Understanding Data Ingestion for Log Analytics and Sentinel Workspace
I’m trying to understand how data ingestion works for both Log Analytics and Microsoft Sentinel. Every time we notice a spike in data ingestion costs for Log Analytics, we see a similar increase in Sentinel costs as well. It seems like data is being ingested into both workspaces, potentially doubling the ingestion and driving up our costs.
Can someone explain if this is expected behavior, or if there’s a way to optimize and avoid duplicate data ingestion between Log Analytics and Sentinel?
I’m trying to understand how data ingestion works for both Log Analytics and Microsoft Sentinel. Every time we notice a spike in data ingestion costs for Log Analytics, we see a similar increase in Sentinel costs as well. It seems like data is being ingested into both workspaces, potentially doubling the ingestion and driving up our costs.Can someone explain if this is expected behavior, or if there’s a way to optimize and avoid duplicate data ingestion between Log Analytics and Sentinel? Read More