We had a question on the Azure Sentinel pricing that was made available last week with the GA.


What data can be ingested at no cost with Azure Sentinel?
Azure Activity Logs, Office 365 Audit Logs and alerts from Microsoft Threat Protection are available for ingestion at no additional cost.


Just to clarify, the cost here is the cost of ingestion in log analytics? There are still charges for -

  • Analysis of this data with Sentinel
  • Retention of these ingested logs beyond the first 90 days?