Beyond 90 Days: Exploring Long-Term Storage Options for Microsoft Sentinel Logs (2024)

Beyond 90 Days: Exploring Long-Term Storage Options for Microsoft Sentinel Logs (1)

🔎Beyond 90 Days: Exploring Long-Term Storage Options for Microsoft Sentinel Logs🔎

As a MSSP, you may find that the default 90-day free retention period for logs can sometimes not be sufficient to cover your service offering.

In this post, we explore available options for storing and searching Sentinel logs beyond this period.

📌 Retention and Archive Policies in Log Analytics Workspaces:

These policies determine when to remove or archive data and can help manage the cost of storing data in the workspace. Archiving allows you to keep older, less frequently used data in your workspace at a reduced cost. When you no longer use the logs but still need to keep the data for compliance or occasional investigation, you can archive the logs to save costs. Archived data stays in the same table as the data that's available for interactive queries, and you can access and analyze it through search jobs or the restore option.

📌Azure Data Explorer (ADX):

A powerful big data analytics platform that is optimized for log and data analytics. ADX uses Kusto Query Language (KQL) as its query language, making it an excellent choice for storing Microsoft Sentinel data. When you export logs to ADX, they are automatically converted to compressed, partitioned Parquet format and can be easily queried.

ADX is well-suited for users who need to run periodic investigations on their historical data and can also be useful for security-related investigations when combined with other data sources.

📌Exporting Data to an Azure Storage Account:

This option is recommended for users who rarely need to perform queries on the data or have specific querying needs. Data export in a Log Analytics workspace lets you continuously export data per selected tables in your workspace, and you can export to an Azure Storage account of type StorageV1 or later, in the same region as your workspace. The exported data can be shifted between tiers using lifecycle management, and you can query specific logs using KQL language and the "externaldata" operator.

📌Storage account export via Logic Apps

This option is recommended for users who rarely need to perform queries on the data and have their storage account set in a different region than their log analytics workspace. It allows you to specify which data you want to retrieve from the Log Analytics workspace and send it to a storage account on a regular schedule. By filtering and aggregating your log data in the query, you can limit the amount of data processed by your Logic Apps workflow.

💡My piece of advice:

1- Familiarize with your data.

2- Be clear about your service offering and capabilities with your customer. 3- Understand your clients' needs.

Beyond 90 Days: Exploring Long-Term Storage Options for Microsoft Sentinel Logs (2024)

FAQs

Which methods can you use to send Microsoft Sentinel logs to long term storage? ›

Below are the three most common/preferable methods used for storing logs in Azure environment for long term retention:
  • Azure Blob Storage (Cold Storage)
  • Azure Data Explorer (Hot Storage)
  • Microsoft Sentinel Archive Tier (Warm Storage)
Dec 19, 2023

How long does Sentinel retain logs? ›

In your Log Analytics workspace, change the interactive retention policy of the SecurityEvent table from the workspace default of 90 days to 180 days, and the total retention policy to 3 years. The total retention period is the sum of the interactive and long-term (archive) retention periods.

What is the maximum data retention period of a Microsoft Sentinel? ›

After you enable Microsoft Sentinel on a Log Analytics workspace, consider these configuration options: Retain all data ingested into the workspace at no charge for the first 90 days. Retention beyond 90 days is charged per the standard Log Analytics retention prices.

Where are Azure Sentinel logs stored? ›

While Microsoft Sentinel is accessible in both the Microsoft Defender and Azure portals, Microsoft Sentinel data is stored in Azure regions.

How does Sentinel collect logs? ›

NXLog can be configured as a log collector agent for Microsoft Sentinel, collecting and forwarding logs to its Azure Log Analytics workspaces. The logs that NXLog can forward to Microsoft Sentinel include Windows DNS Server logs, Linux audit logs, and AIX audit logs.

Which type of Azure storage should you use to store logs? ›

There are various Azure Storage services you can use to store data. The most flexible option for storing blobs from many data sources is Blob storage. Blobs are basically files. They store pictures, documents, HTML files, virtual hard disks (VHDs), big data such as logs, database backups—pretty much anything.

What are the limitations of basic logs sentinel? ›

One the limitations of Basic Logs is that it only supports a subset of the KQL operators, which means you won't be able to utilize Basic Logs data for Analytics Rules and other necessary Microsoft Sentinel functions.

How long should logs be retained? ›

For example, you may keep audit logs and firewall logs for two months. However, if your organization must follow strict laws and regulations, you may keep the most critical logs anywhere between six months and seven years. This timeframe is the log retention period.

What is the maximum number of days that can be set for the retention period in Azure? ›

Azure Virtual Machine backup policy supports a minimum retention range from seven days up to 9999 days. By default, backup of VMs are kept for 7 days in snapshot and 180 days in vault.

Why is Microsoft Sentinel so expensive? ›

Microsoft Sentinel isn't actually free

Unlike many Microsoft security offerings, Microsoft Sentinel is not bundled into a specific Microsoft 365 plan, even at the highest subscription levels. Instead, like most other SIEM/SOAR products, it's priced based on data consumption.

What is the maximum amount of time data will be retained in the Microsoft 365 audit log? ›

Audit log retention policies are part of the new Microsoft Purview Audit (Premium) capabilities. An audit log retention policy lets you specify how long to retain audit logs in your organization. You can retain audit logs for up to 10 years.

What is the maximum of days that logs are retained the backup directory? ›

Automated backup retention is a count and can be set from 1 to 365 backups. Transaction log retention is in days. For Cloud SQL Enterprise Plus edition instances, the range is from 1 to 35 days, with a default of 14 days.

How to view archived logs in Sentinel? ›

Restore archived log data
  1. For Microsoft Sentinel in the Azure portal, under General, select Search. ...
  2. Restore log data in one of two ways: ...
  3. Select the table you want to restore.
  4. Select the time range of the data that you want restore.
  5. Select Restore.
  6. Wait for the log data to be restored.
Apr 3, 2024

How are logs stored in Azure? ›

The diagnostics logs are saved in a blob container named $logs in your storage account. You can view the log data using a storage explorer like the Microsoft Azure Storage Explorer, or programmatically using the storage client library or PowerShell.

How to check audit logs in Sentinel? ›

Turn on auditing and health monitoring for your workspace
  1. In Microsoft Sentinel, under the Configuration menu on the left, select Settings.
  2. Select Settings from the banner.
  3. Scroll down to the Auditing and health monitoring section and select it to expand.
Aug 4, 2024

How do I send custom logs to Sentinel? ›

Configure the Log Analytics agent

Or, from the Log Analytics workspace navigation menu, select Custom logs. In the Custom tables tab, select Add custom log. In the Sample tab, upload a sample of a log file from your device (e.g. access. log or error.

Which of the following Azure storage blob types is the most suitable for logging data from Azure virtual machines? ›

Append blobs are ideal for scenarios such as logging data from virtual machines. Page blobs store random access files up to 8 TiB in size. Page blobs store virtual hard drive (VHD) files and serve as disks for Azure virtual machines.

What do you use to provide real time integration between Microsoft Sentinel and another? ›

Many connectors are packaged with SIEM solutions for Microsoft Sentinel and provide real-time integration. These connectors include Microsoft sources and Azure sources like Microsoft Entra ID, Azure Activity, Azure Storage, and more.

Top Articles
What is the Amex trifecta?
The Key to Effective Utilization Management - Brundage Group
Jordanbush Only Fans
Jackerman Mothers Warmth Part 3
Wordscapes Level 6030
How To Do A Springboard Attack In Wwe 2K22
Txtvrfy Sheridan Wy
How to Type German letters ä, ö, ü and the ß on your Keyboard
Nieuwe en jong gebruikte campers
Carter Joseph Hopf
Nexus Crossword Puzzle Solver
Ap Chem Unit 8 Progress Check Mcq
Mephisto Summoners War
ocala cars & trucks - by owner - craigslist
Dallas Cowboys On Sirius Xm Radio
Sonic Fan Games Hq
Spectrum Field Tech Salary
Roster Resource Orioles
Craigslist Clinton Ar
Morristown Daily Record Obituary
SuperPay.Me Review 2023 | Legitimate and user-friendly
Busted News Bowie County
Wisconsin Volleyball Team Boobs Uncensored
Hannaford Weekly Flyer Manchester Nh
BJ 이름 찾는다 꼭 도와줘라 | 짤방 | 일베저장소
Chicago Based Pizza Chain Familiarly
Table To Formula Calculator
How rich were the McCallisters in 'Home Alone'? Family's income unveiled
24 Hour Drive Thru Car Wash Near Me
Craig Woolard Net Worth
Ghid depunere declarație unică
ShadowCat - Forestry Mulching, Land Clearing, Bush Hog, Brush, Bobcat - farm & garden services - craigslist
Bee And Willow Bar Cart
Watchdocumentaries Gun Mayhem 2
Everything You Need to Know About NLE Choppa
Asian Grocery Williamsburg Va
R&J Travel And Tours Calendar
AI-Powered Free Online Flashcards for Studying | Kahoot!
Banana Republic Rewards Login
Koninklijk Theater Tuschinski
Top 25 E-Commerce Companies Using FedEx
Samantha Lyne Wikipedia
Simnet Jwu
Shipping Container Storage Containers 40'HCs - general for sale - by dealer - craigslist
Collision Masters Fairbanks
Christie Ileto Wedding
What Does the Death Card Mean in Tarot?
Aaca Not Mine
Charlotte North Carolina Craigslist Pets
Palmyra Authentic Mediterranean Cuisine مطعم أبو سمرة
E. 81 St. Deli Menu
Latest Posts
Article information

Author: Merrill Bechtelar CPA

Last Updated:

Views: 6395

Rating: 5 / 5 (50 voted)

Reviews: 89% of readers found this page helpful

Author information

Name: Merrill Bechtelar CPA

Birthday: 1996-05-19

Address: Apt. 114 873 White Lodge, Libbyfurt, CA 93006

Phone: +5983010455207

Job: Legacy Representative

Hobby: Blacksmithing, Urban exploration, Sudoku, Slacklining, Creative writing, Community, Letterboxing

Introduction: My name is Merrill Bechtelar CPA, I am a clean, agreeable, glorious, magnificent, witty, enchanting, comfortable person who loves writing and wants to share my knowledge and understanding with you.