Skip to main content

Microsoft Security Stats

Microsoft Security Stats shows data transformation flow and cost savings for Microsoft Azure targets -- Microsoft Sentinel, Azure Blob Storage, and Azure Data Explorer. Use it to track data reduction percentages, compression ratios, and estimated savings across the pipeline.

Accessing Microsoft Security Stats

Navigate to Stats > Microsoft Security Stats from the main navigation.

Time Range Filter

Select a time period using the Presets tab or specify a custom range with the Date & Time Range tab.

PresetPeriod
TodayCurrent calendar day
This WeekCurrent calendar week
This MonthCurrent calendar month
Last 3 MonthsRolling 3-month window

The maximum allowed range is 3 months. Entity selection is not available on this page -- metrics always reflect all Directors and Clusters.

Savings Summary

Three cards in the page header display estimated savings for the selected time period:

CardDescription
Estimated Total SavingsDollar amount based on reduced data volume relative to average ingestion costs in Microsoft targets
Estimated Time SavingsHours saved through automated pipeline processing compared to manual data cleaning, filtering, and enrichment
Reduced Carbon FootprintEstimated CO2 reduction from lower resource utilization across the data transformation chain

Data Transformation

An interactive flow diagram visualizes the end-to-end data transformation pipeline from devices through the VirtualMetric engine to Microsoft Azure targets. Three tabs filter the view by device category.

Overview Tab

Displays the complete data flow across all device types. The left side shows device groups (Servers, Networks) with their collected data sizes. The center shows the VirtualMetric engine stages -- pre-processing, pipeline processing with per-target data reduction, compression, and post-processing. The right side shows the three target destinations (Microsoft Sentinel, Azure Data Explorer, Azure Blob Storage) with delivered data sizes.

Animated edges connect each stage, and each node displays its data volume.

Servers Tab

Same flow diagram layout filtered to server device types only. The left side breaks down individual server platforms (Windows, Linux, macOS) instead of the aggregated device groups.

Network Devices Tab

Same flow diagram layout filtered to network devices only. The left side shows network device vendors instead of the aggregated device groups.

Target Analytics Cards

Four cards below the flow diagram provide detailed metrics for each Microsoft Azure target.

Data Summary

Aggregate metrics across all three Azure targets:

MetricDescription
Raw data routed to Microsoft targetsTotal raw data volume entering the Microsoft target pipeline
Reduced data across pipelinesTotal data volume after pipeline reduction
Data sent to Microsoft targetsFinal data volume delivered to all three targets

A stacked bar shows the proportional distribution across Microsoft Sentinel, Azure Data Explorer, and Azure Blob Storage.

Microsoft Sentinel

MetricDescription
Data sent to Microsoft SentinelTotal data volume for this target
Reduced percentageData reduction achieved by pipelines
Collected raw data from devicesRaw data volume before processing
Data reduced in pipelinesData volume removed by pipeline processing
Data sent to MS Sentinel targetsFinal data delivered to Sentinel

Azure Blob Storage

MetricDescription
Data sent to Azure Blob StorageTotal data volume for this target
Compressed percentageCompression ratio achieved
Collected raw data from devicesRaw data volume before processing
Data compressedData volume after compression
Data sent to Azure Blob Storage targetsFinal data delivered to Blob Storage

Azure Blob Storage uses data compression rather than pipeline data reduction, so the percentage reflects the compression ratio instead of a reduction percentage.

Azure Data Explorer

MetricDescription
Data sent to Azure Data ExplorerTotal data volume for this target
Reduced percentageData reduction achieved by pipelines
Collected raw data from devicesRaw data volume before processing
Data reduced in pipelinesData volume removed by pipeline processing
Data sent to Azure Data Explorer targetsFinal data delivered to Azure Data Explorer