Microsoft Sentinel (Azure SIEM) per-GB ingestion

Microsoft Sentinel (Azure SIEM) per-GB ingestion

Brand: Microsoft | Category: Network Security

SKU: DZH318Z0BWVD | Part #: DZH318Z0BWVD | MPN: DZH318Z0BWVD

Contact for Pricing — Request a Quote

Request a Quote Contact Us

About the Microsoft Sentinel (Azure SIEM) per-GB ingestion

Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation and Response (SOAR) platform deployed on Microsoft Azure infrastructure. The per-GB ingestion model enables organizations to ingest, analyze, and correlate security data from thousands of sources across hybrid and multicloud environments with consumption-based scaling. Built on Azure Log Analytics, Sentinel leverages machine learning and AI-driven threat detection to identify sophisticated attacks, anomalies, and insider threats in real time across network, endpoint, identity, and application layers.

The platform provides unified threat monitoring through a centralized workspace architecture, eliminating data silos and enabling security operations teams to correlate events across on-premises, cloud, and third-party systems. Sentinel integrates with Microsoft Defender ecosystem products and supports 300+ built-in connectors for third-party security tools, SaaS applications, and custom data sources. The ingestion-based model allows enterprises to pay for actual data consumption rather than fixed capacity, optimizing budget allocation as security monitoring scales.

Sentinel includes AI-powered incident investigation, automated response playbooks, threat hunting capabilities, and compliance-ready reporting. The platform supports integration with existing SOAR workflows, custom automation through Logic Apps, and API-driven extensibility for advanced security operations centers (SOCs) requiring sophisticated orchestration and remediation workflows.

Ideal for

  • Centralized threat detection and incident response across hybrid cloud infrastructure combining on-premises, Azure, AWS, and GCP workloads
  • Real-time endpoint security monitoring and threat hunting using Windows Defender, third-party EDR, and log correlation
  • Identity and access threat detection through Azure AD/Entra ID integration with anomalous sign-in and privilege escalation detection
  • Compliance monitoring and audit logging for regulatory frameworks including PCI DSS, HIPAA, SOC 2, and GDPR with automated evidence collection
  • Automated security incident response and remediation through playbook orchestration and third-party SOAR integration
  • Data exfiltration prevention and insider threat detection by analyzing user behavior patterns and data access anomalies

Technical specifications

ManufacturerMicrosoft
ModelSentinel (Azure SIEM)
Manufacturer Part NumberDZH318Z0BWVD
CategoryNetwork Security / SIEM / SOAR
PlatformAzure Cloud Native
Deployment ModelSoftware as a Service (SaaS)
Ingestion ModelPer-GB consumption-based
Built-on TechnologyAzure Log Analytics
Data RetentionConfigurable 30 days to 2+ years
Built-in Connectors300+
API SupportREST API, Azure SDK
Machine LearningAI-driven anomaly detection, behavioral analytics
Incident ManagementUnified incident dashboard, automated triage, investigation notebooks
AutomationLogic Apps, playbook orchestration, custom API integration
IntegrationMicrosoft Defender suite, third-party SIEM/SOAR, Azure services
AuthenticationAzure AD / Microsoft Entra ID
Compliance FrameworksPCI DSS, HIPAA, SOC 2, GDPR, NIST, ISO 27001
Availability99.99% SLA
Regional DeploymentMultiple Azure regions globally
Multi-tenancySingle workspace or multi-workspace federation

Available from Omnixon Global. Submit an RFQ and our team will confirm configuration and availability for your order.

Technical Specifications

BrandMicrosoft
CategoryNetwork Security
SKUDZH318Z0BWVD
Part NumberDZH318Z0BWVD
ConditionNew
ModelSentinel (Azure SIEM)
Manufacturer Part NumberDZH318Z0BWVD
PlatformAzure Cloud Native
Deployment ModelSoftware as a Service (SaaS)
Ingestion ModelPer-GB consumption-based
Built-on TechnologyAzure Log Analytics
Data RetentionConfigurable 30 days to 2+ years
Built-in Connectors300+
API SupportREST API, Azure SDK
Machine LearningAI-driven anomaly detection, behavioral analytics
Incident ManagementUnified incident dashboard, automated triage, investigation notebooks
AutomationLogic Apps, playbook orchestration, custom API integration
IntegrationMicrosoft Defender suite, third-party SIEM/SOAR, Azure services
AuthenticationAzure AD / Microsoft Entra ID
Compliance FrameworksPCI DSS, HIPAA, SOC 2, GDPR, NIST, ISO 27001
Availability99.99% SLA
Regional DeploymentMultiple Azure regions globally
Multi-tenancySingle workspace or multi-workspace federation