
Explanation:
Box 1: Logs (Analytics)
Need Logs (Analytics) to access incidents for the last 90 days.
Note: In a Microsoft Sentinel workbook, "Logs (Analytics)" refers to the default, full-featured Log Analytics data source for primary security data, offering complete KQL query capabilities and high-speed access, while "Logs (Basic)" utilizes the Basic Logs plan to query less frequently accessed, high-volume, verbose logs at a lower cost, with limitations on retention (8 days), KQL support, and query costs per scanned GB. Analytics logs are more expensive but retain data longer and support full functionality for security operations, whereas Basic logs are a cost- effective option for specific data types with trade-offs in query complexity and scope.
Box 2: Log Analytics
For a Microsoft Sentinel workbook, the data source "resource type" is Log Analytics, which you select when configuring the data source for your query. You then specify one or more Log Analytics workspaces as the source for the data within that resource type.
Reference:
https://learn.microsoft.com/en-us/azure/sentinel/monitor-your-data