9: Pricing Flashcards

(11 cards)

1
Q

What is Sentinel pricing based on?

A

Sentinel pricing is primarily based on the amount of data ingested (per GB). Optional costs also apply for automation, extended retention, and some premium features.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the default data retention period in Sentinel?

A

90 days, included at no additional cost.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Can you extend data retention beyond 90 days?

A

Yes, but it incurs additional cost per GB per month.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is included at no cost in Sentinel ingestion?

A

Logs from Microsoft 365 Defender and Microsoft Entra (formerly Azure AD) are free to ingest into Sentinel.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How can customers reduce ingestion costs?

A

Use filtering with Azure Monitor Agent (AMA) to only send necessary logs. Use compression, reduce verbosity, apply sampling, and tune data sources.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What happens if you send too many verbose logs?

A

Costs increase, queries slow down, and dashboards may lag. You should tune ingestion to focus on relevant, high-value data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Can you archive Sentinel data instead of deleting it?

A

Yes. You can use the Archive Tier to retain logs at a lower cost and restore them when needed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Why should customers care about pricing and retention?

A

It helps with budget planning and avoids surprise costs. Understanding which data is free vs. billable helps teams prioritize what to ingest and store.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Can I see how much each data connector is costing me?

A

Yes. You can use Azure Cost Management or the Sentinel Usage Workbook to track ingestion and cost per table or data source.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Is there a free trial for Sentinel?

A

Yes. You get up to 10GB/day free for the first 31 days after enabling Sentinel.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Do I get billed for running queries or viewing dashboards?

A

No. You’re only billed for ingestion, extended retention, and automation—queries and dashboards are free to use.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly