Where does Defender for Cloud's data is stored?

Rakesh Singh 390 Reputation points
2024-08-13T21:32:52.9033333+00:00

I am looking to understand where does the data and alerts that Defender for Cloud generates for different set of workloads under it, is stored at? I am not able to find any clear documentation anywhere that explains where the data gets stored for Defender for cloud? Is it using any workspace (getting created automatically while enabling a plan)? Would request if this can be explained a little. Would appreciate if there is a link to explain this as well.

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
0 comments No comments
{count} vote

2 answers

Sort by: Most helpful
  1. SIMEON ETIM 26 Reputation points
    2024-08-13T21:45:53.1266667+00:00

    Defender for Cloud’s data is stored in Azure Monitor Logs (formerly known as Log Analytics). The data is stored in one or more Log Analytics workspaces within Azure.

    Here's a breakdown of where the data goes:

    Log Analytics Workspace: When you use Defender for Cloud, the security data it collects, such as security alerts, recommendations, and other related information, is stored in a Log Analytics workspace. This workspace acts like a central database where all the logs and data related to security monitoring are kept.

    Data Storage Location: The physical location of the data is determined by the region where your Log Analytics workspace is created. When you set up the workspace, you choose a region (like West Europe, East US, etc.), and the data is stored in that Azure region. It's important to select a region that complies with your data residency requirements.

    Retention and Access: You can configure how long the data is retained within the workspace and how it can be accessed. The data is accessible through various tools like Azure Monitor, Azure Security Center, and other Azure services.

    So, Defender for Cloud’s data is stored securely in the Azure region where your Log Analytics workspace is hosted, and it can be accessed through Azure's monitoring and security tools.

    1 person found this answer helpful.
    0 comments No comments

  2. Rakesh Singh 390 Reputation points
    2024-08-16T17:29:29.77+00:00

    Defender for Cloud’s data is stored in Azure Monitor Logs (formerly known as Log Analytics). The data is stored in one or more Log Analytics workspaces within Azure.

    Here's a breakdown of where the data goes:

    Log Analytics Workspace: When you use Defender for Cloud, the security data it collects, such as security alerts, recommendations, and other related information, is stored in a Log Analytics workspace. This workspace acts like a central database where all the logs and data related to security monitoring are kept.

    Data Storage Location: The physical location of the data is determined by the region where your Log Analytics workspace is created. When you set up the workspace, you choose a region (like West Europe, East US, etc.), and the data is stored in that Azure region. It's important to select a region that complies with your data residency requirements.

    Retention and Access: You can configure how long the data is retained within the workspace and how it can be accessed. The data is accessible through various tools like Azure Monitor, Azure Security Center, and other Azure services.

    So, Defender for Cloud’s data is stored securely in the Azure region where your Log Analytics workspace is hosted, and it can be accessed through Azure's monitoring and security tools.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.