Microsoft Sentinel

Sentinel Data Lake

Proxy, firewall and DNS are the log sources you need most during an attack, and usually the first ones to drop out of the budget. Data Lake changes that arithmetic. We work out with you which data belongs in which tier, what it costs per month, and how the move runs.

Thumbnail of the Microsoft Sentinel Data Lake webcast

Christopher Brumm and Marvin Rose, both Cyber Security Architects at glueckkanja, walk through the architecture, cost optimization and use cases of Data Lake, with demos from a live environment.

What stops most organizations from keeping all of their security data in Microsoft Sentinel is almost always the cost. For years, the Analytics tier priced comprehensive logging out of reach, so high-volume sources were sampled, dropped, or pushed into a separate platform such as Azure Data Explorer. That was not carelessness, it was rationing: remembering was expensive, and a great deal of visibility was lost. Data Lake changes that arithmetic. Storage runs at roughly two percent of the Analytics rate, ingestion at 0.065 USD per GB against 5.59, everything compressed six to one, with retention of up to twelve years. Storage and compute are billed separately, so large volumes stay cheap and you pay only when you query. That alone replaces the Basic and Auxiliary tiers and removes the need for a separate low-cost store alongside Sentinel. The more interesting part sits next to it: because the data is cheap and stays live, the way you work with it changes. What follows from that for an existing environment depends on the tables already running today.

The Questions to Settle

Icon of a branched structure, symbolizing the mapping of log sources to storage tiers

Which Log Source Belongs in Which Tier

Ingestion volume, IoC matching, hunting value, detection needs and the overlap with Defender XDR tables decide it. Sign-in logs and control plane stay in the Analytics tier, while proxy, DNS and firewall move to Data Lake and come back up through KQL Jobs whenever a detection needs them.
Icon of a gauge, symbolizing separate billing of storage and compute

What It Costs at the End of the Month

Storage, queries and the re-ingestion for detections are billed separately. 300 GB per month at 24 months of retention comes to roughly 140 USD, and a good third of that is the work with the data rather than the storage itself.
Microsoft Sentinel icon

How Analysts Work With It

Full KQL runs directly on Data Lake, with no promotion to the Analytics tier. Async queries reach past the interactive limits, Notebooks no longer need an Azure Machine Learning workspace, Sentinel Graph shows blast radius and attack paths, and the Sentinel MCP Server takes natural-language questions from VS Code.
Icon of a task list, symbolizing the migration steps

What Happens to the Old Constructions

Basic and Auxiliary Logs, summary rules, search jobs and a separate store in Azure Data Explorer lose their purpose. The move runs table by table, and it ends with the question of what can be switched off and when the retention obligations allow it.

The Whitepaper

How We Help With It

Icon for automated threat investigation

Cloud Security Operations Center

Running Microsoft Sentinel and Defender around the clock, including detection engineering on the tables pulled up out of Data Lake.

Icon for configuration analysis

Security Consulting

An assessment of the existing log strategy, tiering per table, and a migration plan that accounts for retention obligations and compliance requirements.

Icon of a lock for hardening

Managed Red Tenant

The hardened administration environment for privileged access, so that analysis in Data Lake does not run over a compromised path.

Let's talk about your log strategy.

Tell us which sources sit in Sentinel today and what you have planned. We send you the whitepaper and sort out with you which table belongs in which tier.
Jan Geisbauer
In our incident analyses, the same logs are almost always missing: proxy, firewall, DNS. Not because nobody wanted them, but because they were too expensive in the Analytics tier. With Data Lake that becomes a question of arithmetic instead of a question of going without. The work lies in deciding, table by table, what has to stay in the Analytics tier and what can be mirrored.
Jan GeisbauerSecurity Lead