Sentinel POC- Architecture and Recommendations For MSSPs (Part 5)
Storage Options
A total retention can be set for both Analytic and Basic tables by configuring a total retention period, after which the data will be moved to Archive completing the retention period. The total retention is maximum 7 years. Search feature can be useful to query and rehydrate data from Archive as and when needed.
All these options above are readily available in Log Analytics Workspace, but some of the external storage options are- Blob Storage and Azure Data Explorer (ADX). Blob storage can be queried via externaldata operator in KQL, which can also be used within an analytic rule. Besides, ADX and Blob Storage can be combined and an external table can be created in ADX pointing the whole container.
Following is the summary of various storage options available currently:
Update: Workspace Manager
This feature allows MSSPs to group customer workspaces depending on their requirements. For example, healthcare customers may have different analytic rule and workbook requirements than education customers; hence, MSSPs can group them and publish different content to each of those workspaces. Since workspaces can be a [art of different groups, contents from different groups to the same workspace can be published. An ideal MSSP solution should include a combination of both Repositories and Workspace Manager.
Comments
Post a Comment