Тёмный

New Low-Cost Log Options, Automation, AI & SIEM Migration | Microsoft Sentinel Updates 

Microsoft Mechanics
Подписаться 346 тыс.
Просмотров 3,5 тыс.
50% 1

Опубликовано:

 

11 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 12   
@davidgorman994
@davidgorman994 2 дня назад
I really struggle with Sentinel. I know it's hugely powerful but it's so expensive to run and hard to know how to optimize.
@shaffiq
@shaffiq 2 дня назад
try to search for Sentinel Optimization workbook, get it installed, get it run, and find the areas of improvement you can make to reduce cost and enhance optimizations
@nestorreveron
@nestorreveron 2 дня назад
👌
@simple-security
@simple-security День назад
Question please: can I use ADX and get similar value to auxiliary logs? If I'm correct ADX would be about $0.008/GB/month and auxiliary is $.19/GB? (plus with adx you pay about $1k/month for the adx cluster, etc)
@MarsorryIckuatuna
@MarsorryIckuatuna 2 дня назад
We subscribed to Sentinel. As powerful as it is, it’s quite unfortunate that it’s a major money HOG! By design, it’s meant to get data from multiple sources, yet - the more you configure for just that reason, the more unaffordable it becomes. This is really for big corporates with bottomless pockets. 😔. I’ll be surprised if my IT Department lasts one more year of this.
@rvt20s
@rvt20s 2 дня назад
What are you ingesting? DM if you want help on controlling costs.
@MSFTMechanics
@MSFTMechanics 2 дня назад
Good news, that's a lot of what this video is about. SOC optimizations to save costs with storage and Auxiliary Logs to affordably pull in important logs you might otherwise not be able to, because they are too vast and potentially too noisy, like firewall logs.
@simple-security
@simple-security День назад
the education and features for lower cost logging have certainly been some time coming. Consider these topics to reduce costs: - logging to ADX - creating data transformations to filter no-value logs - this new auxiliary log feature Hopefully Microsoft or someone will create an up to date video with a deep dive on the above 3 topics, including cost comparison use cases.
@MarsorryIckuatuna
@MarsorryIckuatuna День назад
@@simple-security Thank you, I’ve taken note for my team. Appreciated.
@blirt1653
@blirt1653 2 дня назад
I'm confused as to what Sentinel is providing me that Defender isn't. All we have configured is the 365, Defender and Entra connectors.
@MSFTMechanics
@MSFTMechanics 2 дня назад
Thanks for your comment. The good news is that Microsoft Sentinel is also integrated with the Microsoft Defender XDR portal experience. Microsoft Sentinel has the advantage that you can connect other Cloud and on premises services - IaaS, PaaS, and SaaS - for a view of your entire estate and see how incidents might move between Microsoft and non-Microsoft services.
Далее
Living off Microsoft Copilot
42:06
Просмотров 6 тыс.
Women's Defending + Men's 😮‍💨❌
00:20
Просмотров 938 тыс.
Microservices are Technical Debt
31:59
Просмотров 488 тыс.
Future of work: AI is joining the workforce
22:21
Просмотров 1 тыс.
18 Weird and Wonderful ways I use Docker
26:18
Просмотров 276 тыс.
this Cybersecurity Platform is FREE
39:46
Просмотров 577 тыс.
Microsoft Sentinel in just 30 minutes
36:20
Просмотров 28 тыс.