What you run · Microsoft Sentinel
Govern what enters the workspace
Microsoft Sentinel is the cloud-native SIEM built on a Log Analytics workspace: the Azure Monitor Agent and data connectors feed it through data collection rules, and detections are analytics rules written in KQL over the ASIM normalized schema. It is billed per GB as data enters the workspace, at pay-as-you-go rates or commitment tiers that reserve daily volume at a discount. We tier data before it reaches Log Analytics, normalize to ASIM upstream, and keep the full-fidelity history in a Lake beside it.
01Today
How a Microsoft Sentinel estate looks today
A Sentinel estate is billed per GB as data enters Log Analytics, verbose operational data at the same rate as security signal, with parsing pushed into every analytic rule.
What Microsoft Sentinel does best
Sentinel is the cloud-native consolidation play that actually works: KQL is a serious analytics language, the Defender integration means endpoint, identity, and email signals arrive already correlated, and for Microsoft-heavy estates the operational fit is hard to argue with. Commitment tiers reward predictable volume with real discounts.
The friction is what reaches Log Analytics and in what shape. Sentinel expects data in a consistent schema, and inconsistent field names across firewalls, identity providers, and endpoints mean every analytic rule carries its own parsing logic. Billed volume climbs when verbose operational data lands in the Analytics tier alongside the security events that belong there.
02The five verbs
What we do to a Microsoft Sentinel estate
Keep it and govern what flows in, shrink its footprint, cut what it costs, extend it with an agent, and replace only where replacement is honest.
The workspace, the analytics rules, and the Defender integration. Sentinel stays your SIEM, your team keeps working in it, and every KQL detection keeps firing on the same inputs it fires on today.
Verbose operational data tiers to lower-cost paths before it reaches Log Analytics, while high-value security events keep the Analytics tier.
Billed volume drops while detections keep their inputs, and the commitment tier gets right-sized against what actually flows into the workspace rather than against what the estate happens to produce.
An agent you own works Sentinel incidents, following entities into full-fidelity history the workspace never held.
Never. The control layer sits in front of Sentinel, and the Lake beside it, so the workspace does what it is best at on the data that earns its tier.
The letters mark where each verb acts in the drawing above
03The approach
ASIM upstream, the Lake beside
Normalizing to the ASIM schema upstream means firewall, identity, and endpoint events arrive in consistent fields, which keeps analytic rules simple across a large estate.
Migrations onto Sentinel stall when detections, parsers, and data sources are rebuilt by hand against an unfamiliar schema. We run the old SIEM and Sentinel in parallel against the same routed feed, so detections are validated firing in Sentinel before anything is retired. Yale New Haven Health moved 30,000+ endpoints onto Microsoft Sentinel in two weeks on exactly this pattern.
Full-fidelity copies land in object storage you own, so cheaper Sentinel tiers never mean losing access to raw history, and the next platform decision, whenever it comes, is a routing change.
04Questions
Asked about Microsoft Sentinel estates
How do you control Sentinel ingestion cost without losing detections?
Tier data before it reaches Log Analytics. High-value security events go to the Analytics tier, verbose operational data to lower-cost paths, and full-fidelity copies to storage you own. The billed volume drops while every detection keeps its inputs.
Can you migrate us from Splunk to Sentinel?
Yes, as a parallel run rather than a leap. Both platforms receive the same routed feed while detections are rebuilt and validated in Sentinel, and the cutover is a routing percentage rather than a weekend. The dual-license window collapses from quarters to days.
Does the Lake compete with Sentinel?
No. The Lake holds what the workspace should not have to: full-fidelity history at object-storage cost, replayable into Sentinel on demand. The workspace does detection on the data that earns its tier. Each does the job it is priced for.
Start with the review
You share your diagrams, we review them with you, and you leave with your version of the Logmetry Blueprint drawn on your Microsoft Sentinel estate. No system access, no obligation.