Microsoft Sentinel is a cloud-native security information and event management (SIEM) and security orchestration, automation and response (SOAR) service. It does not have its own storage: you enable Sentinel on an Azure Monitor Log Analytics workspace, and all ingested data lands in tables in that workspace, such as SigninLogs, SecurityEvent and CommonSecurityLog. So the first design decision is how many workspaces you need, where they live, and who can see them.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.