Skip to content
Blog by Morten Knudsen about Microsoft Security, Azure, M365 & Automation
  • Blog Posts
  • Blog Posts by Category
  • Github Repo
  • Speaks & Events
  • Experts Live Denmark
  • Pictures
    • Pictures Microsoft
    • Pictures Tech Peers
  • About | Morten
    • Contact
    • Disclaimer

Blog by Morten Knudsen about Microsoft Security, Azure, M365 & Automation

  • Blog Posts
  • Blog Posts by Category
  • Github Repo
  • Speaks & Events
  • Experts Live Denmark
  • Pictures
    • Pictures Microsoft
    • Pictures Tech Peers
  • About | Morten
    • Contact
    • Disclaimer

cost

Script: Sentinel Data Lake Table Management

20/08/202513/08/2025 by Morten Knudsen

Microsoft Sentinel’s data lake story is quietly powerful: you get fast, 90-day Analytics (Shortterm) for hunting and detections, plus scalable, …

Read more

Tags Compliance, cost, Data Lake, retention, security, Sentinel

Tutorial: Integrate AI into your Powershell scripts

25/05/202525/05/2025 by Morten Knudsen

I have been playing around with integrating AI into my favorite scripting tool: Powershell. This blog serves as a quick-guide …

Read more

Tags ai, azure, cost, identity, security, Sentinel, tutorial

Optimize Costs using Auxiliary Logs for Verbose Logging

18/09/202414/09/2024 by Morten Knudsen

Today, we use logging for many purposes including security hunting with SIEM (Sentinel), troubleshooting, performance telemetry, compliance reporting – but …

Read more

Tags Auxiliary, azure, cost, Kusto, Loganalytics, Logging, Optimize, Sentinel

How to save $$$ by storing your Syslog and Defender for Endpoint long-term logs in Azure Data Explorer cluster using Azure Data Factory and Azure Storage Account export – while keeping Kusto query functionalities ?

15/01/202312/01/2023 by Morten Knudsen

This blog is about keeping long-term Sentinel logs, giving you insight to the options today – with great opportunities to …

Read more

Tags adf, adx, azure, cost, log, Loganalytics, Logging, long-term, longterm, retention, Sentinel

Real example with 43% cost savings on Sentinel log-costs: How to exclude Syslog log-events from banned IPs using AbuseIPDB-service with integration to firewalls

02/01/202329/12/2022 by Morten Knudsen

This is a real-life example of how I helped reduce the log-cost by 43% for LogAnalytics & Sentinel combined for …

Read more

Tags azure, cost, Loganalytics, optimization, Sentinel, Syslog

About | Morten Knudsen

Triple Microsoft MVP (Security, Azure & Security Copilot)

Microsoft Certified Trainer (1999-2025)

Cloud & Security Architect

Blogger aka.ms/morten

Public speaker

Mentor

Co-founder Experts Live Denmark

Board Member Experts Live Global

  • LinkedIn
  • Bluesky
  • Twitter
  • Mail

Recent Posts

  • Modern Outlook/Teams fails with WebView2 error – seen on Win11 ARM
  • Script: Sentinel Data Lake Table Management
  • How to Enforce Macro Security by running only Excel macros signed with your own public-CA–issued code-signing certificate – stored in Azure Keyvault (HSM)
  • How to Block Upload to WeTransfer, DropBox & Google Drive (but Allowing Download) – using Microsoft Purview Data Loss Prevention (DLP)
  • Tutorial: Integrate AI into your Powershell scripts
Tweets by knudsenmortendk
  • Privacy Policy
  • Terms
  • Contact
© 2025 Blog by Morten Knudsen about Microsoft Security, Azure, M365 & Automation • Built with GeneratePress