KeMeT Tech
Field notes

Writeups from the engineers shipping the code.

Production-grade patterns, post-mortems, and migration playbooks. Real numbers from real engagements, written so a senior engineer at your shop can apply them in a week.

siem ·6azure ·5kql ·4sentinel ·3microsoft sentinel ·3detection engineering ·3azure sentinel ·3log-analytics ·1monitoring ·1detection ·1
Jun 22, 2026

Azure Log Analytics Workspace: Design Decisions That Matter at Scale

A Log Analytics Workspace is the foundation of every Azure monitoring and SIEM deployment. Get the workspace topology and cost controls wrong early and you pay for it for years.

#azure#log-analytics#sentinel#monitoring#kql
7 min · Read →
Jun 21, 2026

Microsoft Sentinel Pricing: Where the Bill Comes From and How to Control It

Sentinel's ingestion model punishes noisy data sources fast. Here's how to read your actual bill, pick the right commitment tier, and use tiered log storage to cut costs without losing detection coverage.

#microsoft sentinel#azure#siem#kql#detection engineering
6 min · Read →
Jun 20, 2026

Microsoft Sentinel Training: What Actually Matters in the Field

Most Sentinel courses teach the portal tour. This field note covers what engineers need to operate Sentinel at production scale: KQL, rule testing, cost control, and detection gaps.

#sentinel#detection#kql#azure#siem
6 min · Read →
Jun 11, 2026

Microsoft Sentinel Pricing: What You Actually Pay and How to Cut It

Sentinel bills on two layers most teams never model together. Here is how commitment tiers, free connectors, and Basic Logs interact — with real numbers.

#sentinel#azure#siem#detection-engineering#cost-optimization
6 min · Read →
Jun 10, 2026

Terraform Azure Storage Accounts: Footguns and Production Config

The azurerm_storage_account resource ships with permissive defaults on every security-relevant attribute. Here is how we configure it correctly before production.

#terraform#azure#infrastructure#iac
5 min · Read →
Jun 8, 2026

Azure Sentinel Connectors: What Actually Works in Production

Getting data into Microsoft Sentinel is where most SIEM rollouts quietly fail. This field note covers connector types, AMA migration pitfalls, and DCR routing that holds up under real ingestion load.

#microsoft sentinel#azure sentinel#detection engineering#siem#cloud security
6 min · Read →
May 23, 2026

Microsoft Azure Sentinel in 2026: the portal cutover is five weeks out

The Azure portal for Microsoft Sentinel retires July 1, 2026. This field note covers what breaks if you wait, the query migration already past due, and the new detection capabilities shipping this year.

#azure sentinel#microsoft sentinel#siem#kql#detection engineering
6 min · Read →
May 22, 2026

Migrating Azure Sentinel off MMA: a field guide for production environments

MMA retires August 2024. Here's the AMA + DCR/DCE pattern we used to move fourteen custom connectors with zero ingestion gaps and half the operating cost.

#azure sentinel#siem#log analytics#ama#migration
4 min · Read →
May 21, 2026

Six AI-agent and RAG patterns we keep yanking out of production

Vector retrieval that returns garbage, prompt injection by way of a CSV upload, runaway token bills. Patterns to avoid, with the fix that actually shipped.

#ai agents#rag#llm#security
3 min · Read →