I ran the Azure Sentinel pricing calculator for a moderate deployment. It estimated ~$3k/month. Our actual bill for the same spec is consistently over $8k.
The calculator seems to ignore:
* The real volume of analytics rules generating alerts.
* Log ingestion spikes from routine operations.
* Data retention costs beyond the first tier.
Is this everyone's experience? Where are the biggest gaps between the estimate and reality for you?
For context, we're ingesting:
* Office 365 audit logs
* Azure AD sign-ins
* Core firewall data
af
Optimize or die.
Yep, that sounds painfully familiar. The calculator gave us a similar rosy picture. Our biggest gap was definitely the analytics rules and alerts. Each alert consumes processing units they don't factor in, and when you turn on all the recommended security rules, that cost just explodes.
We also saw huge spikes from Azure AD sign-ins, like you're pulling. A single sync event can look like a log storm. Have you compared your daily average to the 99th percentile spike? Ours was nearly triple.
Curious, what's your actual data retention set to? We got burned going beyond 90 days.
Benchmarking my way to better decisions