Beyond 90 Days: Exploring Long-Term Storage Options for Microsoft Sentinel Logs (2024)

Beyond 90 Days: Exploring Long-Term Storage Options for Microsoft Sentinel Logs (1)

🔎Beyond 90 Days: Exploring Long-Term Storage Options for Microsoft Sentinel Logs🔎

As a MSSP, you may find that the default 90-day free retention period for logs can sometimes not be sufficient to cover your service offering.

In this post, we explore available options for storing and searching Sentinel logs beyond this period.

📌 Retention and Archive Policies in Log Analytics Workspaces:

These policies determine when to remove or archive data and can help manage the cost of storing data in the workspace. Archiving allows you to keep older, less frequently used data in your workspace at a reduced cost. When you no longer use the logs but still need to keep the data for compliance or occasional investigation, you can archive the logs to save costs. Archived data stays in the same table as the data that's available for interactive queries, and you can access and analyze it through search jobs or the restore option.

📌Azure Data Explorer (ADX):

A powerful big data analytics platform that is optimized for log and data analytics. ADX uses Kusto Query Language (KQL) as its query language, making it an excellent choice for storing Microsoft Sentinel data. When you export logs to ADX, they are automatically converted to compressed, partitioned Parquet format and can be easily queried.

ADX is well-suited for users who need to run periodic investigations on their historical data and can also be useful for security-related investigations when combined with other data sources.

📌Exporting Data to an Azure Storage Account:

This option is recommended for users who rarely need to perform queries on the data or have specific querying needs. Data export in a Log Analytics workspace lets you continuously export data per selected tables in your workspace, and you can export to an Azure Storage account of type StorageV1 or later, in the same region as your workspace. The exported data can be shifted between tiers using lifecycle management, and you can query specific logs using KQL language and the "externaldata" operator.

📌Storage account export via Logic Apps

This option is recommended for users who rarely need to perform queries on the data and have their storage account set in a different region than their log analytics workspace. It allows you to specify which data you want to retrieve from the Log Analytics workspace and send it to a storage account on a regular schedule. By filtering and aggregating your log data in the query, you can limit the amount of data processed by your Logic Apps workflow.

💡My piece of advice:

1- Familiarize with your data.

2- Be clear about your service offering and capabilities with your customer. 3- Understand your clients' needs.

Beyond 90 Days: Exploring Long-Term Storage Options for Microsoft Sentinel Logs (2024)

FAQs

Which methods can you use to send Microsoft Sentinel logs to long term storage? ›

Below are the three most common/preferable methods used for storing logs in Azure environment for long term retention:
  • Azure Blob Storage (Cold Storage)
  • Azure Data Explorer (Hot Storage)
  • Microsoft Sentinel Archive Tier (Warm Storage)
Dec 19, 2023

How long does Sentinel retain logs? ›

In your Log Analytics workspace, change the interactive retention policy of the SecurityEvent table from the workspace default of 90 days to 180 days, and the total retention policy to 3 years. The total retention period is the sum of the interactive and long-term (archive) retention periods.

What is the maximum data retention period of a Microsoft Sentinel? ›

After you enable Microsoft Sentinel on a Log Analytics workspace, consider these configuration options: Retain all data ingested into the workspace at no charge for the first 90 days. Retention beyond 90 days is charged per the standard Log Analytics retention prices.

Where are Azure Sentinel logs stored? ›

While Microsoft Sentinel is accessible in both the Microsoft Defender and Azure portals, Microsoft Sentinel data is stored in Azure regions.

How does Sentinel collect logs? ›

NXLog can be configured as a log collector agent for Microsoft Sentinel, collecting and forwarding logs to its Azure Log Analytics workspaces. The logs that NXLog can forward to Microsoft Sentinel include Windows DNS Server logs, Linux audit logs, and AIX audit logs.

Which type of Azure storage should you use to store logs? ›

There are various Azure Storage services you can use to store data. The most flexible option for storing blobs from many data sources is Blob storage. Blobs are basically files. They store pictures, documents, HTML files, virtual hard disks (VHDs), big data such as logs, database backups—pretty much anything.

What are the limitations of basic logs sentinel? ›

One the limitations of Basic Logs is that it only supports a subset of the KQL operators, which means you won't be able to utilize Basic Logs data for Analytics Rules and other necessary Microsoft Sentinel functions.

How long should logs be retained? ›

For example, you may keep audit logs and firewall logs for two months. However, if your organization must follow strict laws and regulations, you may keep the most critical logs anywhere between six months and seven years. This timeframe is the log retention period.

What is the maximum number of days that can be set for the retention period in Azure? ›

Azure Virtual Machine backup policy supports a minimum retention range from seven days up to 9999 days. By default, backup of VMs are kept for 7 days in snapshot and 180 days in vault.

Why is Microsoft Sentinel so expensive? ›

Microsoft Sentinel isn't actually free

Unlike many Microsoft security offerings, Microsoft Sentinel is not bundled into a specific Microsoft 365 plan, even at the highest subscription levels. Instead, like most other SIEM/SOAR products, it's priced based on data consumption.

What is the maximum amount of time data will be retained in the Microsoft 365 audit log? ›

Audit log retention policies are part of the new Microsoft Purview Audit (Premium) capabilities. An audit log retention policy lets you specify how long to retain audit logs in your organization. You can retain audit logs for up to 10 years.

What is the maximum of days that logs are retained the backup directory? ›

Automated backup retention is a count and can be set from 1 to 365 backups. Transaction log retention is in days. For Cloud SQL Enterprise Plus edition instances, the range is from 1 to 35 days, with a default of 14 days.

How to view archived logs in Sentinel? ›

Restore archived log data
  1. For Microsoft Sentinel in the Azure portal, under General, select Search. ...
  2. Restore log data in one of two ways: ...
  3. Select the table you want to restore.
  4. Select the time range of the data that you want restore.
  5. Select Restore.
  6. Wait for the log data to be restored.
Apr 3, 2024

How are logs stored in Azure? ›

The diagnostics logs are saved in a blob container named $logs in your storage account. You can view the log data using a storage explorer like the Microsoft Azure Storage Explorer, or programmatically using the storage client library or PowerShell.

How to check audit logs in Sentinel? ›

Turn on auditing and health monitoring for your workspace
  1. In Microsoft Sentinel, under the Configuration menu on the left, select Settings.
  2. Select Settings from the banner.
  3. Scroll down to the Auditing and health monitoring section and select it to expand.
Aug 4, 2024

How do I send custom logs to Sentinel? ›

Configure the Log Analytics agent

Or, from the Log Analytics workspace navigation menu, select Custom logs. In the Custom tables tab, select Add custom log. In the Sample tab, upload a sample of a log file from your device (e.g. access. log or error.

Which of the following Azure storage blob types is the most suitable for logging data from Azure virtual machines? ›

Append blobs are ideal for scenarios such as logging data from virtual machines. Page blobs store random access files up to 8 TiB in size. Page blobs store virtual hard drive (VHD) files and serve as disks for Azure virtual machines.

What do you use to provide real time integration between Microsoft Sentinel and another? ›

Many connectors are packaged with SIEM solutions for Microsoft Sentinel and provide real-time integration. These connectors include Microsoft sources and Azure sources like Microsoft Entra ID, Azure Activity, Azure Storage, and more.

Top Articles
Can a Trustee Be Held Personally Liable?
FAQs - Rocky Point Hotels | Puerto Penasco Hotels | Rocky Point Mexico
Ingles Weekly Ad Lilburn Ga
Boggle Brain Busters Bonus Answers
Cinepacks.store
Slay The Spire Red Mask
Bbc 5Live Schedule
Day Octopus | Hawaii Marine Life
Grand Park Baseball Tournaments
Nashville Predators Wiki
Things To Do In Atlanta Tomorrow Night
Belle Delphine Boobs
Vrachtwagens in Nederland kopen - gebruikt en nieuw - TrucksNL
Van Buren County Arrests.org
Kayky Fifa 22 Potential
Loslaten met de Sedona methode
Danielle Ranslow Obituary
Blackboard Login Pjc
Truvy Back Office Login
R/Airforcerecruits
Evil Dead Rise Showtimes Near Sierra Vista Cinemas 16
Great ATV Riding Tips for Beginners
Maine Racer Swap And Sell
Www Mydocbill Rada
Google Flights To Orlando
Kempsville Recreation Center Pool Schedule
Ridge Culver Wegmans Pharmacy
Have you seen this child? Caroline Victoria Teague
Graphic Look Inside Jeffrey Dresser
A Man Called Otto Showtimes Near Carolina Mall Cinema
Caderno 2 Aulas Medicina - Matemática
Gvod 6014
Express Employment Sign In
This 85-year-old mom co-signed her daughter's student loan years ago. Now she fears the lender may take her house
Appraisalport Com Dashboard Orders
Electric Toothbrush Feature Crossword
Sdn Fertitta 2024
Mychart Mercy Health Paducah
Booknet.com Contract Marriage 2
Royals Yankees Score
Fairbanks Auto Repair - University Chevron
Martha's Vineyard – Travel guide at Wikivoyage
Csgold Uva
Vci Classified Paducah
Wzzm Weather Forecast
Best Restaurant In Glendale Az
Spn 3464 Engine Throttle Actuator 1 Control Command
60 Second Burger Run Unblocked
Craigslist Pets Lewiston Idaho
Noelleleyva Leaks
Hcs Smartfind
Latest Posts
Article information

Author: Merrill Bechtelar CPA

Last Updated:

Views: 6395

Rating: 5 / 5 (50 voted)

Reviews: 89% of readers found this page helpful

Author information

Name: Merrill Bechtelar CPA

Birthday: 1996-05-19

Address: Apt. 114 873 White Lodge, Libbyfurt, CA 93006

Phone: +5983010455207

Job: Legacy Representative

Hobby: Blacksmithing, Urban exploration, Sudoku, Slacklining, Creative writing, Community, Letterboxing

Introduction: My name is Merrill Bechtelar CPA, I am a clean, agreeable, glorious, magnificent, witty, enchanting, comfortable person who loves writing and wants to share my knowledge and understanding with you.