Sentinel storage option priced low for logs you rarely touch. You can still query it via search jobs, KQL jobs and ordinary KQL, and keep data for as long as 12 years in total.
Also called Microsoft Sentinel data lake.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Data lake tier in context, with comparison tables and the common traps.
Terms in this definition
- General-purpose v1
The older storage account kind (
Storage), which lacks access tiers, Archive and premium file shares and retires on 13 October 2026. Converting to ZRS requires first upgrading to GPv2, a one-way change. - KQL
Kusto Query Language, used read-only to query Azure Data Explorer, Log Analytics and Microsoft Sentinel; log alert rules are written in it too.
Related terms
- Blast radius analysis
Replacing attack path analysis on the incident graph, this Defender view shows how a compromised entity might reach critical assets. The Microsoft Sentinel data lake is a prerequisite.
- Hunting graph
A view within advanced hunting in the Defender portal that draws threat scenarios as interactive node-and-edge graphs, powered by the Microsoft Sentinel data lake and graph.
- KQL job
KQL query, run once or on a schedule, against the Microsoft Sentinel data lake, reaching back as far as 12 years; its results can be promoted into the analytics tier.