What’s next?
There are certain things we need to consider after implementing this Microsoft unified XDR and SIEM solution, and here are a few:
- Data retention/archival: Data retention and archival are essential activities for all organizations. They help to protect against data loss and ensure compliance with regulations. However, it is important to configure data retention and archival correctly to avoid unnecessary costs. The cost of data retention and archival depends on several factors, including the amount of data to be retained, the retention period, and the storage method.
When configuring data retention and archival, organizations should consider their compliance requirements and business needs. For example, some companies are required to maintain logs for a certain period of time in order to comply with regulations.
Take the following examples:
- Microsoft Sentinel provides access to interactive data for two years and archival data for up to 12 years. This can be...