Talk with sales and see if they can get you a trial period so you can measure your ingest. There is a pay as you go option and it’s best if you are under like 70gb iirc. Answer from After-Vacation-2146 on reddit.com
🌐
Reddit
reddit.com › r/azure › sentinel pricing not lining up, and how to get a unit quantity from cost analytics
r/AZURE on Reddit: Sentinel pricing not lining up, and how to get a unit quantity from cost analytics
February 23, 2025 -

We only have one LA workspace on Sentinel, and I can see the history of daily ingest - I can see the kusto query to gather this detail includes isBillable=True so safe to say my xxx GB each day ingested is correct for billing.

I've then taken the cost each day for the Sentinel service (PAYG Analytics meter) so I know what we've been charged. And I've taken the prices from Microsoft's Sentinel pricing page.

And they don't add up, PAYG should be $5.38 per GB, and "Prices shown below reflect the total cost for the data analyzed by Microsoft Sentinel, including data ingestion charges for Azure Monitor Log Analytics for the specific tier".

Using the quantity that I know was ingested, it's coming out to around $4.14 per GB. I feel like if it was possible to view the 'Unit Price' and 'Unit Quantity' details in the cost analysis, I could at least see how many GB we've been charged for, but I can't find any way to get this detail?

Just wondering if anyone has done a deep dive on this before and could suggest why they aren't lining up?

Thanks in advance

🌐
Reddit
reddit.com › r/azure › real cost of azure sentinel
r/AZURE on Reddit: Real Cost of Azure Sentinel
February 23, 2019 -

Can anyone shed some light on what your monthly cost has been? I'm evaluating going from a our MSSP that simply looks at our DCs and Firewalls to something like Exabeam or Sentinel. Exabeam for us appears to be in the 40k range a year. Sentinel, I can't really even estimate because I have to be able to judge how much data I would be ingesting -- where would I even begin with that calculation?

Anyone care to say what their bill is for their size of a company? Might be able to quantify my end from it.

Many thanks.

🌐
Reddit
reddit.com › r/azure › azure sentinel pricing - small scale testing at home
r/AZURE on Reddit: Azure sentinel pricing - small scale testing at home
April 10, 2020 -

Hi - has anyone tried Sentinel at home just to play around with it and use it a bit? Most of my log sources would just be o365 and some Defefender installs and I’d probably try some other devices which aren’t going to be ‘free’ (plus log analytics workspace costs).

Just curious if anyone has used it at home for testing and how much it ended up costing?

🌐
Reddit
reddit.com › r/azure › still having a hard time understanding sentinel's pricing
r/AZURE on Reddit: Still having a hard time understanding Sentinel's pricing
September 21, 2019 -

I'm trying to understand the pricing for Azure Sentinel through Azure's pricing program. (https://azure.microsoft.com/en-us/pricing/calculator/)

I'm having a hard time understanding how pricing works for daily ingested logs.

So the calculation uses daily capacity reservation for both Log Analytics and Sentinel.

For example, if I'm selecting US Central, if the ingested daily logs are 100GB, how can the pricing be $10275.6?

Its $2.46/GB for Sentinel, and $2.76/GB for Log Analytics. I just can't get my head around the logic.

Can someone help?

🌐
Reddit
reddit.com › r/azuresentinel › real world cost examples
r/AzureSentinel on Reddit: Real world cost examples
January 17, 2024 -

Hi,

we are trying to find a SIEM. As an all Azure shop Sentinel would be the obvious solution. But of course there is never budget. :)

So I'm at a total loss. I don't know anything about Sentinel. Just read the costs are primarily dependent on amount of logs ingested & retention - and then on 10000 other things. So nobody can tell us how much it will be for 500 users with defender for endpoint p2, 6 remote site firewalls etc. - I totally understand.

But is there some resource out there that describes real world scenarios and their costs or is anybody willing to share roughly what they are doing and what that estimates to? Just to get a vage feeling for it. Would help tremendously.

Much appreciated. :)

Top answer
1 of 3
1
To do any decent estimation you need to give solid info based on facts. Because you environment is different from all others, and there are 100 of factors that can take it in one direction or the other. https://youtu.be/ryqjtFvXf44?feature=shared This goes through the different cost increases and decreases. My rough average is, but the less servers you have, the more off these numbers will be, taken from average number of roughly 10k servers, DC's will generate alot more ofc, but if you average out, well.. yeah.. Windows Server 300mb/day Linux server 40mb/day But that is based off our data collection, is yours the same? Might be, but does your servers do the same thing? The amount of conditional access policies will highly impact your signinlogs and aadnoninteractivesigninlogs, event size will go from 1000bytes to 15000bytes. Dns? What type of filtering are you looking at? How aggressive are you/the org willing to be with filtering data? Firewalls? Traffic? Ips? Webfiltering? There are so many variables, and above are just the easy ones Compliance requirements? Retention Automation? Enrichment? Need that enterprise api key for virustotal? Paid threat feed vs free? Infrastructure cost for logforwarding solutions, egress cost for cloud, whether that is between Azure regions or another cloud. Iac and DevOps/GitHub to have a good deployment pipeline and not just yolo cowboys in the environment?
2 of 3
1
I can give you a rough estimate based on our environment. Log analytics 100 devices reporting telemetry Threat Intelligence (both built-in and custom source) Intune dynamics365 audit logs sign in logs email events Around 25 £ (last 30 days) Logic apps Around 2 £ (last 30 days) Storage (we redirect logs to blob for regulatory reasons) Around 1 £ My advice is to use Ingestion rules. Azure monitor now supports data transformation rules, and it's a god send technology. Without them, the cost would be more than double, especially MDE logs. You don't need 3/4 of the crap they attach to the logs. Our customer doesn't have firewalls on Azure, but assume they are very chatty, so ingestion is going to be crazy. You'd probably need to filter a lot. Good luck
🌐
Reddit
reddit.com › r/sysadmin › azure sentinel pricing?
r/sysadmin on Reddit: Azure Sentinel Pricing?
July 2, 2020 -

Hey all,

I'm hoping to get some assistance with figuring out how to correctly figure out this pricing. We're only looking to, at this time, ingest Office 365 and Azure logs, which seem to mostly be included under the free ingestion FAQ, although I do see that they've clarified that Azure AD Audit Logs are not free any longer. I also know I need to pay to ingest the log(s) into Log Analytics first, but I'm just lost at how to properly calculate this out. Any pointers would be greatly appreciated. I have an open request for the same from my VAR, but they're taking quite a long time to get back to me about it. The logs we'd like to ingest would be

  • Defender for Endpoint logs

  • Defender for Office 365 logs

  • Intune logs

  • Microsoft 365 Audit Logs

  • Azure AD Activity Logs

  • Cloud App Security Logs

  • Azure Information Protection Logs

Find elsewhere
🌐
Reddit
reddit.com › r/azuresentinel › cost for simple sentinel deployment
r/AzureSentinel on Reddit: Cost for simple Sentinel deployment
October 15, 2024 -

Sorry if this is a stupid question, but I'm not finding any answers that directly answer my questions about Sentinel cost for our beginner usage. After somewhat struggling with alerting in 365/Entra, I'm finding that Microsoft is moving a lot of alerting into Sentinel, presumably to add yet another source of incoming payment. As for the scope of our proposed Sentinel usage, strictly within Entra/365/Teams for now. I see where Microsoft says that Sentinel for Entra is free (assuming Teams and other normal internal stuff with separate licensing), though I imagine only for the normal retention period. If we limit our usage to just internal Entra/365 products for ingestion and stick to default retention, is that Sentinel usage really free? Makes sense if free - just shifting to a better tool for alerting instead of improving the built-in alerting, I guess, since the built-in is lacking...

Top answer
1 of 3
6
Microsoft security consultant here. Sentinel runs on log analytics workspace, which is an Azure resource, therefore PAYG model. The cost will depend entirely on how many logs you are ingesting. Some key points First 5GB storage is free (each month, although don't quote me on this as I could be wrong now) O365 logs (exchange, teams and sharepoint) are free Azure activity logs are free as well. With the new XDR unified platform, there is no need to ingest the Device-* data tables. These used to be expensive as device logs are very noisy. Only companies that require data retention for these logs can forward them. Basic deployment MUST include entra id sign in logs + audit logs + service principals + non interactive logs + intune if it applies to your environment. You need to learn about data collection rules so you can filter out / drop columns you don't need, thus saving ingestion costs. Also, learn the different tables (basic and auxiliary) as by default, analytics tables are used across different sources. As a monthly cost reference, one of our customers has around 250 users, and the cost is around 10 £ (ingesting basic logs as mentioned above). Other customers are well in the 3 digits as they have larger cloud footprints ie firewalls, on prem services etc.
2 of 3
1
I suggest going on POC (30 or 60 day free trial?). Nobody can tell you how much things will cost since it depends on how much logs/event you generate. There's a connector in Content Hub called “Sentinel cost” that can help estimate cost based on what you ingest during the POC.
🌐
Reddit
reddit.com › r/azure › why did azure charge me almost $25 in one day for sentinel and log analytics workspace when i wasn't using it?
r/AZURE on Reddit: Why did Azure charge me almost $25 in one day for Sentinel and Log Analytics Workspace when I wasn't using it?
January 20, 2023 -

I'm kind of new to Azure, using for self study/projects. I typically pay under $2 a day in Azure for storage and other really small things. However, on one particular day, my charges jumped up to more than $26 (+$16 for sentinel, +$8 for log analytics workspace, and a few bucks for the storage charges I typically pay per day).

I wasn't even using Azure within the week which the boosted charges were incurred, and my VMs were all deallocated. Just not sure how the billing here adds up.

I'm thinking that Azure charges for some resources daily, and other resources (like sentinel and log analytics) on a different time increment. Or, this is an error.

I only have a basic support plan so I can't open a ticket in Azure...if anyone can point me to an answer here I would appreciate it a lot.

🌐
Reddit
reddit.com › r/azuresentinel › sentinel pricing advice for small (<25 users) business
r/AzureSentinel on Reddit: Sentinel Pricing advice for small (<25 users) business
April 26, 2025 -

We just migrated to GCC High, so RocketCyber, our current SIEM, doesn't work with it natively (and to be frank, I was never crazy about it). We had to set up a logic app, a VM, and slew of support apparatus in Azure to get it to ingest logs. It's getting quite expensive, so I'm looking at Sentinel as an alternative. I'm very confused about the pricing, with some sites saying it would practically be free, in my use case; others saying it could be hundreds or thousands of dollars a month.

We are 100% cloud-based and we only operate in Microsoft 365, so there are no third-party log sources. We have fewer than 25 full time employees, all of whom are running Windows 11 23H2 or 24H2 and have E3 licenses with Defender Plan 2. They work a standard 8 hour day, 5 day week. IdP is Entra, and all devices are enrolled in Intune. We already run Defender for Endpoint and EDR on devices.

With this scenario, given that I would only need to ingest O365, Entra, and Intune logs, with 6 months to 1 year of retention, what kind of pricing am I looking at?

🌐
Reddit
reddit.com › r/azure › sentinel cost
r/AZURE on Reddit: Sentinel cost
September 24, 2019 -

Can someone help me with the costs of Azure sentinel.

I understand that there is a cost for the amount data sent to it. Except certain M365 products which are free.

Is there any other cost? Like storage maybe?

Top answer
1 of 3
3

Just make sure to set a daily data ingestion limit is all I can say. Assigned an admin to start integrating this and he didn’t tune the filter for security logs being sent and we had like 2k in charges in just a few days.

2 of 3
1

https://azure.microsoft.com/en-us/pricing/details/azure-sentinel/

Taken directly from the pricing page...

Data Retention

Once Azure Sentinel is enabled on your Azure Monitor Log Analytics workspace, every GB of data ingested into the workspace can be retained at no charge for the first 90 days. Retention beyond 90 days will be charged per the standard Azure Monitor Log Analytics retention prices.

Azure Monitor Log Analytics

Azure Sentinel is built on the proven foundation of Azure Monitor Log Analytics platform and enables an extensive query language to analyze, interact with, and derive insights from huge volumes of operational data in seconds. Azure Sentinel is billed based on the volume of data ingested for analysis in Azure Sentinel and stored in Azure Monitor Log Analytics workspace. Please refer to the Azure Monitor Log Analytics pricing for the related data ingestion charges.

Automation and Bring your own Machine Learning

Azure Sentinel integrates with many other Azure services providing enhanced capabilities for Security Information and Event Management (SIEM) and Security Orchestration and Automation and Response (SOAR). Some of these services may have additional charges:

  • You can use Azure Logic Apps to automate your security responses. Please refer to Azure Logic Apps pricing page for related costs.

  • You can bring in your own machine learning models for customized analysis. Please refer to Azure Machine Learning Studio and Azure Databricks pricing to understand the related costs.

🌐
Reddit
reddit.com › r/sysadmin › splunk vs azure sentinel costs?
r/sysadmin on Reddit: Splunk vs Azure Sentinel Costs?
December 20, 2021 -

I see people post about Splunk being too expensive to be an option for them.

If Splunk costs too much, could Azure Sentinel be a more economical option or are they similarly priced?
Is Azure Sentinel included in any Azure or Office 365 plans you may already be paying for?

🌐
Reddit
reddit.com › r/azure › azure sentinel is ga! how exactly does pricing work?
r/AZURE on Reddit: Azure Sentinel is GA! How exactly does pricing work?
May 9, 2017 -

I combined the pricing charts from several different Azure Pricing guides to show the minimum costs for Azure Sentinel in various US datacenters. My consulting firm is also giving away free 30-day PoCs of Azure Sentinel for up to 5 servers if you're interested in having someone else set it up for you. (PoC request is linked from the blog.)

🌐
Reddit
reddit.com › r/azure › be careful with the azure sentinel benefits if you do not want a surprise at the end of the month
r/AZURE on Reddit: Be careful with the Azure Sentinel benefits if you do not want a surprise at the end of the month
November 1, 2021 -

Azure Sentinel Benefits described here

In our education org, we've got ~700 A5 Security licensed faculty and about 900-1000 daily (weekdays) used windows devices including servers.

The benefit would give us about 3.5 GB daily allowance, but the actual data pulled into our log analytics workspace was 7 GB-10 GB.

Conservatively assuming 3.5 GB per weekday overage gives us at least 70GB+ per month for both Sentinel and Log Analytics Workspace ingestion which gives us at least 450 per month CAD on top of our normal bill.

Compound this with the fact that this is not reflected in cost management, but is reflected on the end of the month bill makes this difficult to monitor and account for.

If you're setting up Azure Sentinel for the first time, you do get some free data intake per day for a trial period, I believe. Keep all this in mind if you're looking at setting up integration between Defender 365 and Sentinel.

🌐
Reddit
reddit.com › r/azuresentinel › microsoft sentinel cost workbook
r/AzureSentinel on Reddit: Microsoft Sentinel Cost workbook
September 4, 2023 -

Hi,

Started with the Sentinel 31 days trial 2,3 days ago. Had a quick look at the Microsoft Sentinel Cost workbook, as it looked promising. As noted in the description “it provides insight about possible impact of the Microsoft 365 E5 offer”.

According to https://azure.microsoft.com/en-us/pricing/offers/sentinel-microsoft-365-offer/ the E5 entitles for a 5 MB per user per day grant including Microsoft 365/XDR (or whatever it may be called now, tomorrow lol) advanced hunting data:

Now here’s the problem. Providing the value of the E5 licesens has absolutely no impact on the output … xd

No E5 added

E5 added

And, yes, I’m ingesting the advanced hunting tables as shown below:

Anyone ? Additionally, are you Guys aware of any other method to calculate or include the grant into the overall calculation?

Thanks !

🌐
Reddit
reddit.com › r/azuresentinel › reducing the costs of azure sentinel
r/AzureSentinel on Reddit: Reducing the costs of Azure Sentinel
July 11, 2024 -

Is there something that can be done to reduce the volumes of logs (such as removing noise, filtering, etc) before being ingested into Azure Sentinel thus reducing the costs? Is there the possibility to pass everything through a tool such as fluentd to do the filtering before forwarding them into Azure Sentinel or is this not practical?

Top answer
1 of 5
11
There are many ways to do so. But in general, it depends on the type of log you want to reduce, then one or the other way is the best. If its like a cef based log type such as firewall, then i would say logstash or cribl is a great tool to do so. I have done alot with logstash, basic stuff really, but such as removing not needed stuff, many fields have no use for security analysis, so i simply remove it, so instead of 1500bytes per event, im around 600 or so. Also null out fields with no value, so the additionalextensions field often contain fields with no value, well, if no value why bring the field? If its ama based such as windows Security event or Linux logs, then you can do alot with the dcr, one thing is selecting what you want to collect, but you can also apply conditions to it. You can do alot with dns filtering, remove the mde, ama, arc, and all those agent based dns queries, what parts of dns is valuable for detection? I generally remove the conditional access policy results from noninteractivesignins since they are not really super relevant for that, and i can go and watch them in the gui if needed. There are many tools available to manage your data ingestion. My approach is always to answer the question, why am i ingesting this? And well... If i cant answer it, then dont ingest it. Then you can do much more advanced stuff with splitting destinations so some go to sentinel, some goes elsewhere. That could be based off inline threat intelligence mapping, or context based. But generally, the Microsoft tools on that end are lacking alot unfortunately. Ama for securityevents use xpath v1, from 1999... Its not super flexible...
2 of 5
4
Do you have experience with Cribl? https://cribl.io/blog/integrating-cribl-logstream-with-azure-sentinel-a-practical-walkthrough/ And, here's a couple resources: Reduce costs: https://learn.microsoft.com/en-us/azure/sentinel/billing-reduce-costs Manage and monitor costs for Microsoft Sentinel: https://learn.microsoft.com/en-us/azure/sentinel/billing-monitor-costs
🌐
Reddit
reddit.com › r/azure › azure sentinel on azure pricing calculator
r/AZURE on Reddit: Azure Sentinel on Azure Pricing Calculator
May 15, 2019 -

Anyone here knows if I should include Azure Log Analytics in my pricing when I compute for Azure Sentinel on the Azure Pricing Calculator?

Or am I totally asking the wrong question?

PS. new to Azure Sentinel

🌐
Reddit
reddit.com › r/office365 › pricing guide for azure sentinel
r/Office365 on Reddit: Pricing Guide for Azure Sentinel
September 15, 2018 -

Microsoft finally released Azure Sentinel to GA this week! As always, their pricing page is a bit confusing. So I put together this pricing guide for Azure Sentinel and Log Analytics to help explain the minimum costs for the service.

The great news is that ingesting the security logs from the Microsoft 365 E5 suite is included for free!