Azure Sentinel estimated cost

barry.wong 1 Reputation point
2020-08-06T05:06:18.15+00:00

I understand Azure Sentinel charged by volume of data ingested

But I have no idea how many data the following azure services will ingesting to Sentinel

  • Windows server virtual machines
  • Azure SQL server
  • Fortigate Firewall
  • Azure AD
  • Microsoft Defender

Just want to have an estimated data volume, so that the bill won't surprise when the end of month
Thanks

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
996 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Saurabh Sharma 23,761 Reputation points Microsoft Employee
    2020-08-07T21:43:45.677+00:00

    @barry.wong In order to understand how much data you are going to ingest into Sentinel you need to figure out the how much data you are sending from each of these services to log analytics workspace. For example, In a typical Azure VM you would be sending around 1-3 GB of data/month which will depend on environment and your usage. If you are already ingesting data to log analytics workspace then you can go to Azure portal > Your log analytics > {Select your workspace} > Usage and estimated costs page. This page provides Data ingestion per solution chart to determine the volume of data being sent to log analytics. (see screenshot below)
    16511-image.png

    You can refer to the Estimating the costs to manage your environment for details. You can also refer to the documentation to get the data volume by Azure Resources/Resource Group/Subscription.
    Once you are able to determine the estimated data ingestion of each resource to log analytics then you can use the Pricing Calculator to get estimated cost.

    1 person found this answer helpful.

  2. Luis Antonio Márquez 1 Reputation point
    2021-01-11T17:46:20.06+00:00

    Hi, I understand it is very difficult to know in advance the cost, but you can enable a daily cap (ingestion) per day in the log analytics workspace. Also, you can define a KQL query to know how much storage you are using, or how much has been ingested in that day. This makes calculating the cost simple, and also prevents possible spikes.

    Hope it will be useful. Let me know if you need help to configure the daily limit or with the KQL queries.

    Regards,

    Luis.

    0 comments No comments