Reducing Microsoft Sentinel Costs Without Compromising Detection – Part 2: The Firewall Quest
ID: ab43f81f-a67b-5725-8b0d-d12e04e63040
STIX ID: report--ab43f81f-a67b-5725-8b0d-d12e04e63040
Feed Name: NVISO Labs
This blog demonstrates using Microsoft Sentinel Summary Rules to aggregate Windows Filtering Platform firewall traffic into 20-minute summaries (stored in a Data Lake), including KQL parsing examples, ASIM-compatible parser functions, and an analytic rule to detect vertical port scans — aiming to substantially reduce ingestion costs while retaining essential detection and incident response visibility.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
