Firewall network traffic logs are the largest driver of Microsoft Sentinel ingestion costs. Yet they remain a critical source of information for threat detection, investigations & incident response. Explore how Sentinel Summary Rules can reduce the cost of ingesting firewall traffic events while retaining the visibility SecOp teams need to detect threats & investigate incidents.
Series: Reducing Microsoft Sentinel Costs Without Compromising Detection
A series about Detection Engineering and effective ways to reduce Microsoft Sentinel costs without compromising Detection capabilities.
Reducing Microsoft Sentinel Costs Without Compromising Detection – Part 1: The Summary Rules Quest
This blog is the first in a series exploring how Summary Rules, together with Auxiliary or Data Lake storage, can help organizations optimize SIEM costs without compromising core threat detection and monitoring capabilities.


