A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Hello Ipmando
Only security data gathered by Defender for Cloud's auto-provisioned AMA data collection rules is eligible for the 500 MB/day Defender for Servers Plan 2 ingestion benefit. The Microsoft Sentinel "Windows Security Events via AMA" connector (custom DCR) is used in your setup to gather Security Events. This method is used to ingest data, which is fully billable and handled like regular Log Analytics ingestion. Consequently: IsBillable = true FreeGB is equal to zero. is expected behavior.
Security Events must be gathered via Defender for Cloud auto-provisioning rather than the Sentinel AMA connection DCR in order to qualify for the 500 MB/day incentive.
As updated by you, In Sentinel subscription, under Sentinel log analytics workspace set Enviorment Settings -> Data Collection to Common.
I didn't create its own DCR's but it enabled ingestion benefits to my DCR's made via Sentinel Data Connectors.
and click on Yes for was this answer helpful. And, if you have any further query do let us know.