Skip to content

Microsoft Sentinel: data connectors, data health and cost awareness

How security data reaches Microsoft Sentinel: solutions from the Content hub, service-to-service and agent-based connectors, the Azure Monitor Agent for Syslog, CEF and Windows events, and custom ingestion. How to prove data is really arriving, and how data tiers and data choices drive cost, without guessing prices.

Level
Beginner
Length
About 50 minutes
Contents
3 lessons · final exam
Status
Published · updated 1 Oct 2026
  • Microsoft Sentinel

Skills you'll practise

  • Explain how connectors are delivered through Content hub solutions and name the main connector types
  • Identify the table that Syslog, CEF and Windows Security Events via AMA data lands in
  • Verify that a data source is ingesting by querying its table and using the health features
  • Classify log sources as primary or secondary security data and choose the analytics or data lake tier
  • Describe the cost levers (data volume, event sets, tiers, free data types) without quoting prices

Course outline

  1. 1.How data gets into Microsoft SentinelLesson · 17 min
  2. 2.Proving the data is really arrivingLesson · 15 min
  3. 3.Data tiers and cost awarenessLesson · 18 min
  4. 4.Microsoft Sentinel: data connectors, data health and cost awareness: knowledge checkKnowledge check · 14 questions
  5. 5.Firewall detections went quietScenario
  6. 6.Final exam10 questions · passing it completes the course, so people who already know the material can test out

Sources it draws on

The lessons and questions are written from these references, so learners can go back to the original.

See it with your own jobs and topics

Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.