Skip to content
Blog by Morten Knudsen about Microsoft Security, Azure, M365 & Automation
  • Blog Posts
  • Blog Posts by Category
  • Github Repo
  • Speaks & Events
  • Experts Live Denmark
  • Pictures
    • Pictures Microsoft
    • Pictures Tech Peers
  • About | Morten
    • Contact
    • Disclaimer

Blog by Morten Knudsen about Microsoft Security, Azure, M365 & Automation

  • Blog Posts
  • Blog Posts by Category
  • Github Repo
  • Speaks & Events
  • Experts Live Denmark
  • Pictures
    • Pictures Microsoft
    • Pictures Tech Peers
  • About | Morten
    • Contact
    • Disclaimer

cost

Optimize Costs using Auxiliary Logs for Verbose Logging

18/09/202414/09/2024 by Morten Knudsen

Today, we use logging for many purposes including security hunting with SIEM (Sentinel), troubleshooting, performance telemetry, compliance reporting – but …

Read more

Tags Auxiliary, azure, cost, Kusto, Loganalytics, Logging, Optimize, Sentinel

How to save $$$ by storing your Syslog and Defender for Endpoint long-term logs in Azure Data Explorer cluster using Azure Data Factory and Azure Storage Account export – while keeping Kusto query functionalities ?

15/01/202312/01/2023 by Morten Knudsen

This blog is about keeping long-term Sentinel logs, giving you insight to the options today – with great opportunities to …

Read more

Tags adf, adx, azure, cost, log, Loganalytics, Logging, long-term, longterm, retention, Sentinel

Real example with 43% cost savings on Sentinel log-costs: How to exclude Syslog log-events from banned IPs using AbuseIPDB-service with integration to firewalls

02/01/202329/12/2022 by Morten Knudsen

This is a real-life example of how I helped reduce the log-cost by 43% for LogAnalytics & Sentinel combined for …

Read more

Tags azure, cost, Loganalytics, optimization, Sentinel, Syslog

About | Morten Knudsen

Dual Microsoft MVP (Security & Azure)

Microsoft Certified Trainer

Cloud & Security Architect

Microsoft Sentinel Black Belt

Microsoft Defender Black Belt

Microsoft Cloud Security Influencer

Microsoft Sentinel Influencer

Microsoft Defender for Cloud Influencer

Recent Posts

  • How to authenticate with Windows Hello for Business or FIDO security key in RDP session ?
  • Windows Service Monitoring at Scale using Cloud Native Azure Components
  • Troubleshooting & Monitoring of Log Ingestion with Data Collection Rules
  • Optimize Costs using Auxiliary Logs for Verbose Logging
  • “No Internet access” on Azure VM in new VNET Subnet
Tweets by knudsenmortendk
  • Privacy Policy
  • Terms
  • Contact
© 2025 Blog by Morten Knudsen about Microsoft Security, Azure, M365 & Automation • Built with GeneratePress