Skip to main content
Microsoft

Microsoft Sentinel

Microsoft's cloud-native SIEM/SOAR — pay-per-ingest, AI-based anomaly detection, 350+ pre-built data connectors.

Overview

Microsoft Sentinel in practice

Microsoft Sentinel is Microsoft's SIEM and SOAR platform, built on Log Analytics: no hardware of your own, new data sources attached through ready-made connectors, billing by the volume of data ingested. Anyone planning today has to plan the move as well — Sentinel now lives in the Microsoft Defender portal, and operation through the Azure portal ends on 31 March 2027, after which remaining customers are redirected automatically.

The second planning question is cost, because it hangs almost entirely on data volume. The tiers help: analytics tables for everything that must be detected in real time, cheaper tiers and the Sentinel data lake for logs kept only for later investigation. From 100 gigabytes a day a commitment tier pays off. Alendris runs Sentinel as the detection layer for NIS2 and KRITIS clients, with rules aligned to MITRE ATT&CK tactics and automated response playbooks.