Microsoft Sentinel, Microsoft’s SIEM/SOAR solution, uses an Azure Log Analytics Workspace as it’s backend and as such previously the pricing of sentinel was split between the Log Analytics Workspace and the Sentinel Service. This month (July 2023) Microsoft has been rolling out a simplified pricing for new Sentinel Workspaces.
As you can see below, in an older workspace, we have both the Microsoft Sentinel pricing and the Log Analytics pricing commitments and shown separately.
You will also notice that on the top right there is an option to migrate to the new consolidated pricing.
In a new Sentinel instance, you can see that it is automatically created with the new unified costing.
So, does this make Microsoft Sentinel cheaper?
The short answer is no! The new unified pricing makes the understanding of your Microsoft bill somewhat easier to understand.
However, one area where there is a saving is with the 500MB free ingestion for Defender for Servers Plan 2. Previously the benefit was for the ingestion of the logs into Log Analytics Workspace only but with the new consolidated pricing model the free allowance is also applied for Sentinel.