The SIEM your Microsoft logs are already free on — Microsoft Sentinel is a cloud-native SIEM billed on the data you ingest, not per seat. Azure Activity, Microsoft 365 audit logs and Defender XDR alerts ingest free; everything else runs ~$4.30/GB, or ~$2.96 on a commitment.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Data residency & processing — not the same question
Stored in
Central India · Jio India West · Jio India Central
Same region as the Log Analytics workspace. Data lake: Central India.
Processed in
A US region
Microsoft documents that workspaces outside Europe, Israel and China are processed in the US.
If your obligation is worded as storing data in India, an India region meets it. If your regulator, board or contract speaks about processing or cross-border transfer, settle that before the PoC — the full answer is in the FAQ. Source: Microsoft’s geographical availability and data residency documentation.
Quick answer
This page covers Microsoft Sentinel — the SIEM. The other pillars:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Microsoft’s cloud-native SIEM — it collects logs from across your estate, correlates them into incidents, and gives the SOC one place to hunt and respond. SaaS on Azure, queried with KQL.
What consolidation actually replaces, dimension by dimension.
| Dimension | No / separate AI tool | Microsoft Sentinel |
|---|---|---|
| Pricing axis | Per device or per user | Per GB ingested per day |
| Microsoft logs | Paid like any other source | Azure Activity, M365, XDR alerts free |
| High-volume logs | Full rate or drop them | Data lake tier at a fraction of analytics |
| Infrastructure | Servers, storage, upgrades | SaaS on Azure — nothing to run |
| SIEM and XDR | Two consoles, manual correlation | One incident queue in Defender |
| Retention | Priced from day one | 90 days included, then charged |
| Honest caveat | — | Third-party ingest escalates the bill |
| Best fit | — | Microsoft-standardised estates |
The SIEM of choice for Microsoft estates — for non-Microsoft log volume, on-prem or air-gapped, weigh Splunk or Elastic (TechBag sells Splunk).
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Sentinel is switched on top of an Azure Monitor Log Analytics workspace — that workspace is where your data actually lives, and it is why Sentinel and Log Analytics charges can appear as separate line items on older classic pricing. The first 90 days of retention are included.
Hundreds of connectors pull logs in — first-party Microsoft sources (Entra, Defender XDR, Azure Activity, M365) plus syslog/CEF, AWS, GCP and third-party appliances. Whether a source is free or paid is the single biggest driver of your bill.
Scheduled KQL rules, near-real-time rules and Microsoft's multistage attack detection turn raw events into alerts and incidents. Note: once you move to the Defender portal, the Defender XDR correlation engine takes over incident grouping from Fusion.
A low-cost tier for high-volume, low-value logs — ingest around $0.05/GB, storage around $0.026/GB/month billed on a uniform 6:1 compression rate, and queries charged per GB scanned. This is how you keep firewall and proxy logs without paying analytics rates for them.
Sentinel is consolidating into the Microsoft Defender portal for unified SIEM + XDR operations, and now exposes an MCP server so AI agents can query the data lake and graph. The Azure portal experience retires on 31 March 2027.
One workspace where people meet, make, and share — work moving in one place, not emailed between tools.
Sentinel collects, correlates and stores security telemetry — and the tier each table lands in is what sets your bill. Here are the five pieces that matter. Part of Defender XDR, managed in one portal, with Security Copilot AI.
First-party Microsoft sources, syslog/CEF, AWS, GCP and third-party appliances.
Azure Activity, M365 audit logs and Defender XDR alerts ingest at no charge.
High-volume, low-value logs at roughly $0.05/GB ingest and $0.026/GB/month storage.
Redact, split, filter and normalise data as it lands — the main lever on your bill.
KQL-driven detections plus hundreds of out-of-the-box templates from the Content hub.
Behavioural baselining across identities and hosts to surface anomalies rules miss.
Query the whole estate proactively; bookmarks and hunts preserve investigation context.
Ingest indicators, match them against your telemetry, and use the free MDTI feed.
Automated response built on Azure Logic Apps — billed separately from Sentinel.
Route, tag, assign and close incidents automatically without writing a playbook.
In the Defender portal, Sentinel and Defender XDR incidents merge into one queue.
Generative-AI triage plus an MCP server exposing the data lake and graph to AI agents.
Endpoint protection, XDR and Security Copilot.
The platform vision, explained by Microsoft.
The low-cost tier that changes SIEM economics.
Controlling the bill — the buying decision.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets Sentinel apart (and where Splunk or Elastic may fit better).
Every SIEM is priced on data volume, but the detail that decides Sentinel's economics is which sources are free. Azure Activity logs, Office 365 audit logs (SharePoint, Exchange, Teams) and security alerts from the whole Defender XDR family ingest at no charge. For an organisation already standardised on Microsoft 365 and Azure, that means a large share of the telemetry a SOC actually wants is free to collect, and you pay mainly for the third-party sources you add. This is the single strongest financial argument for Sentinel, and it is a real one rather than a marketing claim — Microsoft documents the free data types explicitly. The corollary matters just as much: if your noisiest logs come from non-Microsoft firewalls, proxies and network sensors, none of that discount applies to you, and the bill is set by whatever those devices emit.
The oldest problem in SIEM is that you are forced to choose between keeping a log and affording it. Compliance says retain everything; the analytics rate says retain nothing you do not need to alert on. Sentinel's data lake tier is the structural answer: high-volume, low-value logs go into a tier that ingests at roughly $0.05/GB and stores at roughly $0.026/GB/month, billed on a uniform 6:1 compression rate — so 600 GB of raw data bills as 100 GB — with KQL querying built in and charged per GB scanned. You keep the firewall and proxy data for the auditor and the incident responder without paying analytics rates for logs nobody writes a detection against. Getting the tiering right is most of the work in controlling a Sentinel bill, and it is exactly the modelling TechBag does before you sign.
Sentinel's native tie to Defender XDR is the operational argument. In the Defender portal, alerts from Sentinel analytics rules and alerts from Defender XDR land in one unified incident queue, correlated by Defender's own engine rather than sitting in two consoles waiting for an analyst to notice they are the same attack. Entity pages for users, devices and IP addresses merge Sentinel and Defender data into a single view, and advanced hunting queries span both. For a SOC that already runs Defender for Endpoint, Defender for Office 365 and Entra ID Protection, this removes the integration work that a third-party SIEM makes you do and maintain. It is also why the portal transition below is not merely a UI change.
This is the most important fact for anyone buying or renewing Sentinel right now, and it deserves to be stated plainly rather than buried. Microsoft Sentinel will no longer be supported in the Azure portal after 31 March 2027; all customers move to the Microsoft Defender portal. Microsoft says the transition itself carries no extra cost and billing is unchanged, but the operational changes are real and worth scoping early: the Fusion correlation rule is disabled in favour of the Defender XDR engine, some automation-rule conditions behave differently, Workspace Manager is not available, incidents created through the API or manually do not sync to the Defender portal, and the IdentityInfo table stops supporting table-level RBAC. If you have built automation against any of those, plan the migration rather than discovering it at the deadline.
Being honest, and TechBag sells Splunk too: Sentinel's cost advantage is conditional on your estate being Microsoft-shaped. The free first-party connectors are genuinely valuable, but the moment your highest-volume sources are non-Microsoft — network firewalls, web proxies, NDR sensors, custom application logs — you are paying analytics rates on the noisiest data you own, and Sentinel bills can escalate quickly and less predictably than an EPS-based or capacity-based model. Splunk remains ahead on raw search power, detection-engineering flexibility and handling genuinely diverse telemetry at scale, which is why mature detection teams still choose it. QRadar's EPS-based pricing is more predictable for regulated buyers who need to forecast a number. And Sentinel is SaaS-only on Azure, so if you have a hard on-premises or air-gapped requirement, it is simply not a candidate.
Microsoft Sentinel is the right SIEM for organisations already standardised on Microsoft 365 and Azure that want SIEM and XDR in one console, value free first-party telemetry, and can use the data lake tier to keep high-volume logs affordably. It is a 2025 Gartner Magic Quadrant Leader and the fastest-growing enterprise SIEM. It is the wrong choice if your log volume is dominated by non-Microsoft sources, if you need on-premises or air-gapped deployment, or if you have a mature detection-engineering team whose value comes from Splunk's search flexibility. TechBag sells Splunk as well, and the useful thing we do here is model your actual GB/day by source before you commit — the number that decides this, and the one vendors are slowest to help you calculate. Quoted in INR with GST.
Inventory your log sources and estimate GB/day for each, separating free first-party Microsoft sources from paid third-party ones. This number decides everything. TechBag does this modelling free.
Stand up the Log Analytics workspace, connect the free Microsoft sources first, then add third-party feeds deliberately — deciding analytics tier versus data lake tier per table.
Enable Content hub rule templates, tune out the noise, build automation rules and playbooks, and set retention per table rather than globally.
Operate in the Defender portal ahead of the 31 March 2027 Azure retirement, review the bill monthly against the model, and re-tier tables as volumes change.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Our Microsoft logs — Entra, M365 audit, Defender alerts — ingest free, which meant most of what our SOC actually watches cost us nothing to collect. That changed the business case completely.”
“One incident queue across Sentinel and Defender XDR is the real win. We stopped correlating by hand across two consoles, and mean time to triage dropped noticeably.”
“The data lake tier let us finally keep twelve months of firewall logs for the auditor without paying analytics rates on data nobody writes a detection against.”
“KQL is genuinely powerful once your team learns it, and the Content hub templates gave us a working detection set on day one rather than month three.”
“Honest warning: our first month's bill was double the estimate because nobody modelled the proxy logs. Get the ingest tiering right before you turn connectors on, not after.”
“We had automation built on Fusion and the Workspace Manager. The Defender portal move meant reworking it — worth scoping that migration early rather than at the deadline.”
“For a mixed estate with heavy non-Microsoft network gear, we ran the numbers and Splunk was the better fit. TechBag told us that straight even though they sell Sentinel.”
“As an Indian enterprise, having TechBag model the GB/day by source in INR before we committed was the difference between a predictable budget and a surprise.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint-security (EDR/XDR) market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Gartner MQ Leader 2025 — this page.
The grid nobody publishes — detection efficacy & agent maturity vs Microsoft-estate fit and TCO.
Deep on Microsoft data; ingest cost varies elsewhere.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
The SIEM leaders — honest lanes; the edge is free first-party ingest + one incident queue with Defender. Deepest search, or on-prem? Splunk. We say so (and sell it).
| Dimension | Microsoft Sentinel | Splunk Enterprise Security | IBM QRadar | Google Security Operations | Elastic Security |
|---|---|---|---|---|---|
| Position | Cloud-native SIEM for Microsoft estates | The search-power incumbent | The regulated-industry stalwart | Cloud-agnostic security analytics | Open, ELK-based |
| Pricing axis | Per GB ingested per day | Workload or ingest — historically costly | EPS-based — predictable to forecast | Flat per-employee-ish, volume-agnostic | Resource-based; free self-managed tier |
| Microsoft-estate integration | Native; first-party logs free | Good connectors, paid ingest | Connectors, no native tie | Connectors, no native tie | Connectors, no native tie |
| Search & detection engineering | KQL — powerful, Azure-shaped | SPL — still the benchmark | AQL, strong OOTB content | YARA-L, very large scale | Lucene/ES|QL, very flexible |
| Deployment model | SaaS only, on Azure | Cloud, on-prem or hybrid | Cloud or on-prem | SaaS only, on Google Cloud | Cloud, on-prem, air-gapped |
| Cost predictability | Varies with log volume — model it first | Historically the expensive option | EPS licensing forecasts cleanly | Volume-agnostic pricing | Self-managed cost is controllable |
| Long-term log retention | Data lake tier at ~$0.026/GB/mo | Available, priced accordingly | Available | 12 months hot by default | Frozen/searchable snapshots |
| SOAR & automation | Playbooks on Logic Apps (billed separately) | Splunk SOAR (own product) | QRadar SOAR | Native SOAR included | Basic; often paired with a SOAR |
| AI in the SOC | Security Copilot + MCP server for agents | Cisco AI Assistant | watsonx-assisted | Gemini-powered | Elastic AI Assistant |
| The thing to plan around | Azure portal retires 31 Mar 2027 | Cisco integration reshaping roadmap | SaaS assets sold to Palo Alto; XSIAM migration | Google Cloud dependency | You run and tune it yourself |
| Best fit | Microsoft-standardised estates | Mature detection-engineering teams | Regulated buyers needing forecastable cost | Huge volume, cloud-agnostic | Budget-constrained or air-gapped |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Microsoft Sentinel is one of 30 SIEM & log management products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →
Sentinel bills on data ingested, so this is the only sum that matters. The baseline puts every GB on the analytics tier at pay-as-you-go (~$4.30/GB). The optimised figure moves your low-value logs to the data lake tier (~$0.05/GB) and prices the rest at the 100 GB/day commitment rate (~$2.96/GB) once you qualify. Microsoft’s published East US rates at ~₹84/USD; regional rates differ and Microsoft calls them estimates, not quotes. Excludes Logic Apps, Functions and Copilot, which bill separately.
Free first-party sources — Azure Activity, Microsoft 365 audit logs and Defender XDR alerts — are excluded from both figures, so count only your billable GB. The commitment rate applies at 100 GB/day and above. Illustrative: your TechBag quote models your real sources.
Sentinel is billed on data ingested per day, not per user or device — so the only figure that matters is your GB/day, by source. Rates below are Microsoft’s published East US figures (converted at ~₹84/USD) and vary by region; Microsoft describes them as estimates, not quotes. TechBag models your real ingest before you commit and quotes in INR with GST.
Best for starting out or low volume
Best above ~69 GB/day
Best for high-volume, low-value logs
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
What is your GB/day by source, and which of those sources are free first-party Microsoft logs?
Which tables belong in the analytics tier and which in the cheaper data lake tier? This is the main cost lever.
Does your volume justify a commitment tier? The break-even against pay-as-you-go is roughly 69 GB/day for the 100 GB commit.
How long must each data type be kept for compliance, given 90 days is included and the rest is charged?
What is your plan for the 31 March 2027 Azure portal retirement, and what automation depends on Fusion or Workspace Manager?
Does your obligation speak about STORING data in India or PROCESSING it there? Sentinel stores in Central India / Jio India regions but processes in a US region — settle which one your regulator means before the PoC.
Have you priced Logic Apps playbooks, Azure Functions connectors and Security Copilot SCUs separately from Sentinel itself?
If your highest-volume logs are non-Microsoft, have you compared Splunk or an EPS-priced option? TechBag advises across both.
Have you modelled the annual bill in INR with GST, including growth in log volume?
Model your real GB/day by source before you commit, plan the 31 March 2027 Defender portal move, or get an honest Sentinel-vs-Splunk comparison — in INR/GST.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.