I've been asked to estimate how much license is needed to ingest Office 365 (and Azure AD) logs.
Not sure what variables are in place - but there are about 1200 users. Does anyone have a ballpark estimate on the size of raw ingestion for that (e,g, 10GB a day)?
Thanks in advance for any insights.
Sizing for O365 is typically not a clear cut exercise. There are so many different variables that can affect the volume. A couple of examples:
My preference is to encourage the customer to turn it on for a few hours/days to get a baseline as the inputs will go back and retrieve 30+ days (depending on size of tenant). This can be done on a dev box etc if customer is worried about prod impact. I normally scope for 500kb > 1mb per user per day (again depending on their usage).
In terms of very rough numbers based on a couple of customers: