Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelHard
A security engineer is tasked with optimizing the cost of Microsoft Sentinel. The current Log Analytics workspace is ingesting a large volume of non-security-critical logs that are only needed for occasional auditing and compliance purposes, not for real-time threat detection. These logs are currently stored in the 'Analytics' tier, incurring standard ingestion and retention costs. What is the most cost-effective way to manage these specific logs in Microsoft Sentinel?
- AReduce the retention period for all logs in the Log Analytics workspace.
- BFilter out the non-security-critical logs at the data connector level.
- CTransition the non-security-critical logs to 'Archived Logs' in the Log Analytics workspace.
- DMove the non-security-critical logs to the 'Basic' Log Analytics pricing tier.
Show answer & explanationAnswer & explanation
Correct answer: C. Transition the non-security-critical logs to 'Archived Logs' in the Log Analytics workspace.
The 'Archived Logs' tier in Log Analytics (and thus Sentinel) is designed for long-term, infrequently accessed data that does not require real-time analytics. It offers significantly lower storage costs compared to the 'Analytics' tier, making it ideal for compliance and auditing logs that are not security-critical.
Why the other options are wrong
- A. Reducing retention for *all* logs might compromise compliance for other critical data and doesn't target the specific cost issue of non-critical logs.
- B. Filtering them out entirely means they won't be available for auditing or compliance, which contradicts the requirement.
- D. The 'Basic' tier is typically for specific use cases (e.g., Defender for Cloud) and may not offer the same cost savings or query capabilities for long-term archival as 'Archived Logs'.
Microsoft Sentinel Log Archiving
Microsoft Sentinel leverages Log Analytics' 'Archived Logs' tier for cost-effective long-term storage of logs that are not frequently queried but are needed for compliance or historical analysis.
- Significantly lower storage cost than 'Analytics' tier.
- Querying archived data incurs retrieval costs.
- Ideal for infrequently accessed, long-term retention data.
Memory trick: Archive: For Logs You Love to Keep, But Don't Often Peek!