capability

Sentinel Data Lake Architecture

A Sentinel data lake architecture combines Analytics, Basic, Auxiliary, long-term retention, search/export jobs, Log Analytics data export rules, Azure Data Lake Storage Gen2, and Azure Data Explorer for tiered security data retention and analysis.

capabilitiesCurrent

Relationships

Configuration Methods

MethodSupportReference or Gap
PortalSupported Reference
PowerShellSupported Reference

PowerShell is useful for search jobs and selected operational tasks; use ARM/Bicep/Terraform for durable data export and table plan configuration.

REST APISupported Reference
GraphGapSentinel data lake configuration is Azure Monitor, Storage, Event Hubs, and Azure Data Explorer infrastructure, not a Microsoft Graph Security configuration surface.
ARMSupported Reference
BicepSupported Reference
TerraformSupportedazurermazurerm_log_analytics_data_export_rule Reference

Pair data export rules with storage, Event Hubs, table plan, ADX, and RBAC resources; not every downstream lake schema decision is handled by the export rule.

GitHub ActionsSupported Reference
Azure DevOpsSupported Reference