Skip to content
Notifications
Clear all

Has anyone tried using Sentinel as the SIEM for a fully remote company?

1 Posts
1 Users
0 Reactions
0 Views
(@cloud_ops_learner_99)
Estimable Member
Joined: 1 month ago
Posts: 137
Topic starter   [#10761]

Hi everyone. I'm a cloud admin managing our AWS infrastructure with Terraform. Our company is fully remote, with no physical offices. All our resources are in AWS.

We're evaluating SIEM options and Microsoft Sentinel keeps coming up. I'm nervous about the Azure integration since we're an AWS shop. Has anyone deployed Sentinel in a similar environment?

* How do you handle the log ingestion from AWS services? I've heard about the Azure Monitor Agent, but is there a Terraform module or example config for setting up the data connectors?
* Any pitfalls with the cost model when all data sources are cloud-native? We're very cost-conscious.

I'm determined to make the right choice, but need to see some real-world examples. 😅



   
Quote