Steps and procedure to setup Azure Sentinel with free data sources for KQL Query ?

EnterpriseArchitect 5,036 Reputation points
2024-03-15T03:39:00.6266667+00:00

I need some help and assistance in configuring my current Azure Entra ID Premium P2 tenant to allow Azure Sentinel to ingest logs and query using KQL with no additional or monthly cost.

I can see the below article mentioning there is no data charged when ingesting these alerts and logs to Sentinel:

Microsoft Sentinel data connector Free data type
Azure Activity Logs AzureActivity
Azure Activity Logs AzureActivity
Microsoft Entra ID Protection SecurityAlert (IPC)
Office 365 OfficeActivity (SharePoint)
OfficeActivity (Exchange)
OfficeActivity (Teams)
Microsoft Defender for Cloud SecurityAlert (Defender for Cloud)
Microsoft Defender for IoT SecurityAlert (Defender for IoT)
Microsoft Defender XDR SecurityIncident
SecurityAlert
Microsoft Defender for Endpoint SecurityAlert (MDATP)
Microsoft Defender for Identity SecurityAlert (AATP)
Microsoft Defender for Cloud Apps SecurityAlert (Defender for Cloud Apps)

https://video2.skills-academy.com/en-us/azure/sentinel/billing?tabs=simplified%2Ccommitment-tiers#free-data-sources

However, I am not sure where to start to configure the Azure Sentinel part.

I assume this https://azure.microsoft.com/en-au/pricing/details/microsoft-sentinel/ pricing is only applicable when I am ingesting some data sources, other than the above.

Thank you in advance.

Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
11,254 questions
Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
370 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,040 questions
Microsoft Entra
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,351 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Clive Watson 5,951 Reputation points MVP
    2024-03-15T11:59:05.59+00:00

    That is correct you enable those data connectors from the [Content Hub]in Microsoft Sentinel. Workbooks like "Workspace Usage" will show you that a Table is billable or not just to confirm during the trial period. https://video2.skills-academy.com/en-us/azure/sentinel/quickstart-onboard#install-a-solution-from-the-content-hub