Creating workbooks
In Microsoft Sentinel, we can use workbooks to define what we want to monitor and how we do it. Similar to alert rules, we have the option to use predefined templates or to create custom alerts. In contrast with alert rules, with workbooks, we create dashboards to monitor data in real time.
When the first edition of this book came out, there were 39 connectors available. This is another indicator of how fast Microsoft Sentinel is developing. At this moment, there are 114 templates available, and this list is very similar to the list of data connectors. Basically, there is at least one workbook template for each data connector. We can choose any template for the list displayed in the following screenshot:
Each template will enable an additional dashboard that is customized to monitor a certain data source. In the following screenshot, we can see the dashboard for Azure activities...