Security logs are valuable but expensive when ingested at full price. High-volume sources such as firewall flows, proxy logs or DNS queries may be needed for investigations and compliance, yet rarely used for real-time detection. Sentinel and Log Analytics therefore offer tiers, called table plans, that trade features for cost. Microsoft has been evolving these options, so focus on the concepts and check current names in the portal.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 6 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.