Defender for Endpoint log retention

Luís Costa 226 Reputation points
2024-08-27T11:01:19.6966667+00:00

Hi there,

In order to increase data retention for CloudAppEvents or DeviceRegistryEvents tables i know we can ingest them in Microsoft Sentinel.

My question is if there is another way to store these logs? I just want to retain the logs for cold storage and ingesting them into Sentinel will have a significant ingestion cost.

Thanks

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,173 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
50 questions
0 comments No comments
{count} votes

Accepted answer
  1. Givary-MSFT 33,476 Reputation points Microsoft Employee
    2024-08-28T05:54:25.0133333+00:00

    @Luís Costa

    Thank you for reaching out to us.

    Yes, there is another way to store the logs from CloudAppEvents or DeviceRegistryEvents tables without ingesting them into Microsoft Sentinel. You can use Microsoft Defender for Endpoint to stream Advanced Hunting events to your Storage account.

    Reference: https://learn.microsoft.com/en-us/defender-endpoint/api/raw-data-export-storage

    Once the data is stored in your Storage account, you can use Azure Blob Storage lifecycle management to automatically move the data to cold storage after a certain period of time. This can help reduce the cost of storing the data over the long term.

    Reference: https://learn.microsoft.com/en-us/azure/storage/blobs/lifecycle-management-overview

    Let me know if you have any further questions, feel free to post back.

    Please remember to "Accept Answer" if answer helped, so that others in the community facing similar issues can easily find the solution.

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.