Microsoft Sentinel cost: per GB of security data ingested
Sentinel bills per GB of data ingested and analyzed (on top of Log Analytics storage), with commitment tiers that discount at volume. High-volume log sources drive the bill. Filtering and tiering ingestion are the levers. Here is the model.
Quick answer
Microsoft Sentinel bills per GB of data ingested and analyzed (a Sentinel analysis charge on top of the underlying Log Analytics storage), with commitment tiers that discount the per-GB rate at higher daily volumes. High-volume, low-value log sources drive the bill, so filtering noisy logs before ingestion, using basic/auxiliary logs for low-value data, and right-sizing the commitment tier are the levers.
Microsoft Sentinel is a cloud-native SIEM, and like most SIEMs its cost is dominated by data volume: you pay to ingest and analyze the security logs it correlates. Because security data can be enormous, controlling what you ingest, and at what tier, is the heart of managing Sentinel cost.
Ingestion is the bill
Sentinel charges a per-GB analysis fee on data ingested, on top of the Log Analytics workspace storage the data lives in. The combined ingestion-and-analysis cost per gigabyte is the dominant line. A high-volume environment ingesting many log sources, firewalls, endpoints, cloud audit logs, can ingest terabytes, and the cost scales with it.
Commitment tiers and log tiers
| Lever | Effect |
|---|---|
| Commitment tiers | Discounted per-GB rate for a committed daily volume |
| Basic / auxiliary logs | Cheaper ingestion for low-value, high-volume logs |
| Ingestion filtering | Drop noise before it is ingested |
Committing to a daily ingestion volume unlocks a lower per-GB rate than pay-as-you-go, so a predictable high-volume workload saves by committing to its baseline. Basic and auxiliary log tiers offer cheaper ingestion for high-volume, low-value logs you need for occasional investigation but not real-time analytics. And filtering, dropping noisy or irrelevant logs before ingestion, cuts volume at the source.
Controlling Sentinel cost
Filter high-volume, low-value logs before ingestion, route logs that do not need real-time analytics to cheaper basic/auxiliary tiers, right-size the commitment tier to your steady baseline (committing to the variable top strands the discount), and set retention deliberately. The discipline mirrors Log Analytics and CloudWatch Logs: ingest what you will act on, and tier or drop the rest.
FAQ
How is Microsoft Sentinel priced?
Per GB of data ingested and analyzed (a Sentinel analysis charge on top of the underlying Log Analytics storage), with commitment tiers that discount the per-GB rate at higher committed daily volumes. Ingestion volume is the dominant cost, so high-volume log sources drive the bill.
How do I reduce Sentinel cost?
Filter high-volume, low-value logs before ingestion, route logs that do not need real-time analytics to cheaper basic or auxiliary tiers, right-size the commitment tier to your steady baseline, and set retention deliberately. Ingesting only what you will act on, and tiering or dropping the rest, is the core discipline.
What are Sentinel commitment tiers?
Pricing tiers where you commit to a daily ingestion volume in exchange for a lower per-GB rate than pay-as-you-go. A predictable high-volume workload saves by committing to its baseline daily volume, while pay-as-you-go suits variable or lower volume. Commit to the steady baseline, not the variable top.
What are basic and auxiliary logs in Sentinel?
Cheaper ingestion tiers for high-volume, low-value logs that you need for occasional investigation but not real-time analytics or alerting. Routing verbose, low-priority logs to these tiers reduces ingestion cost compared to putting everything in the standard analytics tier.
Why is my Sentinel bill high?
Usually high-volume log ingestion: many verbose sources (firewalls, endpoints, cloud audit logs) sending large volumes into the standard analytics tier. Filter noisy logs before ingestion, move low-value logs to basic or auxiliary tiers, and commit to your baseline volume for a discount to bring it down.
Does C3X estimate Sentinel cost?
Sentinel cost is driven by data ingestion volume, a usage input tied to your log sources. C3X prices the surrounding Azure infrastructure, and you model ingestion volume to estimate the per-GB SIEM charges.
What to do next
Estimate the infrastructure around your SIEM before you deploy. C3X reads your Terraform and prices your resources against a live catalog. Start with the quickstart.
Share this post
Try C3X on your own Terraform
Free and open source. No API key required. One command to install, one command to estimate.