Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel1 / 5
You need Microsoft Sentinel security logs to remain available for compliance for 2 years. The workspace keeps Sentinel analytics logs interactively for 90 days, and you want to retain older data at lower cost without moving the table out of the analytics tier. What should you configure for the relevant tables?
CorrectIncorrect
Alex
Use table-level total retention for long-term compliance retention. In a Microsoft Sentinel workspace, analytics retention keeps data available for near-real-time analytics, alerting, hunting, and workbooks. Total retention extends retention beyond that interactive period for long-term access. Configure the relevant tables with total retention of 730 days for two years. Increasing analytics retention to 730 days can also keep data interactive, but it is not the lower-cost approach when only older compliance data needs occasional access. Moving a table to the data lake tier only is a different choice that can remove real-time Sentinel capabilities for that data.
Sourcelearn.microsoft.com
Follow-up answers are available in the app. Create a free account — no credit card required.
Question 1 of 5
Create a free account