logo

Reducing Microsoft Sentinel Costs Without Compromising Detection – Part 1: The Summary Rules Quest

ID: 2784269c-2ba0-5d4d-94cb-f65dabc0f3ac

STIX ID: report--2784269c-2ba0-5d4d-94cb-f65dabc0f3ac

Feed Name: NVISO Labs

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Christos Giampoulakis

...
...

This blog post explains how to reduce Microsoft Sentinel log storage costs by using Summary Rules together with Auxiliary/Data Lake (and optional split transformations) to store aggregated events in cost-efficient tiers while retaining the ability to perform investigations and alerts via analytic rules; it includes a data-tiers comparison, solution overview (splitting data, creating summary rules, and analytic rules), cost analysis, and contrasts with KQL jobs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.