logo

Reducing Microsoft Sentinel Costs Without Compromising Detection – Part 2: The Firewall Quest

ID: ab43f81f-a67b-5725-8b0d-d12e04e63040

STIX ID: report--ab43f81f-a67b-5725-8b0d-d12e04e63040

Feed Name: NVISO Labs

Date Published: 2026-07-07

Date Updated: 2026-07-07

Author: Christos Giampoulakis

...
...

This blog demonstrates using Microsoft Sentinel Summary Rules to aggregate Windows Filtering Platform firewall traffic into 20-minute summaries (stored in a Data Lake), including KQL parsing examples, ASIM-compatible parser functions, and an analytic rule to detect vertical port scans — aiming to substantially reduce ingestion costs while retaining essential detection and incident response visibility.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.