Back

Microsoft Sentinel SIEM: Features, Pricing, and Alternatives in 2026

Microsoft Sentinel SIEM: Features, Pricing, and Alternatives in 2026

Microsoft publishes Sentinel’s analytics-tier rates by region, so you can model an ingestion bill against your own daily volume before committing to a workspace. In East US, pay-as-you-go ingestion runs $4.30 per GB, and the 50 GB/day commitment tier costs $161.25 per day.

This guide covers how those meters bill, the extra charges that land under other Azure service names, and three modeled cost scenarios at small, mid-size, and enterprise volumes.

What Is Microsoft Sentinel SIEM?

Microsoft Sentinel is a cloud-hosted security information and event management (SIEM) service that Microsoft runs on Azure as a cloud SIEM. Every deployment sits on a Log Analytics workspace that holds the table plans, retention settings, and Kusto Query Language (KQL) queries an analyst works against. Microsoft describes the product as a cloud-native SIEM combining AI, automation, and threat intelligence, and it ships as one complete service with no separately licensed module.

The product is now moving into the Defender portal on a fixed timeline. The Defender portal is Microsoft’s unified security console for Defender XDR, the extended detection and response suite that correlates alerts across endpoints, identities, email, and cloud apps, and folding Sentinel into that same workspace means analysts run SIEM and XDR from one interface. Workspaces created since July 1, 2025 already onboard there, and every remaining workspace follows by March 31, 2027 when the Azure portal experience retires.

What the Analytics-Tier Rate Includes

Sentinel’s analytics tier is the default table plan for any data an active detection rule reads, and its per-GB rate is the primary meter behind every cost scenario in this guide. The rate bundles analytics rules, hunting, workbooks, threat intelligence, UEBA, automation rules, and 350+ data connectors into a single charge. Sentinel also runs as a SOAR platform (security orchestration, automation, and response), so the usual SIEM vs SOAR split collapses into one product your analysts run from the same portal, though playbooks bill on top as Azure Logic Apps workflows.

The September 2025 release added the data lake at general availability and a Model Context Protocol (MCP) server in preview. Microsoft was also named a Leader in the 2025 Gartner Magic Quadrant for SIEM and holds a Leader position in the IDC MarketScape Worldwide SIEM 2026 Vendor Assessment (doc #US54126826, June 2026).

How Microsoft Sentinel Pricing Works

Sentinel bills through two different meter models depending on when the workspace was created. Older workspaces created before July 2023 still show two separate line items on the Azure bill, one Sentinel commitment tier charge for the security analytics layer and one Azure Monitor commitment tier charge for the underlying Log Analytics ingestion.

Workspaces created after July 2023 use the simplified model, where each GB written to an Analytics-plan table bills at one combined rate that already includes Log Analytics ingestion, so the $2.30/GB Log Analytics pay-as-you-go rate never shows as its own line.

Everything outside the analytics tier runs on separate meters at far lower rates. Retention past 90 days, the data lake, Basic Logs, and Auxiliary Logs each have their own per-GB pricing covered in the sections below.

Pay-as-You-Go

Pay-as-you-go charges only for what reaches the analytics tier each day and carries no daily commitment. The model wins below roughly 38 GB a day, since $161.25 (the 50 GB/day commitment tier price) divided by $4.30 (the pay-as-you-go per-GB rate) works out to 37.5 GB before the 50 GB tier becomes the cheaper option. Regional rates differ, and the Sentinel pricing page includes a selector for pulling the right per-GB number for your workspace region.

Commitment Tiers

A commitment tier fixes a daily price for a set analytics-tier volume, and overage bills at that tier’s effective rate. Tiers save up to 52 percent against pay-as-you-go, and you can raise one immediately, though lowering is limited to once every 31 days.

Tiers also bind to a single workspace and cannot be pooled. The 50 GB/day tier is a public preview promotion, held until March 31, 2027 for sign-ups through December 31, 2026.

East US daily prices, with the effective per-GB rate at each tier, look as follows:

Tier (GB/day)Daily price (East US)Effective per GB
50 (promotional)$161.25$3.23
100$296.00$2.96
200$548.00$2.74
300$800.00$2.67
400$1,037.33$2.59
500$1,265.00$2.53

Data Lake Tier (Lower-Cost Storage)

The data lake tier prices data far below analytics rates. In East US, ingestion runs $0.05/GB, processing $0.10/GB, storage $0.026/GB per month, and query analysis $0.005/GB scanned. Ingestion and processing charges apply only to tables set to data-lake-only retention, and the pricing page still lists 30 days of free storage during preview. Storage bills at 6:1 compression, so 600 GB of raw data counts as 100 GB stored.

Firewall, network, and proxy logs are the usual candidates for the lake, since analytics rules and custom detections don’t run on lake data, and new rows take up to 15 minutes to become queryable. Any table your team needs to alert on in real time belongs in the analytics tier instead.

Basic Logs and Auxiliary Logs

Basic Logs and Auxiliary Logs are Log Analytics table plans built for verbose sources that don’t need analytics rules running against them. Basic ingestion runs $0.50/GB, and Auxiliary is listed at $0.15/GB in Sentinel contexts and $0.05/GB on the Azure Monitor page, with both plans charging $0.005/GB scanned per query.

Basic caps interactive retention at 30 days, while Auxiliary keeps data interactive for the full retention period, and both plans hold data for up to 12 years.

Free Data Sources and Microsoft Licensing Credits

Several Microsoft-native tables ingest at no charge:

  • Azure and Microsoft 365 activity: AzureActivity and OfficeActivity cover SharePoint, Exchange, and Teams.
  • Workspace health: Health-monitoring records in the SentinelHealth table ingest at no charge.
  • Defender and Entra alerts: SecurityAlert and SecurityIncident arrive free from Microsoft Defender extended detection and response (XDR) and Entra ID Protection.

Alerts are free, but raw Defender telemetry and Entra ID sign-in data are billable. Microsoft 365 E5, A5, F5, and G5 tenants also get 5 MB per user per day, worth up to $2,200 a month on a 3,500-seat E5 tenant. Microsoft applies that grant automatically, with no sign-up step.

The Full Cost of Microsoft Sentinel (Including Hidden Charges)

Several Sentinel charges bill on meters outside the analytics rate. They land under other Azure service names, such as Azure Monitor and Logic Apps, so a cost view filtered to Sentinel understates the total.

  • Retention beyond 90 days: free for 90 days, then $0.10/GB per month to two years and $0.02/GB to 12 years, plus per-GB search jobs.
  • Common Event Format (CEF) and Syslog forwarding: the Linux forwarder VM bills as ordinary Azure compute, and extra CEF AdditionalExtensions fields inflate volume.
  • UEBA tables: user and entity behavior analytics needs no license. Its tables bill as stored data.
  • Security Copilot: Security Compute Units (SCUs) cost $4 per SCU per hour provisioned, $6 in overage, above the E5 and E7 bucket.
  • Playbooks and connector functions: automation rules run free; playbooks bill as Azure Logic Apps and some connectors as Azure Functions.
  • Charges after deletion: removing Sentinel leaves ingestion and retention charges running until you delete the Log Analytics workspace.

To get the true cost of running Sentinel, add the retention, forwarder compute, playbook execution, and Copilot SCU charges to the per-GB analytics rate, then check the Azure bill under Azure Monitor, Logic Apps, and Azure Functions for the lines that a Sentinel-only filter hides.

Microsoft Sentinel Cost Scenarios

The scenarios below use published East US simplified rates, a 30-day month, and a 365-day year. Free tables and retention sit outside these numbers. Each row is an original calculation based on those rates.

ScenarioAnalytics-tier volumePricing modelMonthlyAnnual
Small org30 GB/dayPay-as-you-go$3,870$47,085
Mid-size org100 GB/day100 GB commitment tier$8,880$108,040
Enterprise500 GB/day500 GB commitment tier$37,950$461,725

At 30 GB/day the 50 GB tier would cost $4,838 a month, so pay-as-you-go stays cheaper. At 100 GB/day the comparison flips: pay-as-you-go would cost $156,950 a year against $108,040 on the commitment. The 500 GB tier saves $26,550 a month over pay-as-you-go at the same volume.

Sentinel tiers stay bound to a single workspace, and pooling only applies at the Log Analytics layer through a dedicated cluster of at least 100 GB/day. To model retention and daily ingestion by log type against your own workspace, run the numbers through Microsoft’s cost estimator.

How to Reduce Microsoft Sentinel Costs

Savings come from routing detection-relevant tables to the analytics tier and moving everything else to a cheaper table plan, mostly through data collection rules (DCRs). DCRs rewrite rows in the ingestion pipeline before storage, so any filter applied after ingestion has no effect on billed volume.

Six practices cover where the savings actually come from:

  • Filter data before it reaches Sentinel: DCRs apply KQL changes before storage, and workspaces with Sentinel pay no Azure Monitor filtering charge on top. For Windows Security Events, XPath filtering on the source machines is cheaper still, and events 4634 and 4647 are the usual first drops.
  • Route data to the right tier: A split rule in one DCR sends detection-relevant rows to an analytics table and verbose rows to a lake, Basic, or Auxiliary table. Syslog informational rows can go to a custom Auxiliary table while higher-severity events remain in the analytics tier.
  • Use Basic Logs for high-volume, low-value sources: Basic Logs suit web server logs, Domain Name System (DNS) logs, and raw endpoint telemetry that your team reads only during an incident or hunt. Query charges bill the full time range scanned, so three days of a 100 GB/day table costs 300 GB of query charges, and any table an active rule reads belongs in analytics.
  • Maximize free data sources and licensing credits: Configure the free-data connectors throughout the deployment, including Defender XDR, Azure Activity, and Microsoft 365. That volume shows on the Azure bill as the Free Benefit – M365 Defender Analysis meter under the Sentinel service name, and you should subtract it before sizing a commitment tier.
  • Right-size and right-time the commitment tier: Tier sizing should come off 31 days of billable volume in the Usage table, since a tier comes down only once every 31 days. The 100 GB tier pays for itself at 68.8 GB/day ($296 ÷ $4.30), and a workspace averaging 70 GB/day with 15 GB of free Defender alerts bills 55 GB and belongs on the 50 GB tier.
  • Catch ingestion spikes before they hit the bill: Spikes often trace to one connector, and _LogOperation logs an ingestion-rate warning you can alert on every five minutes while Usage shows billable MB per table.

Every practice in the list happens after the data has already been shipped to Azure, so the savings depend on how quickly your team catches misrouted or oversized sources. Coralogix handles the same problem earlier in the chain, processing telemetry in-stream and routing low-value sources to cheaper pipeline tiers before they ever bill as analytics volume.

Microsoft Sentinel Pricing vs. Alternatives

A SIEM pricing comparison should examine which gigabytes each vendor meters and what its rate bundles. The lowest headline number on a list of SIEM tools does not provide that comparison.

Sentinel meters analytics-tier ingestion with UEBA, automation rules, and threat intelligence included. Retention, storage tiers, and automation execution bill separately, so a low headline rate can still land higher.

Microsoft Sentinel vs. Splunk

Splunk sells security through Splunk Enterprise Security running on top of the Splunk platform, and it does not publish a public per-GB rate the way Sentinel does. Customers negotiate pricing against ingest volume, workload, or entity count depending on the contract model, so two organizations pushing the same daily GB can land on very different bills.

Sentinel’s analytics-tier rate is public and bundles analytics into the per-GB number, which gives you a starting point to model against before any negotiation. The final comparison still depends on each organization’s licensing model, data volume, retention, and negotiated terms.

Microsoft Sentinel vs. Coralogix

Coralogix charges $0.42/GB for log ingestion, and its published pricing includes all features and support without itemizing Cloud SIEM as a line of its own. Sentinel meters analytics-tier ingestion at a higher per-GB rate and then adds retention on a separate meter, with 90 days free followed by $0.10/GB per month interactive or $0.02/GB per month long-term, and Copilot SCUs, playbooks, and UEBA storage each show up as their own charges.

Retention economics diverge further past the 90-day window. Coralogix writes telemetry to your own cloud bucket in Parquet format, queryable from the console without rehydration, at roughly $0.003/GB in object storage after 5x compression.

Is Microsoft Sentinel the Right SIEM for Your Organization?

Sentinel makes financial sense when your estate is already Microsoft-shaped. Defender alerts and Microsoft 365 activity land free, while raw Entra ID sign-in data is billable. Sentinel billing uses data ingestion and does not use a per-user E5 slice of Entra or hunting data, and analysts can work incidents in the Defender portal.

The model turns expensive when third-party data dominates. Firewall and proxy logs pay the full analytics rate, as do Amazon Web Services (AWS) or Google Cloud Platform (GCP) logs. Kubernetes application logs carry the same charge. Organizations handling regulated data or facing sophisticated threats benefit from dedicated security staff and/or a 24/7 managed detection and response service like Snowbit MDR to act on alerts around the clock.

On Coralogix, observability and Cloud SIEM data bill through one ingestion meter. If you want to see what your Sentinel analytics volume would cost when observability and SIEM share one meter, the Coralogix pricing page shows the per-GB rates.

Frequently Asked Questions About Microsoft Sentinel SIEM Pricing

Is Microsoft Sentinel being discontinued?

The Azure portal experience retires on March 31, 2027, while the service continues in the Defender portal. Workspaces, KQL queries, and analytics rules carry over.

Is Microsoft Sentinel free?

Microsoft Sentinel is a paid service. The free trial covers 10 GB/day for 31 days on a new workspace. E5 tenants get 5 MB per user daily, and native alert tables ingest free.

Is Microsoft Sentinel still available?

Yes. Sentinel runs in the Defender portal, and the August 18, 2026 retirement covers the Azure operated by 21Vianet region only.

Does Microsoft Sentinel have a SIEM?

Yes. Sentinel is the SIEM itself, and SOAR playbooks and UEBA come with it.

What is a commitment tier in Microsoft Sentinel?

Commitment tiers set a fixed daily price for analytics-tier volume, from 100 GB/day to 50,000 GB/day. Overage bills at the tier’s discounted rate, not the pay-as-you-go rate. Reductions come once every 31 days.

Can I group multiple workspaces and share commitment tiers?

Sentinel tiers apply per workspace. A Log Analytics dedicated cluster of at least 100 GB/day pools the Log Analytics commitment tier across linked workspaces.

What data should I ingest into the analytics tier versus the data lake tier?

Anything an active rule reads stays in the analytics tier; network and firewall logs can go to the lake. Lake tables raise no alerts, so a move there stops their detections.

What other charges should I be aware of when using Microsoft Sentinel?

Retention beyond 90 days, Logic Apps playbook runs, Security Copilot SCUs, and forwarder VM compute bill outside the analytics meter. Some connectors also bill as Azure Functions.

Where can I find legacy meter information?

The Azure Monitor pricing page documents the legacy Search Jobs, Search Queries, and Log Data Restore meters. Workspaces outside the data lake still bill against them.

How is the Microsoft Sentinel MCP server billed?

Microsoft’s pricing FAQ states that “MCP tools invoke underlying Sentinel platform services such as data lake queries or graph operations, which are billed based on their respective meters.” No MCP line item appears on the bill.

What is the 50 GB commitment tier promotion?

The entry tier has a public-preview price and is open to sign-ups through December 31, 2026. Sign-ups in that window hold the price until March 31, 2027.

How does Microsoft Sentinel pricing compare to Splunk?

Splunk pricing depends on customer-specific licensing and negotiated terms, while Sentinel publishes analytics-tier rates and includes analytics in the per-GB rate. Compare the products using your own ingestion, retention, and automation requirements.

Is Azure Sentinel the same as Microsoft Sentinel?

Yes. Microsoft renamed Azure Sentinel at Ignite in November 2021, and workspaces created after July 2023 bill through the single simplified meter instead of the classic dual-meter model.

At what daily ingestion volume does a commitment tier beat pay-as-you-go?

The 50 GB tier breaks even at 37.5 GB/day of billable volume and the 100 GB tier at 68.8 GB/day. Each figure assumes a $4.30/GB pay-as-you-go analytics rate; Microsoft’s published rate varies by region, with US Central listed at $5.22 per GB. Free Defender alert volume doesn’t count.

On this page