Microsoft Sentinel Log integrity and non-repudiation

Darren Hughes 0 Reputation points
2024-09-03T12:09:04.5066667+00:00

I have a question about Microsoft Sentinels Log integrity and non-repudiation properties of audit logs. For Example SPLUNK uses Bucket hashing to protect it's logs. Does Sentinel via Azure have any such protection, or can anyone shed light on how the log files immutability is guaranteed?

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,123 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Clive Watson 6,351 Reputation points MVP
    2024-09-03T13:18:34.5966667+00:00

    source:

    https://video2.skills-academy.com/en-us/azure/azure-monitor/logs/data-security#3-the-azure-monitor-service-receives-and-processes-data

    Data in database storage can't be altered once ingested but can be deleted via purge API path. Although data can't be altered, some certifications require that data is kept immutable and can't be changed or deleted in storage. Data immutability can be achieved using data export to a storage account that is configured as immutable storage.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.