Where does Sentinel store the information that are displayed in the Incident View?

Deller, Vinzent 0 Reputation points
2024-02-14T09:43:35.72+00:00

Hello, I am currently wondering where Sentinel stores the information that is displayed in the Incident View. My Log Analytics has a data retention of 90 days, each table has 90 days retention without an archive period. In Sentinel I can view incidents that are older than 2 years. Where does Sentinel get this data from? Regards
vinzent

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
981 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Clive Watson 5,716 Reputation points MVP
    2024-02-14T12:28:15.1+00:00

    Microsoft stores additional metadata in your deployed region, so you do have longer than 90days for limited specific data like this.