Configure interactive and long-term data retention in Microsoft Sentinel (2024)

In the previous deployment step, you enabled the User and Entity Behavior Analytics (UEBA) feature to streamline your analysis process. In this article, you learn how to set up interactive and long-term data retention, to make sure your organization retains the data that's important in the long term. This article is part of the Deployment guide for Microsoft Sentinel.

Configure data retention

Retention policies define when to remove data, or mark it for long-term retention, in a Log Analytics workspace. Long-term retention lets you keep older, less used data in your workspace at a reduced cost. To set up data retention plans, consult Log retention plans in Microsoft Sentinel, and use one or both of these methods, depending on your use case:

Next steps

In this article, you learned how to set up interactive and long-term data retention.

Configure interactive and long-term data retention in Microsoft Sentinel (2024)

FAQs

What is the data retention period of a Microsoft Sentinel workspace? ›

After you enable Microsoft Sentinel on a Log Analytics workspace, consider these configuration options: Retain all data ingested into the workspace at no charge for the first 90 days. Retention beyond 90 days is charged per the standard Log Analytics retention prices.

Which methods can you use to send Microsoft Sentinel logs to long term storage? ›

Below are the three most common/preferable methods used for storing logs in Azure environment for long term retention:
  • Azure Blob Storage (Cold Storage)
  • Azure Data Explorer (Hot Storage)
  • Microsoft Sentinel Archive Tier (Warm Storage)
Dec 19, 2023

How do you implement a data retention policy in Azure? ›

From the Log Analytics workspaces menu in the Azure portal, select your workspace. Select Usage and estimated costs in the left pane. Select Data Retention at the top of the page. Move the slider to increase or decrease the number of days, and then select OK.

How to set retention for log analytics workspace? ›

Changing Azure Log Analytics Retention
  1. In the Azure portal, find your Log Analytics workspace.
  2. Click on Usage and Estimate costs under the General section.
  3. Click on Daily Retention.
  4. Adjust the slider to the desired level of retention up to 730 days.

How long is the retention period for data in Microsoft Office 365? ›

If a paid subscription ends or is terminated, Microsoft retains customer data stored in Microsoft 365 in a limited-function account for 90 days to enable the subscriber to extract the data. After the 90-day retention period ends, Microsoft disables the account and deletes the customer data.

What is the maximum amount of time data will be retained in the Microsoft 365 audit log? ›

Audit log retention policies are part of the new Microsoft Purview Audit (Premium) capabilities. An audit log retention policy lets you specify how long to retain audit logs in your organization. You can retain audit logs for up to 10 years.

Where does Microsoft Sentinel store data? ›

Microsoft Sentinel is billed for the volume of data analyzed in Microsoft Sentinel and stored in Azure Monitor Log Analytics workspace. Data can be ingested as three different types of logs: Analytics Logs, Basic Logs and Auxiliary Logs (preview).

How long are logs kept in Sentinel? ›

Analytics logs are the default log type for Log Analytics and offer a good balance between features and price. If you are starting with Microsoft Sentinel, all your tables will probably be Analytics logs. Analytics logs can be retained for 730 days, but they are also the most expensive log type.

What is the difference between Microsoft Sentinel and Azure Sentinel? ›

As previously mentioned, both names refer to the same product. Microsoft renamed Azure Sentinel to Microsoft Sentinel in November 2021.

What is the Azure long-term retention policy? ›

For SQL Database, you can configure full long-term retention (LTR) backups for up to 10 years in Azure Blob Storage. After the LTR policy is configured, full backups are automatically copied to a different storage container weekly.

How do you implement data retention? ›

The following practices should be considered necessary when deciding on your data retention policy and its implementation.
  1. Categorize and periodically audit data. ...
  2. Identify legal requirements and schedule retention periods. ...
  3. Enact backups and backup testing. ...
  4. Ensure data purging and disposal measures are defined.

What do you do to configure a long-term retention plan for your Azure SQL Database? ›

To enable LTR, you can define a policy using a combination of four parameters: weekly backup retention (W), monthly backup retention (M), yearly backup retention (Y), and week of the year (WeekOfYear). If you specify W, one backup every week is copied to long-term storage.

What are data connectors in Sentinel? ›

Built-in connectors enable connection to the broader security ecosystem for non-Microsoft products. For example, use Syslog, Common Event Format (CEF), or REST APIs to connect your data sources with Microsoft Sentinel.

What are the log retention requirements? ›

Different compliance frameworks have different retention period recommendations:
  • HIPAA: 6 years.
  • PCI DSS: 1 year.
  • NIST: 3 years.
  • SOX: 7 years.
  • GLBA: 6 years.
Nov 8, 2022

How do I assign a retention policy to a user? ›

Use the Exchange admin center to apply a retention policy to a single mailbox. Go to Recipients > Mailboxes. In User Mailbox, click Mailbox features. In the Retention policy list, select the policy you want to apply to the mailbox, and then click Save.

How long does SentinelOne retain logs? ›

How long can SentinelOne retain data? SentinelOne enables effective threat hunting with an industry leading data retention of 365 days out of the box for malware and fileless attack incidents. We offer 14 days standard historical EDR data retention that is affordably upgradeable to 365 days.

What is the retention period of SIEM? ›

Cloud SIEM​

Insights and Signals that are attached to Insights are retained in Cloud SIEM indefinitely. Signals that are not attached to Insights are retained in Cloud SIEM: For 30 days if suppressed. For 365 days if unsuppressed.

What is the default retention period for Azure monitor? ›

The default retention period in Log Analytics is 90 days.

Top Articles
Unlock a Secured Wi-Fi Connection
Composable Applications: What Are They and Why Do You Need Them? | Azion
Golden Abyss - Chapter 5 - Lunar_Angel
Skylar Vox Bra Size
Http://N14.Ultipro.com
Manhattan Prep Lsat Forum
Here are all the MTV VMA winners, even the awards they announced during the ads
Dr Doe's Chemistry Quiz Answer Key
Slapstick Sound Effect Crossword
Sunday World Northern Ireland
Smokeland West Warwick
Toonily The Carry
Aberration Surface Entrances
Urban Airship Expands its Mobile Platform to Transform Customer Communications
Everything you need to know about Costco Travel (and why I love it) - The Points Guy
Why Is 365 Market Troy Mi On My Bank Statement
Persona 4 Golden Taotie Fusion Calculator
Gopher Hockey Forum
Geometry Review Quiz 5 Answer Key
Skip The Games Fairbanks Alaska
Dragonvale Valor Dragon
Knock At The Cabin Showtimes Near Alamo Drafthouse Raleigh
Anotherdeadfairy
Ontdek Pearson support voor digitaal testen en scoren
Inbanithi Age
Chime Ssi Payment 2023
Kentuky Fried Chicken Near Me
Barista Breast Expansion
Klsports Complex Belmont Photos
Lbrands Login Aces
Mississippi Craigslist
Airg Com Chat
Does Royal Honey Work For Erectile Dysfunction - SCOBES-AR
Evil Dead Rise - Everything You Need To Know
Nacogdoches, Texas: Step Back in Time in Texas' Oldest Town
Texters Wish You Were Here
Craigslist Georgia Homes For Sale By Owner
7543460065
The TBM 930 Is Another Daher Masterpiece
R/Moissanite
Wilson Tattoo Shops
Wilson Tire And Auto Service Gambrills Photos
Nimbleaf Evolution
Headlining Hip Hopper Crossword Clue
Craigslist Sparta Nj
How to Find Mugshots: 11 Steps (with Pictures) - wikiHow
Laura Houston Wbap
Brutus Bites Back Answer Key
The Missile Is Eepy Origin
Tenichtop
Latest Posts
Article information

Author: Edwin Metz

Last Updated:

Views: 6453

Rating: 4.8 / 5 (78 voted)

Reviews: 85% of readers found this page helpful

Author information

Name: Edwin Metz

Birthday: 1997-04-16

Address: 51593 Leanne Light, Kuphalmouth, DE 50012-5183

Phone: +639107620957

Job: Corporate Banking Technician

Hobby: Reading, scrapbook, role-playing games, Fishing, Fishing, Scuba diving, Beekeeping

Introduction: My name is Edwin Metz, I am a fair, energetic, helpful, brave, outstanding, nice, helpful person who loves writing and wants to share my knowledge and understanding with you.