MS Sentinel gurus - Does anyone know if it's possible to take advantage of Microsoft log sources being <https://learn.microsoft.com/en-us/azure/sentinel/billing?tabs=free-data-meters#free-data-sources|free to ingest into Sentinel> (Such as Azure Activity Logs, Office 365 etc) while still sending the logs in via Cribl Stream?Obviously the preference would be to send everything via Cribl, but I presume the free ingestion of Microsoft logs will be calculated/only count via the built in Sentinel data connectors for each of those log sources - Whereas if you start ingesting those through Cribl, you'd have to send it through a log source like syslog in which case you then get billed for everythingAnyone with experience using Cribl with Sentinel - Is that right, or is there a sneaky workaround?
Question
Is it possible to take advantage of Microsoft log sources being free to ingest into Sentinel?
Sign up
Already have an account? Login
Login to the community
No account yet? Create an account
Using your Cribl Curious or University Account
User Login Employee loginEnter your E-mail address. We'll send you an e-mail with instructions to reset your password.
