Cloud Security Stack
Tools and buyer guides

Tools

Microsoft Sentinel gets expensive fast. Here is where the money goes

Ingestion pricing punishes exactly the logs people connect first. What to keep hot, what to send cheap, and the settings that cut a bill without cutting detection.

13 min read · Reviewed 22 August 2026 · Written against Microsoft's published Sentinel and Log Analytics pricing model.

The pricing model in one paragraph

Sentinel bills primarily on the volume of data ingested and retained, measured in gigabytes. That means cost is driven by what you connect and how chatty it is, not by how many detections you run or how many analysts use it. The consequence is unintuitive: a well-tuned deployment can cost a fraction of a badly scoped one with identical detection coverage.

The four decisions that set your bill

01

Which connectors you enable

Some sources are enormous and low value by default. Verbose firewall and proxy logs will dominate a bill while contributing to very few detections. Connect them deliberately, not because the connector exists.

02

Commitment tier versus pay as you go

Above a predictable daily volume, a commitment tier is materially cheaper per gigabyte. Most organisations stay on pay as you go for far longer than the maths justifies.

03

Which tables need to be searchable in real time

Not everything needs analytics-tier retention. Data you keep for investigation rather than live detection can sit in a cheaper tier and still be queryable.

04

Transformation at ingest

Dropping fields or filtering noisy rows before they land is the single most effective lever, and the least used. Filter at ingest, not in the query.

Where the spend usually sits

Relative, and drawn from the shape of typical deployments rather than from a survey.

  • Network and proxy logs45
  • Endpoint and Defender data25
  • Identity and sign-in logs20
  • Everything else10

An argument about proportions, not measured data. Check your own workspace usage before acting.

Check the free grants before you optimise anything

Some Microsoft first-party security data carries an ingestion allowance for eligible Microsoft 365 licences. Organisations regularly discover they have been paying to ingest data they were entitled to ingest free. Verify this against your own licensing before restructuring anything else.

The verdict

Our pick

Filter at ingest, then commit to a tier

Transformation rules cut volume without cutting detections, and a commitment tier then applies a lower rate to what remains. In that order, because committing to an unfiltered volume locks in the waste.

Who should skip

Do not cut identity and sign-in logs to save money. They are among the cheapest sources and they carry the highest detection value in a Microsoft estate.

Disclosure. Some links on this site are affiliate links. Scoring weights are published before any programme is joined, and commission is never a ranking input. Full policy, and the method behind this guide.