview)
31-
performs over the Microsoft Sentinel data lake. AI compute used by the analyzer to reason over this data doesn't incur any cost while this tool is in preview. When the entity analyzer becomes generally available, you get charged for the Security Compute Units (SCUs) required to deliver the reasoned entity risk analysis based on prevalence, threat intelligence, and relationships.
30+
You pay for the KQL queries the [entity analyzer](sentinel-mcp-data-exploration-tool.md#entity-analyzer)
31+
performs over the Microsoft Sentinel data lake. You're charged for the Security Compute Units (SCUs) required to deliver the reasoned entity risk analysis based on prevalence, threat intelligence, and relationships.
3232

3333
### Triage tool
3434

@@ -48,7 +48,7 @@ The following limits are specific to Microsoft Sentinel data lake MCP tools:
4848
| Query window for tools | 800 characters |
4949

5050
### Microsoft Sentinel entity analyzer tool
51-
Each tenant can use the entity analyzer MCP tool up to the following limits while this feature is in preview:
51+
Each tenant can use the entity analyzer MCP tool up to the following limits:
5252
- 250 total runs an hour
5353
- 500 total runs a day
5454
- 10 concurrent runs at a time (based on available service capacity)

0 commit comments

Comments
 (0)