Sentinel Data Lake Architecture
A Sentinel data lake architecture combines Analytics, Basic, Auxiliary, long-term retention, search/export jobs, Log Analytics data export rules, Azure Data Lake Storage Gen2, and Azure Data Explorer for tiered security data retention and analysis.
capabilitiesCurrent
Relationships
Microsoft Sentinel
Source productproductSecurityAlert
Related tabletableSecurityIncident
Related tabletableDeviceProcessEvents
Related tabletableDeviceNetworkEvents
Related tabletableThreatIntelIndicators
Related tabletableMicrosoft Sentinel REST API
API accessapiAzure Monitor Logs Ingestion API
API accessapi
Source productproductSecurityAlert
Related tabletableSecurityIncident
Related tabletableDeviceProcessEvents
Related tabletableDeviceNetworkEvents
Related tabletableThreatIntelIndicators
Related tabletableMicrosoft Sentinel REST API
API accessapiAzure Monitor Logs Ingestion API
API accessapi
Configuration Methods
| Method | Support | Reference or Gap |
|---|---|---|
| Portal | Supported | Reference |
| PowerShell | Supported | Reference PowerShell is useful for search jobs and selected operational tasks; use ARM/Bicep/Terraform for durable data export and table plan configuration. |
| REST API | Supported | Reference |
| Graph | Gap | Sentinel data lake configuration is Azure Monitor, Storage, Event Hubs, and Azure Data Explorer infrastructure, not a Microsoft Graph Security configuration surface. |
| ARM | Supported | Reference |
| Bicep | Supported | Reference |
| Terraform | Supported | azurermazurerm_log_analytics_data_export_rule Reference Pair data export rules with storage, Event Hubs, table plan, ADX, and RBAC resources; not every downstream lake schema decision is handled by the export rule. |
| GitHub Actions | Supported | Reference |
| Azure DevOps | Supported | Reference |