Microsoft Sentinel: Long Term Storage Retention (2024)

Below is an article about three different methods to store logs in Azure/Microsoft Sentinel for a long term storage.

SPOILER ALERT: Sentinel Archive Tier is a better approach for most scenarios 🙂

Pre-requisites

  • Microsoft Sentinel vs Log Analytics Workspace | LinkedIn
  • Basic Knowledge around Azure Blob Storage
  • Basic Knowledge around Azure Data Explorer
  • Microsoft Sentinel: Analytic vs Basic vs Archive | LinkedIn

Overview

As discussed in the previous article, Microsoft Sentinel is not a platform to dump all the logs in and use as a storage box. Although organizations would require some time to store heavy volume/low value logs in "some" storage for two reasons:

  • Compliance requirement
  • Retro-threat hunting

Below are the three most common/preferable methods used for storing logs in Azure environment for long term retention:

  • Azure Blob Storage (Cold Storage)
  • Azure Data Explorer (Hot Storage)
  • Microsoft Sentinel Archive Tier (Warm Storage)

Azure Blob Storage

Azure Blob Storage "used to be" the only method to store logs for a long term retention, due to its cheaper cost. This method was preferred mainly for scenarios where the long term retention of logs is mainly for compliance requirements (and not for retro-threat hunting).

Analogy

Storing logs in Azure Blob Storage is similar to,

  • compressing your files
  • storing them in an external hard drive
  • away from your computer, and not on your desk

You rarely want to view/edit/use the files in the external hard drive. And when you want it, you will have to take some effort to migrate the files from the external hard drive to your computer - to view/edit/use it.

Pros

✅ Cheapest of all the listed methods

✅ Easy to maintain and manage

Cons

❌ Requires building an automation to move the logs from Azure Blob Storage (Cold Storage) to Log Analytics Workspace (Hot Storage)

Azure Data Explorer

Azure Data Explorer was preferred (or forced to prefer) mainly by large organizations where it was a requirement to have high volume/low value logs on a hot storage. A method to store high volume/low value logs on hot storage isn't the optimized approach - especially when its putting a hole in the wallet.

Analogy

Storing logs in Azure Data Explorer is similar to,

  • NOT compressing your files
  • storing them in a different LAPTOP
  • away from your computer, but still on your desk

You rarely want to view/edit/use the files in the laptop. And when you want it, you don't have the migrate the files from the laptop to your computer. Instead you can view/edit/use the files directly in the laptop. Although you need to make sure the laptop is maintained regularly and has power in the battery.

Pros

✅ Easily accessible with no custom automation to access the logs

Cons

❌ Expensive - ingestion cost and data export cost

❌ Requires maintenance and management

Microsoft Sentinel Archive Tier

Microsoft Sentinel Archive Tier was announced around early 2022 to have the benefits of both - Blob Storage and Azure Data Explorer. This method is resolving issues for both scenarios - compliance requirements and retro-threat hunting in the most optimized approach.

Analogy

Storing logs in Microsoft Sentinel Archive Tier is similar to,

  • compressing your files
  • storing them on a different folder
  • on your computer and on your desk

You rarely want to view/edit/use the files in your computer. And when you want it, you don't have to "migrate" the files, but just decompress the files from the folder (which doesn't involve much effort).

Pros

✅ Easily accessible with a few clicks

✅ Not as expensive as Azure Data Explorer

✅ Doesn't require any maintenance or management

Cons

❌ There's a very minimal cost for running search and restore jobs

The only time we would require running search and restore jobs on Microsoft Sentinel is when the organization hits a P1 incident - and the cost for search and restore would be considered peanuts when compared with the impact of the incident

Conclusion

Azure Blob Storage was the cheapest and only option - when Microsoft Sentinel was first released. Azure Data Explorer was the second best option (if the organization is happy to accept the cost) to keep the logs in a hot storage.

Microsoft Sentinel Archive Tier is the best of both worlds where the solution was designed to be cheaper, as well as easily accessible. Azure Blob Storage still lives as a valid solution till date - when it comes to storing low value logs "purely" for Compliance requirements only.

Microsoft Sentinel Archive Tier can be used for 80 to 90% of the scenarios, and Azure Blob Storage could resolve the remaining. 🙂

Shout out to Benjamin Kovacevic for providing insights on the above

Microsoft Sentinel: Long Term Storage Retention (2024)
Top Articles
What Every Millennial Needs To Know About Saving And Finance
9 Part-Time Jobs with Health Benefits For Stay-At-Home Moms ?? - Merry for Money
Northern Counties Soccer Association Nj
Worcester Weather Underground
Bj 사슴이 분수
³µ¿Â«»ÍÀÇ Ã¢½ÃÀÚ À̸¸±¸ ¸íÀÎ, ¹Ì±¹ Ķ¸®Æ÷´Ï¾Æ ÁøÃâ - ¿ù°£ÆÄ¿öÄÚ¸®¾Æ
Tv Guide Bay Area No Cable
St Als Elm Clinic
Computer Repair Tryon North Carolina
Displays settings on Mac
Music Archives | Hotel Grand Bach - Hotel GrandBach
Ivegore Machete Mutolation
Craigslist Pets Sac
Craigslist Farm And Garden Cincinnati Ohio
Theresa Alone Gofundme
NHS England » Winter and H2 priorities
The best TV and film to watch this week - A Very Royal Scandal to Tulsa King
If you bought Canned or Pouched Tuna between June 1, 2011 and July 1, 2015, you may qualify to get cash from class action settlements totaling $152.2 million
PowerXL Smokeless Grill- Elektrische Grill - Rookloos & geurloos grillplezier - met... | bol
Glenda Mitchell Law Firm: Law Firm Profile
The Blind Showtimes Near Amc Merchants Crossing 16
The Old Way Showtimes Near Regency Theatres Granada Hills
Two Babies One Fox Full Comic Pdf
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Znamy dalsze plany Magdaleny Fręch. Nie będzie nawet chwili przerwy
Restaurants In Shelby Montana
Scott Surratt Salary
Umn Biology
Summoners War Update Notes
Primerica Shareholder Account
3473372961
Broken Gphone X Tarkov
Ridge Culver Wegmans Pharmacy
Lil Durk's Brother DThang Killed in Harvey, Illinois, ME Confirms
Truis Bank Near Me
1400 Kg To Lb
How To Get Soul Reaper Knife In Critical Legends
Cox Outage in Bentonville, Arkansas
How Many Dogs Can You Have in Idaho | GetJerry.com
More News, Rumors and Opinions Tuesday PM 7-9-2024 — Dinar Recaps
FREE - Divitarot.com - Tarot Denis Lapierre - Free divinatory tarot - Your divinatory tarot - Your future according to the cards! - Official website of Denis Lapierre - LIVE TAROT - Online Free Tarot cards reading - TAROT - Your free online latin tarot re
Lucifer Morningstar Wiki
Bekkenpijn: oorzaken en symptomen van pijn in het bekken
2013 Honda Odyssey Serpentine Belt Diagram
Walmart 24 Hrs Pharmacy
Sml Wikia
Bluebird Valuation Appraiser Login
Houston Primary Care Byron Ga
Skybird_06
32 Easy Recipes That Start with Frozen Berries
Latest Posts
Article information

Author: Terence Hammes MD

Last Updated:

Views: 6370

Rating: 4.9 / 5 (69 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Terence Hammes MD

Birthday: 1992-04-11

Address: Suite 408 9446 Mercy Mews, West Roxie, CT 04904

Phone: +50312511349175

Job: Product Consulting Liaison

Hobby: Jogging, Motor sports, Nordic skating, Jigsaw puzzles, Bird watching, Nordic skating, Sculpting

Introduction: My name is Terence Hammes MD, I am a inexpensive, energetic, jolly, faithful, cheerful, proud, rich person who loves writing and wants to share my knowledge and understanding with you.