Microsoft Sentinel
Cloud and workloads

Data Transformation

In brief

The page date was updated, and the guidance now specifies that transformations to Analytics tables in Sentinel-enabled Log Analytics workspaces are exempt from Azure Monitor’s filtering ingestion charge. The Azure Monitor reference link was also updated.

What Defender admins need to know

No action is required; use the revised guidance when reviewing transformation costs.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

#Customer intent: As a security engineer, I want to customize data ingestion and transformation in Microsoft Sentinel so that analysts can filter, enrich, and secure log data efficiently.

  • The Logs ingestion API allows you to send custom-format logs from any data source to your Log Analytics workspace, and store those logs either in certain standard tables, or in custom-formatted tables that you create. You have full control over the creation of these custom tables, down to specifying the column names and types. The API uses DCRs to define, configure, and apply transformations to these data flows.