@psec-comp Thank you for reaching out to us. As I understand that you are interested in assessing how well Microsoft Sentinel can cluster alerts together and you are looking to upload a small amount of EDR logs and alerts in JSON format to Azure Sentinel for processing.
I would like to suggest that you refer to the following resources that explain how to ingest logs of any format in Azure Sentinel:
https://www.youtube.com/watch?v=Voewqmt8xr0&list=PL8wOlV8Hv3o8ri_K_8c2THT_4ZJ_KKl90&index=12
https://www.youtube.com/watch?v=fzHyOqLPxCY&list=PL8wOlV8Hv3o8ri_K_8c2THT_4ZJ_KKl90&index=14
These videos provide step-by-step instructions on how to ingest logs of any format in Azure Sentinel. While they do not specifically cover how to use an Azure Storage account to upload logs, they should provide you with the information you need to get started.
I hope this helps. If you have any further questions or concerns, please let me know.
Please remember to "Accept Answer" if answer helped, so that others in the community facing similar issues can easily find the solution.