<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>whennotif.io</title><description>Security, Identity &amp; Cloud – Blog by Juergen Waldl</description><link>https://whennotif.io/</link><language>en</language><item><title>Release: Sentinel IngestIQ - Free Ingest Calculator for Microsoft Sentinel</title><link>https://whennotif.io/blog/sentinel-ingest-calculator-release/</link><guid isPermaLink="true">https://whennotif.io/blog/sentinel-ingest-calculator-release/</guid><description>The Sentinel IngestIQ Calculator is here. A free tool for calculating and optimizing Microsoft Sentinel ingestion costs - covering all six optimization layers.</description><pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;It&amp;#39;s here: The &lt;strong&gt;Sentinel IngestIQ Calculator&lt;/strong&gt; is now available - &lt;strong&gt;free and without registration&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;In my last article, I described &lt;a href=&quot;/blog/sentinel-ingest-calculation&quot;&gt;why cost calculation for Microsoft Sentinel has become nearly impossible&lt;/a&gt;. Six interlinked optimization layers, dozens of interdependent variables, and a pricing model that seems to change every few months. Mapping all of this in a spreadsheet is tedious at best - and usually inaccurate.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;IngestIQ solves exactly this problem.&lt;/strong&gt;&lt;/p&gt;
&lt;h2&gt;What the Tool Does&lt;/h2&gt;
&lt;p&gt;The calculator covers the &lt;strong&gt;complete Sentinel cost optimization path&lt;/strong&gt; - from gross calculation to the final monthly bill:&lt;/p&gt;
&lt;h3&gt;Step 1 - Environment Parameters&lt;/h3&gt;
&lt;p&gt;Enter your infrastructure: users, servers (Windows, Linux, DCs), firewalls, DNS servers, proxies, network devices. The tool calculates the expected daily ingestion volume per category - drawing on a mix of experience from various Sentinel implementation and migration projects I personally worked on, as well as estimates from reputable sources (e.g. CIS, Microsoft, etc.).&lt;/p&gt;
&lt;h3&gt;Step 2 - Free Data Sources&lt;/h3&gt;
&lt;p&gt;Automatic deduction of free sources: Azure Activity Logs, Office 365 Audit Logs, and Security Alerts. Depending on the environment, that&amp;#39;s 10-30% of total volume.&lt;/p&gt;
&lt;h3&gt;Step 3 - M365 E5 Security Benefit&lt;/h3&gt;
&lt;p&gt;Activatable via toggle: 5 MB/user/day data grant for Entra Sign-In Logs, Audit Logs, MDCA, and Purview. Shows the exact savings in € per day and month.&lt;/p&gt;
&lt;h3&gt;Step 4 - Defender for Servers P2&lt;/h3&gt;
&lt;p&gt;Complete ROI calculator: 500 MB/server/day benefit vs. €10/server/month upgrade cost. The tool recommends the optimal number of P2 licenses and shows whether the upgrade is economically worthwhile.&lt;/p&gt;
&lt;h3&gt;Step 5 - Auxiliary Logs / Data Lake&lt;/h3&gt;
&lt;p&gt;Per-source configuration with slider: Which log sources should go to the Data Lake (€0.40/GB) instead of the Analytics Tier (€4.80/GB)? DNS, proxy, firewall, NAC, non-interactive sign-ins - each with configurable split ratio.&lt;/p&gt;
&lt;h3&gt;Step 6 - Commitment Tiers &amp;amp; Pre-Purchase&lt;/h3&gt;
&lt;p&gt;Commitment tier selection with automatic recommendation based on actual Analytics volume. Plus pre-purchase plan calculation with 12-month projection.&lt;/p&gt;
&lt;h3&gt;Bonus: Commercial Cost Overview&lt;/h3&gt;
&lt;p&gt;Professional cost breakdown with all line items (Analytics Tier, Data Lake, MDC P2 licenses, Pre-Purchase CUs) - including a 12-month projection chart. Ideal for proposals and architecture decisions.&lt;/p&gt;
&lt;Callout type=&quot;info&quot;&gt;
  All calculation factors (GB per user, per server, per firewall, etc.) are transparently accessible and can be adjusted as needed - so you can calibrate the tool to your specific environment.
&lt;/Callout&gt;&lt;h2&gt;Why Free?&lt;/h2&gt;
&lt;p&gt;I believe good security tools should be accessible to everyone - not just organizations with large budgets. Sentinel is a powerful SIEM, but the complexity of cost calculation prevents many from leveraging available optimization options. IngestIQ aims to remove that barrier.&lt;/p&gt;
&lt;p&gt;The tool was born from practice: I originally used lists, Excel files, and a lot of tedious manual work to create sizings for my customers at &lt;a href=&quot;https://base-it.at&quot;&gt;base-IT&lt;/a&gt; - until I decided that the broader community deserved something better. This calculator is the result - and I hope it will help many people get a clearer picture of their Sentinel costs.&lt;/p&gt;
&lt;h2&gt;PDF Export&lt;/h2&gt;
&lt;p&gt;The Commercial Proposal can be exported as a &lt;strong&gt;professionally structured PDF&lt;/strong&gt; - perfect for:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Proposals and cost estimates&lt;/li&gt;
&lt;li&gt;Architecture documentation&lt;/li&gt;
&lt;li&gt;Management presentations&lt;/li&gt;
&lt;li&gt;Budget planning&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Try It Now&lt;/h2&gt;
&lt;p&gt;👉 &lt;strong&gt;&lt;a href=&quot;/tools/sentinel-calculator&quot;&gt;Open Sentinel IngestIQ →&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;em&gt;Feedback, feature requests, or bug reports? Reach out on &lt;a href=&quot;https://linkedin.com/in/j%C3%BCrgen-waldl-6592837b&quot;&gt;LinkedIn&lt;/a&gt; or via &lt;a href=&quot;mailto:info@juergenwaldl.net&quot;&gt;email&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
</content:encoded></item><item><title>Calculating Sentinel Costs? Why Sizing Has Become Rocket Science...</title><link>https://whennotif.io/blog/sentinel-ingest-calculation/</link><guid isPermaLink="true">https://whennotif.io/blog/sentinel-ingest-calculation/</guid><description>Cost calculation for Microsoft Sentinel in 2026 is more complex than ever. This article covers the levers, hidden benefits, and why a spreadsheet won&apos;t cut it anymore.</description><pubDate>Sun, 12 Apr 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;I&amp;#39;ve been working with Microsoft Sentinel for years - as Lead Architect Security at &lt;a href=&quot;https://base-it.at&quot;&gt;base-IT&lt;/a&gt;, I regularly deploy the Microsoft SIEM &amp;amp; SOAR solution for customers. And if there&amp;#39;s one thing I&amp;#39;ve learned, it&amp;#39;s this: &lt;strong&gt;Cost calculation for Sentinel has become the most complex part of the entire deployment.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Sound like an exaggeration? Unfortunately, it isn&amp;#39;t. We&amp;#39;re no longer talking about a simple GB × price model (well, yes - in principle, but...). We&amp;#39;re talking about a system with &lt;strong&gt;interlinked optimization layers&lt;/strong&gt;, where turning the wrong dial on one can invalidate another.&lt;/p&gt;
&lt;Callout type=&quot;info&quot;&gt;
  I barely know anyone who truly understands their Sentinel costs down to the detail. Most just take the Pay-As-You-Go price and hope for the best. This article aims to solve that &quot;mystery.&quot; If you still need help after reading this, don&apos;t hesitate to reach out.
&lt;/Callout&gt;&lt;h2&gt;The Core Problem: Too Many Variables&lt;/h2&gt;
&lt;p&gt;When someone asks me: &lt;em&gt;&amp;quot;What will Sentinel cost us?&amp;quot;&lt;/em&gt;, my honest answer is: &lt;strong&gt;It depends.&lt;/strong&gt; On significantly more factors than you&amp;#39;d expect...&lt;/p&gt;
&lt;h3&gt;The Obvious Variables&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Number of users&lt;/strong&gt; - drives Sign-In Logs, Entra Audit Logs, collaboration data, business applications, and much more&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Number of servers&lt;/strong&gt; - Windows Event Logs, Security Event Logs, Syslog, performance counters&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Network devices&lt;/strong&gt; - firewalls, switches, access points, NAC&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;DNS/DHCP infrastructure&lt;/strong&gt; - often the single largest log producer by volume, yet still a very interesting log source&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Proxy/SWG&lt;/strong&gt; - web traffic logs can easily generate several GB/day per 1,000 users and offer comparatively little added value&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;The Less Obvious Variables&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Licensing&lt;/strong&gt; - Does the organization have M365 E5 or E5 Defender Suite? That activates one of many Microsoft Ingest Benefits.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Microsoft Defender for Cloud&lt;/strong&gt; - Is Plan 2 for Servers active? That directly impacts ingestion costs.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Log verbosity&lt;/strong&gt; - A domain controller produces significantly more event logs than a standard server.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Non-interactive sign-ins&lt;/strong&gt; - Token refreshes and silent SSO typically generate 3-10× the volume of interactive sign-ins.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Time of day&lt;/strong&gt; - Yes, this matters too. Log distribution across 24 hours is not uniform, and weekends naturally look different again.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;The Layers of Cost Optimization&lt;/h2&gt;
&lt;p&gt;What makes this truly complex: There isn&amp;#39;t &lt;em&gt;one&lt;/em&gt; price. There are multiple benefits and optimization options that build upon each other. Each stage reduces costs - but only if you know about it and apply it correctly.&lt;/p&gt;
&lt;h3&gt;Step 1: Calculate Gross Volume&lt;/h3&gt;
&lt;p&gt;The first step is relatively straightforward: Estimate the daily gross ingestion volume per category. How many GB/day each source will produce.&lt;/p&gt;
&lt;p&gt;Sounds trivial, but it isn&amp;#39;t. Because who actually knows how much data their own infrastructure produces? And Microsoft&amp;#39;s own estimates are... to put it kindly: &lt;strong&gt;rarely accurate&lt;/strong&gt; (or non-existent).&lt;/p&gt;
&lt;p&gt;My experience from various projects:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Log Category&lt;/th&gt;
&lt;th&gt;Typical Driver&lt;/th&gt;
&lt;th&gt;Magnitude&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;&lt;tr&gt;
&lt;td&gt;Sign-In Logs&lt;/td&gt;
&lt;td&gt;per user/day&lt;/td&gt;
&lt;td&gt;15-25 MB (interactive + non-interactive)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Control Plane (Entra Audit)&lt;/td&gt;
&lt;td&gt;per user/day&lt;/td&gt;
&lt;td&gt;3-8 MB&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Windows Event Logs&lt;/td&gt;
&lt;td&gt;per server/day&lt;/td&gt;
&lt;td&gt;200-500 MB (DC: 500-2000 MB)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Firewall&lt;/td&gt;
&lt;td&gt;per FW/day&lt;/td&gt;
&lt;td&gt;highly variable, 500 MB - 50 GB&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DNS&lt;/td&gt;
&lt;td&gt;per DNS server/day&lt;/td&gt;
&lt;td&gt;1-20 GB (!)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Proxy/SWG&lt;/td&gt;
&lt;td&gt;per 1,000 users/day&lt;/td&gt;
&lt;td&gt;2-10 GB&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;Callout type=&quot;info&quot;&gt;
  DNS &amp; DHCP logs are a classic: Hardly anyone expects a single DNS/DHCP server to produce several GB per day. These are often the most expensive &quot;surprises&quot; on the first monthly bill. The same applies to firewall logs, of course.
&lt;/Callout&gt;&lt;h3&gt;Step 2: Subtract Free Data Sources&lt;/h3&gt;
&lt;p&gt;What many don&amp;#39;t know: &lt;strong&gt;Some data sources are completely free in Sentinel.&lt;/strong&gt; This is documented in the &lt;a href=&quot;https://learn.microsoft.com/azure/sentinel/billing#free-data-sources&quot;&gt;Microsoft documentation&lt;/a&gt;, but surprisingly often overlooked in sizing exercises.&lt;/p&gt;
&lt;p&gt;The following sources cost &lt;strong&gt;nothing&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Azure Activity Logs&lt;/strong&gt; (&lt;code&gt;AzureActivity&lt;/code&gt; table) - all control plane activities of Azure subscriptions&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Office 365 Audit Logs&lt;/strong&gt; (&lt;code&gt;OfficeActivity&lt;/code&gt; table) - SharePoint, Exchange, Teams activities&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Security Alerts&lt;/strong&gt; (&lt;code&gt;SecurityAlert&lt;/code&gt; table) - alerts from Defender XDR, Defender for Cloud, Defender for Identity, MDE, MDCA, MDO&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Depending on the environment, that&amp;#39;s easily &lt;strong&gt;15-30% of total volume&lt;/strong&gt; that simply drops off. For customers with primarily cloud workloads and M365, it can be even more.&lt;/p&gt;
&lt;h3&gt;Step 3: The M365 E5 Security Benefit&lt;/h3&gt;
&lt;p&gt;This is where it gets really interesting. Customers with &lt;strong&gt;Microsoft 365 E5&lt;/strong&gt; or &lt;strong&gt;E5 Defender Suite Add-on&lt;/strong&gt; receive a &lt;a href=&quot;https://azure.microsoft.com/en-us/pricing/offers/sentinel-microsoft-365-offer&quot;&gt;Data Grant&lt;/a&gt; of &lt;strong&gt;5 MB per user per day&lt;/strong&gt; for specific Sentinel data sources.&lt;/p&gt;
&lt;p&gt;That sounds small - but it isn&amp;#39;t. For 1,000 users, that&amp;#39;s 5 GB/day deducted from:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Entra ID Sign-In and Audit Logs&lt;/li&gt;
&lt;li&gt;Microsoft Defender for Cloud Apps (MDCA)&lt;/li&gt;
&lt;li&gt;Microsoft Purview Information Protection&lt;/li&gt;
&lt;li&gt;M365 Advanced Hunting data (Defender XDR)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;At a Pay-As-You-Go price of &lt;strong&gt;€4.80/GB&lt;/strong&gt; (EU West region), that&amp;#39;s &lt;strong&gt;€24/day or €720/month&lt;/strong&gt; in savings - just from the E5 benefit. For 5,000 users, we&amp;#39;re talking &lt;strong&gt;€3,600/month&lt;/strong&gt;.&lt;/p&gt;
&lt;h3&gt;Step 4: Defender for Servers P2 Benefit&lt;/h3&gt;
&lt;p&gt;Those with &lt;strong&gt;Microsoft Defender for Cloud Plan 2&lt;/strong&gt; active get an additional &lt;a href=&quot;https://learn.microsoft.com/azure/defender-for-cloud/data-ingestion-benefit&quot;&gt;ingestion benefit of 500 MB per server per day&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This benefit applies to specific security tables:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;SecurityEvent&lt;/code&gt; / &lt;code&gt;WindowsEvent&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;SecurityAlert&lt;/code&gt; / &lt;code&gt;SecurityBaseline&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;WindowsFirewall&lt;/code&gt; / &lt;code&gt;ProtectionStatus&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;Update&lt;/code&gt; / &lt;code&gt;UpdateSummary&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Important:&lt;/strong&gt; The upgrade from Defender for Cloud P1 to P2 costs approximately &lt;strong&gt;€10/server/month&lt;/strong&gt;. Whether that pays off depends directly on how much eligible data the servers actually produce.&lt;/p&gt;
&lt;p&gt;The math simplified:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;A Windows server typically produces 200-500 MB/day of eligible events (DCs naturally more)&lt;/li&gt;
&lt;li&gt;The benefit covers 500 MB/day → most of it is covered&lt;/li&gt;
&lt;li&gt;Savings at €4.80/GB: approximately &lt;strong&gt;€1-2.40/server/day = €30-72/server/month&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Minus the €10/month upgrade cost: &lt;strong&gt;Net €20-62/server/month savings&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;With 50 Windows servers, that can mean savings of &lt;strong&gt;€1,000-3,000/month&lt;/strong&gt;. That&amp;#39;s significant.&lt;/p&gt;
&lt;h3&gt;Step 5: Auxiliary Logs / Data Lake Tier&lt;/h3&gt;
&lt;p&gt;This is - in my opinion - one of the best features Microsoft introduced in 2026, making the pricing model considerably more complex yet again.&lt;/p&gt;
&lt;p&gt;The idea: Not all logs need real-time detection in the Analytics Tier. Some log sources have extremely high volume but are primarily relevant for threat hunting and forensics - not real-time alerting.&lt;/p&gt;
&lt;p&gt;For exactly these data, there&amp;#39;s the &lt;strong&gt;Data Lake Tier&lt;/strong&gt; (formerly &amp;quot;Auxiliary Logs&amp;quot;) with a drastically reduced price of approximately &lt;strong&gt;€0.40/GB&lt;/strong&gt; (the calculation behind that would warrant its own blog article...) instead of €4.80/GB in the Analytics Tier.&lt;/p&gt;
&lt;p&gt;Typical candidates for the Data Lake Tier:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Log Source&lt;/th&gt;
&lt;th&gt;Why Data Lake?&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;DNS/DHCP Logs&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Extremely high volume, rarely needed for real-time detection&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Proxy/SWG Logs&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Summary/block events in Analytics, the rest in the Data Lake&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Firewall allow traffic&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Deny/threat logs in Analytics, allow traffic in the Data Lake&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;NAC/Switch Logs&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Auth failures in Analytics, port events in the Data Lake&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Non-interactive sign-ins&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Token refreshes rarely need real-time detection&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;p&gt;The trick: You split a source&amp;#39;s traffic - e.g., at a &lt;strong&gt;1:6 ratio for DNS&lt;/strong&gt; (1 part Analytics, 6 parts Data Lake). This preserves detection capability for critical events while massively saving on high-volume data.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Example calculation:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;A DNS server produces 3 GB/day&lt;/li&gt;
&lt;li&gt;All in Analytics Tier: 3 × €4.80 = &lt;strong&gt;€14.40/day&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Split 1:6 → 0.5 GB Analytics + 3 GB Data Lake: (0.5 × €4.80) + (3 × €0.40) = &lt;strong&gt;€3.60/day&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Savings: 75%&lt;/strong&gt; for this one source&lt;/li&gt;
&lt;/ul&gt;
&lt;Callout type=&quot;info&quot;&gt;
  Microsoft themselves explicitly recommend the Data Lake Tier for &quot;lower fidelity or secondary security data&quot; - see the &lt;a href=&quot;https://learn.microsoft.com/azure/sentinel/billing-reduce-costs#use-the-microsoft-sentinel-data-lake-for-lower-fidelity-or-secondary-security-data&quot; target=&quot;_blank&quot;&gt;official documentation&lt;/a&gt;.
&lt;/Callout&gt;&lt;h3&gt;Step 6: Commitment Tiers &amp;amp; Pre-Purchase Plans&lt;/h3&gt;
&lt;p&gt;Once you know your actual Analytics Tier volume after steps 1-5, you can save even more with &lt;strong&gt;Commitment Tiers&lt;/strong&gt;. Instead of Pay-As-You-Go, you book a fixed daily volume and receive a volume discount.&lt;/p&gt;
&lt;p&gt;Tiers start at &lt;strong&gt;50 GB/day&lt;/strong&gt; (note - likely only temporarily available) and offer &lt;strong&gt;discounts of up to 50%+&lt;/strong&gt; compared to PAYG depending on volume. The catch: You pay the commitment even if you consume less. That&amp;#39;s why it&amp;#39;s critical to know the volume &lt;strong&gt;after&lt;/strong&gt; optimization steps 2-5 before committing.&lt;/p&gt;
&lt;p&gt;Additionally, since 2024 there are &lt;strong&gt;Pre-Purchase Plans&lt;/strong&gt;: You buy Sentinel Commit Units (CUs) upfront with a very attractive discount (depending on Azure region - but potentially up to 20-30%) and apply them over 12 months. These CUs only apply to the Analytics Tier - the Data Lake Tier is not covered.&lt;/p&gt;
&lt;h2&gt;Why a Spreadsheet Won&amp;#39;t Cut It Anymore&lt;/h2&gt;
&lt;p&gt;Looking at these options, it becomes clear: &lt;strong&gt;The calculation is a multi-dimensional optimization problem.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The steps aren&amp;#39;t independent. Both the E5 benefit and the MDC P2 benefit reduce the volume that can be shifted to the Data Lake. Identifying which log sources make sense for Data Lake Tier ingestion and how much that would cost is difficult. And the final Analytics volume determines which Commitment Tier and Pre-Purchase Plan makes sense.&lt;/p&gt;
&lt;p&gt;When you additionally consider that:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Each log category has its own volume factor&lt;/li&gt;
&lt;li&gt;Free sources and the E5 benefit only affect specific tables&lt;/li&gt;
&lt;li&gt;MDC P2 only covers Windows-based (no Syslog) events&lt;/li&gt;
&lt;li&gt;The Data Lake split is configurable per source (and even more granularly)&lt;/li&gt;
&lt;li&gt;Commitment Tiers have a minimum you pay even if you&amp;#39;re under&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;...you have a system with &lt;strong&gt;dozens of interdependent variables&lt;/strong&gt;. That&amp;#39;s nearly impossible to model cleanly in a simple spreadsheet - and certainly not intuitive for someone doing it for the first time.&lt;/p&gt;
&lt;h2&gt;Conclusion: We Need a Better Tool&lt;/h2&gt;
&lt;p&gt;The reality is: Most sizing conversations I have follow the same pattern. You estimate roughly, take the PAYG price, and then wonder about the first bill. Or you optimize in one area, miss another - and end up paying more than necessary.&lt;/p&gt;
&lt;p&gt;What&amp;#39;s missing is a tool that brings all these variables together. That understands the dependencies. That shows which optimization pays off for &lt;em&gt;this specific&lt;/em&gt; environment and which doesn&amp;#39;t. And that presents the results in a way you can directly use in a proposal or architecture decision.&lt;/p&gt;
&lt;Callout type=&quot;info&quot;&gt;
  &lt;strong&gt;Sneak Peek:&lt;/strong&gt; I&apos;m currently working on exactly such a tool. A Sentinel Ingest Calculator that covers all benefits &amp; optimization options - from gross calculation through free sources, E5, MDC P2, and Data Lake all the way to Commitment Tiers and Pre-Purchase Plans. Including ROI calculation for MDC P2, waterfall visualization, and PDF export of a &quot;Commercial Proposal.&quot;&lt;br /&gt;&lt;br /&gt;
  The tool will be &lt;strong&gt;released for free&lt;/strong&gt; soon - stay tuned. 🚀
&lt;/Callout&gt;&lt;div class=&quot;sneak-peek-gallery&quot;&gt;
  &lt;figure&gt;
    &lt;img src=&quot;/images/blog/sentinel-calculator-input-sources.png&quot; alt=&quot;Sentinel IngestIQ Calculator - Log source input with categories, multipliers, and daily volume&quot; /&gt;
    &lt;figcaption&gt;Configure log sources: categories, multipliers, and daily volume at a glance&lt;/figcaption&gt;
  &lt;/figure&gt;
  &lt;figure&gt;
    &lt;img src=&quot;/images/blog/sentinel-calculator-waterfall-benefits.png&quot; alt=&quot;Sentinel IngestIQ Calculator - Waterfall visualization of cost optimization across all benefit stages&quot; /&gt;
    &lt;figcaption&gt;Waterfall visualization: cost reduction step by step across all benefit stages&lt;/figcaption&gt;
  &lt;/figure&gt;
  &lt;figure&gt;
    &lt;img src=&quot;/images/blog/sentinel-calculator-cost-summary.png&quot; alt=&quot;Sentinel IngestIQ Calculator - Final cost overview with commitment tiers and total savings&quot; /&gt;
    &lt;figcaption&gt;Result: final cost overview with commitment tiers and total savings&lt;/figcaption&gt;
  &lt;/figure&gt;
&lt;/div&gt;&lt;h2&gt;Essential Documentation&lt;/h2&gt;
&lt;p&gt;For those wanting to dive deeper, here&amp;#39;s the Microsoft documentation I consider essential:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://learn.microsoft.com/azure/sentinel/billing&quot;&gt;Plan costs and understand Microsoft Sentinel pricing and billing&lt;/a&gt;&lt;/strong&gt; - the starting point for everything&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://learn.microsoft.com/azure/sentinel/billing-reduce-costs&quot;&gt;Reduce costs for Microsoft Sentinel&lt;/a&gt;&lt;/strong&gt; - Commitment Tiers, Data Lake, Pre-Purchase&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://learn.microsoft.com/azure/sentinel/billing#free-data-sources&quot;&gt;Free data sources&lt;/a&gt;&lt;/strong&gt; - which tables are free&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://learn.microsoft.com/azure/defender-for-cloud/data-ingestion-benefit&quot;&gt;Defender for Servers P2 Ingestion Benefit&lt;/a&gt;&lt;/strong&gt; - the 500 MB/server/day benefit&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://learn.microsoft.com/azure/sentinel/enroll-simplified-pricing-tier&quot;&gt;Switch to simplified pricing tiers&lt;/a&gt;&lt;/strong&gt; - the unified pricing since July 2023&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://learn.microsoft.com/azure/sentinel/billing-pre-purchase-plan&quot;&gt;Pre-Purchase Plans&lt;/a&gt;&lt;/strong&gt; - CU-based upfront discounts&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://learn.microsoft.com/azure/sentinel/manage-data-overview&quot;&gt;Data tiers and retention&lt;/a&gt;&lt;/strong&gt; - Analytics vs. Data Lake vs. Archive&lt;/li&gt;
&lt;/ol&gt;
&lt;hr&gt;
&lt;p&gt;&lt;em&gt;Have questions about Sentinel cost calculation or optimization options? Reach out on &lt;a href=&quot;https://linkedin.com/in/j%C3%BCrgen-waldl-6592837b&quot;&gt;LinkedIn&lt;/a&gt; or via &lt;a href=&quot;mailto:info@juergenwaldl.net&quot;&gt;email&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
</content:encoded></item></channel></rss>