Chapter 8: Creating and Using Workbooks
Microsoft Sentinel workbooks are a way to create and show customizable and interactive reports that can display graphs, charts, and tables. Information can be presented from Log Analytics workspaces using the same Kusto Query Language (KQL) queries that you already know how to use. These workbooks are based on the workbook technology that has already been used with other Azure resources, including Azure Monitor and Log Analytics workspaces.
Microsoft Sentinel provides several templates that are ready for use. You can use these templates to create your own workbook that can then be modified as needed. Most of the data connectors that are used to ingest data come with their own workbooks, to allow you better insight into the data that is being ingested using tables and visualizations, including bar and pie charts. You can also make your own workbooks from scratch, if required.
In this chapter, you will learn the following topics:
-
...