Create & Manage Azure Sentinel Workspaces
Plan for the Azure Sentinel Workspace You can install the Azure Sentinel solution in Log Analytics Workspace, whose implementation is mostly focused on the Log Analytics Workspace creation. The only important option when creating a new log on the Log Analytics Workspace is the region which specifies the location where the log data will reside. The three implementation options are: Single-Tenant with a single Azure Sentinel Workspace Single-Tenant with regional Azure Sentinel Workspace Multi-Tenant Single-tenant single workspace This workspace can receive logs from resources in other regions within the same tenant. Generally the log data (when collected) always travel across different regions and stored in another region, which creates two possible concerns- first, it can incur a bandwidth cost. Second, if there is a data governance requirement to keep data in a specific region, then the single workspace option would not be an implementation option. Its pros and...