{"id":450,"date":"2022-12-29T23:47:36","date_gmt":"2022-12-29T22:47:36","guid":{"rendered":"https:\/\/mortenknudsen.net\/?p=450"},"modified":"2023-01-02T09:51:30","modified_gmt":"2023-01-02T08:51:30","slug":"example-of-sentinel-cost-optimization-with-43-savings-how-to-exclude-syslog-log-events-from-banned-ips-using-abuseipdb-service-with-integration-to-firewalls","status":"publish","type":"post","link":"https:\/\/mortenknudsen.net\/?p=450","title":{"rendered":"Real example with 43% cost savings on Sentinel log-costs: How to exclude Syslog log-events from banned IPs using AbuseIPDB-service with integration to firewalls"},"content":{"rendered":"\n<p class=\"has-base-color has-accent-2-background-color has-text-color has-background wp-block-paragraph\">This is a real-life example of how <strong>I helped reduce the log-cost by 43%<\/strong> for <strong>LogAnalytics &amp; Sentinel<\/strong> combined for a customer &#8211; by <strong>filtering banned IPs out of Syslog-data using API from AbuseIPDB<\/strong>. Banned IPs are for example port-scanners on the internet.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Some time ago, I analyzed the <strong>Syslog Traffic events<\/strong> going into a customers <strong>CommonSecurityLog<\/strong> <strong>table<\/strong> in Azure LogAnalytics.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I discovered that <strong>~ 50% of the traffic<\/strong> was coming from <strong>port-scanners on the internet <\/strong>scanning the <strong>public IPs<\/strong> of the main <strong>firewall<\/strong> and branch office firewalls. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"425\" src=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/laws-1024x425.jpg\" alt=\"\" class=\"wp-image-467\" srcset=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/laws-1024x425.jpg 1024w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/laws-300x125.jpg 300w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/laws-768x319.jpg 768w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/laws-1536x638.jpg 1536w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/laws-2048x850.jpg 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Sample of data after enabling the exemptions, you can read about in this blog<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Of course <strong>my customer drops this traffic<\/strong>, but my customer <strong>also wanted to drop the syslog entry of the events caused by these banned IP addresses to save money<\/strong> (removing the mentioned 50%). They use Azure LogAnalytics for logging and Microsoft Sentinel as SIEM.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">From a security hunting perspective, some of you would say, that you want this information kept in your logs, both for detections &amp; investigations and compliance reason &#8211; whereas others would argue that this is an <strong>accepted risk exemption<\/strong>. Choose your security-level yourself \ud83d\ude42<\/p>\n\n\n\n<h5 class=\"wp-block-heading\">Design Considerations<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">When designing your Azure LogAnalytics environment, consider to use commitment tier or dedicated cluster; Basic logs and Archive logs. I have also covered the <a href=\"https:\/\/mortenknudsen.net\/?p=73\" target=\"_blank\" rel=\"noreferrer noopener\">new data transformation in another blog-post<\/a>. More cost optimization tips are covered <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/azure-monitor\/best-practices-cost\" target=\"_blank\" rel=\"noreferrer noopener\">here<\/a><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>Configure pricing tier or dedicated cluster for your Log Analytics workspaces<\/td><td>By default, Log Analytics workspaces will use pay-as-you-go pricing with no minimum data volume. If you collect enough amount of data, you can significantly decrease your cost by using a&nbsp;<a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/azure-monitor\/logs\/cost-logs#commitment-tiers\">commitment tier<\/a>&nbsp;or&nbsp;<a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/azure-monitor\/logs\/logs-dedicated-clusters\">dedicated cluster<\/a>, which allows you to commit to a daily minimum of data collected in exchange for a lower rate.<br><br>See&nbsp;<a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/azure-monitor\/logs\/cost-logs\">Azure Monitor Logs cost calculations and options<\/a>&nbsp;for details on commitment tiers and guidance on determining which is most appropriate for your level of usage. See&nbsp;<a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/azure-monitor\/usage-estimated-costs#usage-and-estimated-costs\">Usage and estimated costs<\/a>&nbsp;to view estimated costs for your usage at different pricing tiers.<\/td><\/tr><tr><td>Configure tables used for debugging, troubleshooting, and auditing as Basic Logs<\/td><td>Tables in a Log Analytics workspace configured for&nbsp;<a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/azure-monitor\/logs\/basic-logs-configure\">Basic Logs<\/a>&nbsp;have a lower ingestion cost in exchange for limited features and a charge for log queries. If you query these tables infrequently, this query cost can be more than offset by the reduced ingestion cost.<\/td><\/tr><tr><td>Configure data retention and archiving<\/td><td>There is a charge for retaining data in a Log Analytics workspace beyond the default of 30 days (90 days in Sentinel if enabled on the workspace). If you need to retain data for compliance reasons or for occasional investigation or analysis of historical data, configure&nbsp;<a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/azure-monitor\/logs\/data-retention-archive\">Archived Logs<\/a>, which allows you to retain data for up to seven years at a reduced cost.<br><br>See&nbsp;<a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/azure-monitor\/logs\/data-retention-archive\">Configure data retention and archive policies in Azure Monitor Logs<\/a>&nbsp;for details on how to configure your workspace and how to work with archived data.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Is there another design option?  <strong>YES<\/strong> with <strong><a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/azure-monitor\/best-practices-cost\" target=\"_blank\" rel=\"noreferrer noopener\">ADX &#8211; <\/a>Azure Data Explorer<\/strong>. See teaser at the very end of this blog-post. I will cover this in a later blog-post.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Implementation strategy we chose to skip Syslog events from Banned IPs<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Going back to my customer-case, when we were looking into our options, we found, that some of the firewall vendors provided malicious IP-list capabilities, but our investigations concluded that they were not updated as frequent as we wanted (at least at the time of implementation), so we decided to come up with the solution outlined below:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>We wanted to subscribe to an <strong>external well-known web-service<\/strong>, that could deliver <strong>updated insight (real-time)<\/strong> if an IP address was considered as <strong>malicious \/ abuse<\/strong>. It should support <strong>ConfidenceScore<\/strong>\n<ul class=\"wp-block-list\">\n<li>We decided to go with <strong>AbuseIPDB<\/strong>, where we could buy an API-access and there is a fantastic community of companies sending abuse-data into their backend.<\/li>\n\n\n\n<li>NOTE: AbuseIPDB are not paying me anything to write this blog. Maybe there are similar services &#8220;out-there&#8221;, but that was the service we chose. And I have found it to be very stable and useful.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>We wanted the <strong>logic for &#8216;drop-traffic&#8217; &amp; &#8216;drop-syslog-event&#8217;<\/strong> <strong>to be done on the firewall<\/strong> close to the entry-point, so we didn&#8217;t have to transform data in the LogAnalytics backend in a pipeline. <\/li>\n\n\n\n<li>We wanted to build a script (script #1 &#8211; provided below), that could <strong>extract the list of IP addresses<\/strong> from <strong>CommonSecurityLog<\/strong> and <strong>run a API-call against AbuseIPDB<\/strong> to check if an ip address was reported <strong>banned<\/strong> &#8211; or it was <strong>clean<\/strong>\n<ul class=\"wp-block-list\">\n<li>The logic should build a <strong>single TXT-file with a list of banned ip-addresses<\/strong><\/li>\n\n\n\n<li>Lastly the script should <strong>upload the file<\/strong> to an <strong>Azure App Service<\/strong>, which was only accessible from the firewalls.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Every 5 min<\/strong> (or other frequency), <strong>the firewall should import the file<\/strong> and update its cache of banned IPs\n<ul class=\"wp-block-list\">\n<li>When traffic was seen from any of these ip addresses, a rule would drop the traffic and drop the syslog event entry, so no syslog was sent to LogAnalytics<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Every 24 hours<\/strong>, another script (script #2 &#8211; provided below) should <strong>re-analyze the banned list of IPs<\/strong> to <strong>remove any IPs<\/strong>, which had been <strong>whitelisted<\/strong> again during the last 24 hours on AbuseIPDB.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"has-accent-2-color has-text-color wp-block-heading\">Results &#8211; Customer gained a 43% drop of their log &amp; Sentinel-costs !!<\/h2>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"has-accent-2-color has-text-color wp-block-paragraph\"><strong>After 48 hours, the log-cost for this customer dropped with 43% for Azure LogAnalytics and Sentinel combined, due to this optimization of Syslog-data<\/strong>.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">Scripts<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">You can find the 2 scripts <a href=\"https:\/\/github.com\/KnudsenMorten\/BlockBannedIPsWithAbuseIPDBIntegrationPaloAlto\" target=\"_blank\" rel=\"noreferrer noopener\">using the github link<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Each of the scripts are being detailed later in this blog.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">Maybe there are more built-in ways to handle this today, compared to our choices approx 24 months ago. But the solution is running perfectly today &#8211; and it is a great example of how you can optimize your log-costs by thinking out of the box \ud83d\ude42<\/p>\n<\/blockquote>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"939\" height=\"1024\" src=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Abuse-1-1-939x1024.jpg\" alt=\"\" class=\"wp-image-461\" srcset=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Abuse-1-1-939x1024.jpg 939w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Abuse-1-1-275x300.jpg 275w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Abuse-1-1-768x838.jpg 768w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Abuse-1-1.jpg 1138w\" sizes=\"auto, (max-width: 939px) 100vw, 939px\" \/><figcaption class=\"wp-element-caption\">Example from AbuseIPDB (AbuseIPDB.com)<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Script #1 | AbuseIPDB-Check.ps1 |Runs every 1 hour<\/h2>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"48\" src=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step4-1024x48.jpg\" alt=\"\" class=\"wp-image-456\" srcset=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step4-1024x48.jpg 1024w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step4-300x14.jpg 300w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step4-768x36.jpg 768w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step4.jpg 1185w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"690\" src=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step5-1024x690.jpg\" alt=\"\" class=\"wp-image-457\" srcset=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step5-1024x690.jpg 1024w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step5-300x202.jpg 300w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step5-768x517.jpg 768w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step5.jpg 1327w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">API-check of IP-address against AbuseIPDB<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"702\" src=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/step5-2-1024x702.jpg\" alt=\"\" class=\"wp-image-463\" srcset=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/step5-2-1024x702.jpg 1024w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/step5-2-300x206.jpg 300w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/step5-2-768x526.jpg 768w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/step5-2.jpg 1319w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">When the script #1 runs again, it will skip re-checking the banned IP if it was already in the list. It will only add new IPs<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"104\" src=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step6-1024x104.jpg\" alt=\"\" class=\"wp-image-458\" srcset=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step6-1024x104.jpg 1024w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step6-300x30.jpg 300w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step6-768x78.jpg 768w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step6.jpg 1054w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">CSV-file and TXT-file are build<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"178\" src=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step7-FTP-1024x178.jpg\" alt=\"\" class=\"wp-image-459\" srcset=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step7-FTP-1024x178.jpg 1024w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step7-FTP-300x52.jpg 300w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step7-FTP-768x134.jpg 768w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step7-FTP.jpg 1475w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Files are uploaded to Azure App<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"539\" height=\"850\" src=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Output-sample.jpg\" alt=\"\" class=\"wp-image-460\" srcset=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Output-sample.jpg 539w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Output-sample-190x300.jpg 190w\" sizes=\"auto, (max-width: 539px) 100vw, 539px\" \/><figcaption class=\"wp-element-caption\">Sample output file, which is read every 5 min from the Palo Alto Firewall (or Cisco firewall or other firewall)<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Script #2 &#8211; CheckAbuseWhitelistedIPAddresses.ps1 |Runs every 24 hours<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"708\" src=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/2-step4-1024x708.jpg\" alt=\"\" class=\"wp-image-464\" srcset=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/2-step4-1024x708.jpg 1024w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/2-step4-300x207.jpg 300w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/2-step4-768x531.jpg 768w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/2-step4.jpg 1370w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">All banned IPs are re-checked against AbuseIPDB. Any whitelisted IPs will be removed from the banned list<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"104\" src=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step6-1-1024x104.jpg\" alt=\"\" class=\"wp-image-465\" srcset=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step6-1-1024x104.jpg 1024w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step6-1-300x30.jpg 300w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step6-1-768x78.jpg 768w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step6-1.jpg 1054w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">CSV-file and TXT-file are build<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"178\" src=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step7-FTP-1-1024x178.jpg\" alt=\"\" class=\"wp-image-466\" srcset=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step7-FTP-1-1024x178.jpg 1024w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step7-FTP-1-300x52.jpg 300w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step7-FTP-1-768x134.jpg 768w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/Step7-FTP-1.jpg 1475w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Files are uploaded to Azure App<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Is there an alternative option?  YES (ADX &#8211; Azure Data Explorer)<\/h2>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">An alternative option is to use a short retention of 1-3 month of the data in Sentinel\/LogAnalytics for security hunting &#8211; and then send data into a Azure Data Explorer cluster for longer retention and compliance reasons. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"548\" src=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/export-data-from-azure-monitor2-1024x548.png\" alt=\"\" class=\"wp-image-455\" srcset=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/export-data-from-azure-monitor2-1024x548.png 1024w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/export-data-from-azure-monitor2-300x161.png 300w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/export-data-from-azure-monitor2-768x411.png 768w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/export-data-from-azure-monitor2-1536x822.png 1536w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/export-data-from-azure-monitor2.png 1764w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"999\" height=\"316\" src=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/export-data-from-azure-monitor.png\" alt=\"\" class=\"wp-image-454\" srcset=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/export-data-from-azure-monitor.png 999w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/export-data-from-azure-monitor-300x95.png 300w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/export-data-from-azure-monitor-768x243.png 768w\" sizes=\"auto, (max-width: 999px) 100vw, 999px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">I will cover this in another later blog-post. <\/p>\n<\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>This is a real-life example of how I helped reduce the log-cost by 43% for LogAnalytics &amp; Sentinel combined for &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"Real example with 43% cost savings on Sentinel log-costs: How to exclude Syslog log-events from banned IPs using AbuseIPDB-service with integration to firewalls\" class=\"read-more button\" href=\"https:\/\/mortenknudsen.net\/?p=450#more-450\" aria-label=\"Read more about Real example with 43% cost savings on Sentinel log-costs: How to exclude Syslog log-events from banned IPs using AbuseIPDB-service with integration to firewalls\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":464,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"ngg_post_thumbnail":0,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[55,54,57,58],"tags":[18,104,5,105,24,103],"class_list":["post-450","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-azure","category-azure-loganalytics","category-azure-security","category-sentinel","tag-azure","tag-cost","tag-loganalytics","tag-optimization","tag-sentinel","tag-syslog","infinite-scroll-item","resize-featured-image"],"featured_image_src":"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/2-step4.jpg","author_info":{"display_name":"Morten Knudsen","author_link":"https:\/\/mortenknudsen.net\/?author=1"},"jetpack_featured_media_url":"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2022\/12\/2-step4.jpg","jetpack_sharing_enabled":true,"jetpack_likes_enabled":true,"_links":{"self":[{"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=\/wp\/v2\/posts\/450","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=450"}],"version-history":[{"count":38,"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=\/wp\/v2\/posts\/450\/revisions"}],"predecessor-version":[{"id":523,"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=\/wp\/v2\/posts\/450\/revisions\/523"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=\/wp\/v2\/media\/464"}],"wp:attachment":[{"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=450"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=450"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=450"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}