Azure-Sentinel/Workbooks
Joseph McCallum-Nattrass 1ea70ea4e8
Removed Fallback Resource Block
2024-05-23 12:48:05 +01:00
..
Images Merge branch 'master' into pr/10450 2024-05-21 18:10:06 +05:30
42CrunchAPIProtectionWorkbook.json Adding 42CrunchAPIProtectionWorkbook 2023-03-15 14:33:45 +05:30
ADXvsLA.json Update ADXvsLA.json 2021-07-29 11:07:05 +02:00
AIA-Darktrace.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
AIVectraDetectWorkbook.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
AMAmigrationTracker.json Update AMAmigrationTracker.json 2023-05-23 17:44:16 +01:00
ASC-ComplianceandProtection.json Update ASC-ComplianceandProtection.json 2020-10-13 15:28:16 +03:00
AWSS3.json AWS S3 Workbook 2022-02-21 14:47:29 +00:00
AcscEssential8.json fixed fromTemplateId 2023-08-29 18:17:05 +10:00
AdvancedKQL.json resolving workbook validation error 2023-11-11 22:00:54 +05:30
AdvancedWorkbookConcepts.json Fixing documentation violations for PR check 2023-04-20 21:26:46 -04:00
AksSecurity.json Revert "Updated AKS Workbook FileNames" (#6850) 2022-12-08 17:49:26 +05:30
AlsidIoA.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
AlsidIoE.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
AmazonWebServicesNetworkActivities.json Adding Workbooks back to Standalone folder 2022-10-27 15:21:57 +05:30
AmazonWebServicesUserActivities.json Adding Workbooks back to Standalone folder 2022-10-27 15:21:57 +05:30
AnalyticsEfficiency.json coping the content for workbooks 2022-12-02 17:13:59 +05:30
AnalyticsHealthAudit.json Updated AnalyticsHealthAudit.json 2023-02-05 23:21:04 +11:00
AnomaliesVisualization.json coping the content for workbooks 2022-12-02 17:13:59 +05:30
AnomalyData.json coping the content for workbooks 2022-12-02 17:13:59 +05:30
ArchivingBasicLogsRetention.json Merge branch 'master' into pr/7807 2023-07-24 12:16:28 +05:30
AttackSurfaceReduction.json Removed locale from doc links. 2022-06-28 15:33:08 +02:00
AutomationHealth.json Update AutomationHealth.json 2023-08-10 17:46:00 +10:00
AzDDoSStandardWorkbook.json AZ DDOS workbook update (#6377) 2022-10-13 15:12:32 +05:30
AzureActiveDirectoryAuditLogs.json Updating name for Workbook Thycotic 2022-09-01 12:24:24 +05:30
AzureActiveDirectorySignins.json Updating name for Workbook Thycotic 2022-09-01 12:24:24 +05:30
AzureActivity.json changes per PR review by Shain 2021-09-23 14:13:17 -07:00
AzureAuditActivityAndSignin.json Azure Active Directory to Entra ID 2023-11-11 16:56:17 +05:30
AzureFirewall.json changed to gallery templates and added AWS 2019-09-23 09:16:01 +03:00
AzureFirewallWorkbook.json Update AzureFirewallWorkbook.json 2021-09-21 11:59:02 -07:00
AzureInformationProtection.json Moving back workbooks back to workbook folder. 2022-08-16 18:37:13 +05:30
AzureKeyVaultWorkbook.json Update KeyVault workbook 2021-02-02 14:11:14 +02:00
AzureLogCoverage.json Azure Active Directory to Entra ID 2023-11-11 16:56:17 +05:30
AzureNetworkWatcher.json Fix bug 2020-02-04 22:45:23 -08:00
AzureOpenAIMonitoring.json Create AzureOpenAIMonitoring.json 2024-03-22 22:24:11 +05:30
AzureSentinelCost.json Fixed hardcoded price value 2023-06-17 23:01:11 +10:00
AzureSentinelSecurityAlerts.json coping the content for workbooks 2022-12-02 17:13:59 +05:30
AzureServiceHealthWorkbook.json Update AzureServiceHealthWorkbook.json 2024-04-30 09:13:40 +05:30
BETTER_MTD_Workbook.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
Barracuda.json Update Barracuda.json 2023-03-17 14:13:48 +05:30
CheckPoint.json changed to gallery templates and added AWS 2019-09-23 09:16:01 +03:00
Cisco.json Updating name for Workbook Thycotic 2022-09-01 12:24:24 +05:30
CiscoFirepower.json Removing resource references 2022-06-01 08:51:42 +05:30
CiscoMeraki.json Updated w/ IP data 2021-03-09 14:55:53 -06:00
Citrix.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
CitrixWAF.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
CodelessConnectorBuilder.json Create CodelessConnectorBuilder.json 2024-05-09 21:02:46 -04:00
CognniIncidentsWorkbook.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
ConditionalAccessTrendsandChanges.json fixed error 2023-03-23 09:45:10 -04:00
CyberArkEPV.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
CyberpionOverviewWorkbook.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
DCR-Toolkit.json Update DCR-Toolkit.json 2023-10-11 11:59:51 -04:00
DSTIMWorkbook.json Create DSTIMWorkbook.json 2023-11-11 22:13:16 +05:30
DataCollectionHealthMonitoring.json Reverted 'jsonData' to og state, also removed leftover subscriptionId 2022-12-30 12:29:51 +01:00
DelineaWorkbook.json Updating name for Workbook Thycotic 2022-09-01 12:24:24 +05:30
Dns.json Update Dns.json 2023-07-27 15:53:37 +05:30
DoDZeroTrustWorkbook.json Azure Active Directory to Entra ID 2023-11-11 16:56:17 +05:30
DuoSecurity.json Move New Community Content to Proper Location 2021-06-10 10:41:18 -07:00
EventAnalyzer.json Adding Workbooks back to Standalone folder 2022-10-27 15:21:57 +05:30
ExchangeCompromiseHunting.json Update fromTemplateId 2021-03-19 15:52:45 -07:00
ExchangeOnline.json changed to gallery templates and added AWS 2019-09-23 09:16:01 +03:00
ExtraHopDetectionSummary.json CEF Changes for standalone files 2022-09-23 17:33:18 +05:30
F5BIGIPSystemMetrics.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
F5Networks.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
ForcepointCASB.json Adding Workbooks back to Standalone folder 2022-10-27 15:21:57 +05:30
ForcepointCloudSecuirtyGatewayworkbook.json Adding Workbooks back to Standalone folder 2022-10-27 15:21:57 +05:30
ForcepointDLP.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
ForcepointNGFW.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
ForcepointNGFWAdvanced.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
Fortigate.json reverting workbook and fixing validation 2023-03-15 15:09:32 +05:30
GitHubSecurityWorkbook.json more fixes 2020-06-10 02:01:38 +00:00
IOT_Alerts.json Fix IoT workbook template bugs 2020-07-09 10:56:03 +03:00
IdentityAndAccess.json Adding Workbooks back to Standalone folder 2022-10-27 15:21:57 +05:30
IllusiveADS.json Merge branch 'users/demehra/cefchangesstandalon' of https://github.com/Azure/Azure-Sentinel into users/demehra/cefchangesstandalon 2022-09-23 19:03:19 +05:30
IllusiveASM.json Copying back workbooks which were moved to solution. 2022-08-10 11:06:24 +05:30
IncidentOverview.json coping the content for workbooks 2022-12-02 17:13:59 +05:30
IncidentTasksWorkbook.json Adding DCR toolkit workbook, advanced workbook concepts workbook, and incident tasks workbook 2023-04-20 21:12:55 -04:00
InfobloxNIOS.json ACN_CD_InfobloxUpdate (#879) 2020-07-24 11:54:35 -07:00
InsecureProtocols.json Update InsecureProtocols.json 2023-02-15 13:07:13 +01:00
IntrotoKQL.json Updating KQL workbook for summer update 2022-07-26 14:00:49 -04:00
IntsightsIOCWorkbook.json coping the content for workbooks 2022-12-02 17:13:59 +05:30
InvestigationInsights.json resolving workbook validation error 2023-11-11 22:00:54 +05:30
IoTAssetDiscovery.json updating locale 2021-03-22 17:51:10 +02:00
LinuxMachines.json Revert "Package Creation for Syslog-- DO NOT MERGE AS 1P" (#5140) 2022-05-31 12:36:05 +05:30
Log4jPostCompromiseHunting.json Rename Log4jPostCompromiseHunting to Log4jPostCompromiseHunting.json 2022-01-26 08:57:58 +05:30
LogAnalyticsQueryAnalysis.json Create LogAnalyticsQueryAnalysis.json 2022-12-22 00:01:39 +05:30
LogSourcesAndAnalyticRulesCoverage.json Update LogSourcesAndAnalyticRulesCoverage.json 2022-06-17 14:30:13 +02:00
M365SecurityPosture.json Adding M365 Security Posture workbook to go with playbook. 2021-05-24 18:03:49 -04:00
MITREAttack.json coping the content for workbooks 2022-12-02 17:13:59 +05:30
ManualSentinelIncident.json Update ManualSentinelIncident.json 2023-03-31 15:24:04 +02:00
MicrosoftCloudAppSecurity.json Adding Workbooks back to Standalone folder 2022-10-27 15:21:57 +05:30
MicrosoftDefenderForEndPoint.json Update MicrosoftDefenderForEndPoint.json 2022-04-15 00:35:40 +05:30
MicrosoftDefenderForOffice365.json MDO Workbook - Fixing Select All Issue (#7047) 2023-01-17 17:15:35 +05:30
MicrosoftSentinelCostEUR.json Azure Active Directory to Entra ID 2023-11-11 16:56:17 +05:30
MicrosoftSentinelCostGBP.json Azure Active Directory to Entra ID 2023-11-11 16:56:17 +05:30
MicrosoftSentinelDeploymentandMigrationTracker.json Fix Edit Watchlist blade reference in workbook 2024-04-17 08:36:17 -07:00
MicrosoftTeams.json Update MicrosoftTeams.json 2022-02-24 22:45:32 +05:30
NetskopeEvents.json netskope workbook 2022-10-05 23:21:48 -04:00
NormalizedNetworkEvents.json removed fallback resource id KQL error 2024-02-08 14:01:14 +05:30
Office365.json Handled multilingual support in queries 2023-01-12 15:39:46 +05:30
OnapsisAlarmsOverview.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
OneIdentity.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
OptimizationWorkbook.json Update to v1.4 2024-05-12 20:43:06 +10:00
OrcaAlerts.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
PaloAltoNetworkThreat.json Updating to include new CEF Changes 2022-05-31 17:06:53 +05:30
PaloAltoOverview.json Updating to include new CEF Changes 2022-05-31 17:06:53 +05:30
Perimeter81OverviewWorkbook.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
PlaybookHealth.json fixing validations 2023-06-22 14:57:03 +05:30
PrancerSentinelAnalytics.json Create PrancerSentinelAnalytics.json 2023-10-06 18:08:19 +05:30
ProofPointThreatDashboard.json add-new-proofpoint-workbook 2021-08-26 18:26:27 +08:00
ProofpointPOD.json Fix the broken links 2024-03-18 15:24:38 +05:30
ProofpointTAP.json Added the proofpoint tap workbook back 2021-07-23 11:22:14 +05:30
PulseConnectSecure.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
QualysVM.json ACNCD_Custom_DataConnector_v2 (#729) 2020-06-19 14:00:16 -07:00
QualysVMv2.json updated dataType for Qualys V2 version 2021-08-17 12:01:52 +05:30
README.md branding changes 2021-11-29 11:00:33 -08:00
SOCProcessFramework.json Trying to resolve validation error for workbook 2023-11-11 21:38:11 +05:30
SecurityOperationsEfficiency.json Update SecurityOperationsEfficiency.json 2023-07-03 16:16:19 +05:30
SecurityStatus.json coping the content for workbooks 2022-12-02 17:13:59 +05:30
SensitiveOperationsinAzureActivityLogReview.JSON Update SensitiveOperationsinAzureActivityLogReview.JSON 2022-12-07 09:20:42 -06:00
SentinelCosts.json Azure Active Directory to Entra ID 2023-11-11 16:56:17 +05:30
SentinelHealth.json Fixing workbook sync comments 2022-10-06 16:50:52 +05:30
SentinelWorkspaceReconTools.json Azure Active Directory to Entra ID 2023-11-11 16:56:17 +05:30
Sentinel_Central.json Removed Fallback Resource Block 2024-05-23 12:48:05 +01:00
SharePointAndOneDrive.json Update SharePointAndOneDrive.json 2022-02-25 18:09:14 +05:30
SolarWindsPostCompromiseHunting.json Azure Active Directory to Entra ID 2023-11-11 16:56:17 +05:30
SonicWallFirewall.json Removed fallbackResourceIds reference 2024-01-02 12:59:17 -07:00
SophosXGFirewall.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
SquadraTechnologiesSecRMM.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
SymantecProxySG.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
SymantecVIP.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
SysmonThreatHunting.json fix master conflicts 2020-07-02 21:05:26 +02:00
TalonInsights.json Update TalonInsights.json 2023-02-20 18:11:55 +02:00
ThreatIntelligence.json Rename TI workbook template field 2022-07-11 16:05:55 -07:00
TrendMicroDeepSecurityAttackActivity.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
TrendMicroDeepSecurityOverview.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
TrendMicroXDROverview.json Add pipeline API for OAT (#7641) 2023-04-18 14:41:10 +05:30
UnifiSG.json Unifi Security Gateway Connector (#1096) 2021-06-01 11:19:21 -07:00
UnifiSGNetflow.json Unifi Security Gateway Connector (#1096) 2021-06-01 11:19:21 -07:00
UserEntityBehaviorAnalytics.json Update UserEntityBehaviorAnalytics.json 2023-12-15 09:17:34 +01:00
UserMap.json Azure Active Directory to Entra ID 2023-11-11 16:56:17 +05:30
VirtualMachinesInsights.json changed to gallery templates and added AWS 2019-09-23 09:16:01 +03:00
VisualizationDemo.json Update VisualizationDemo.json 2020-07-13 22:22:45 -04:00
WebApplicationFirewallFirewallEvents.json changed to gallery templates and added AWS 2019-09-23 09:16:01 +03:00
WebApplicationFirewallGatewayAccessEvents.json remove resource 2020-07-30 18:28:35 +03:00
WebApplicationFirewallOverview.json changed to gallery templates and added AWS 2019-09-23 09:16:01 +03:00
WebApplicationFirewallWAFTypeEvents.json update WebApplicationFirewallFirewallEvents.json and template validation 2022-04-20 17:29:28 -07:00
WindowsFirewall.json Copying back workbooks which were moved to solution. 2022-08-10 11:06:24 +05:30
WithSecureTopComputersByInfections.json add: WithSecure Elements via Function Solution and Top computers by infections Workbook 2024-02-22 12:25:21 +01:00
WizFindings.json added correct path 2023-09-29 11:22:13 +03:00
WorkbooksMetadata.json Merge branch 'master' into pr/10392 2024-05-16 18:04:39 +05:30
WorkspaceAuditing.json Add files via upload 2020-09-28 17:33:38 +13:00
WorkspaceUsage.json Updates 2024-04-03 17:58:15 +05:30
ZimperiumWorkbooks.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
ZscalerFirewall.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
ZscalerOffice365Apps.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
ZscalerThreats.json update made to clear extra changes 2022-09-23 19:11:44 +05:30
ZscalerWebOverview.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
esetSMCWorkbook.json Copied back workbooks to workbook folder. 2022-06-28 15:15:23 +05:30
microsoftdefenderforidentity.json Fixed typo in microsoftdefenderforidentity.json 2024-04-22 14:44:45 +02:00
pfsense.json workbook, connector, parsers 2021-03-02 22:23:45 +00:00
syslogoverview.json Created a new workbook for Syslog Overview 2022-06-23 00:28:38 +05:30

README.md

How to contribute new workbook

This assumes you already have a workbook that you want to share as a Microsoft Sentinel template.
Once this process is completed, Microsoft Sentinel users will be able to save an instance of your template that will visualize the data in their own workspace.

To learn how to create workbooks - go to workbooks documentation.

  1. Go to your workbook -> edit mode -> advanced editor.

  2. Copy the gallery template.

  3. Add fromTemplateId to your template - this allows us to identify in our telemetry the specific sentinel workbook that was opened. Please be consistent with the format sentinel-"workbookName", for example (in the end of the gallery template):

     "styleSettings": {},
     "fromTemplateId": "sentinel-MyNewWorkbook",
     "$schema": "https://github.com/Microsoft/Application-Insights-Workbooks/blob/master/schema/workbook.json"
    
    
  4. Capture 2 screenshots of your workbook - in dark and light theme (this will eventually be the preview images displayed in the workbooks blade).

Step 2 - Create a pull request to this repository

This pull request will contain:

  • The screenshots of your workbook. Place them under workbooks/images/preview.
    Please be consistent with the filename conventions - the dark theme filename should contain the word "black" and the light theme image should contain the word "white".

  • The gallery template json of your workbook. Place it directly under workbooks directory.

  • (optional) A logo that you want the workbook to display. Place it under workbooks/images/logos - if not supplied - it will be the generic workbooks logo.
    This logo should be in SVG format.

  • Change workbooksMetadata.json file, so that it will contain a new section, which will include:

    {
     "workbookKey": "YourWorkbookKey", // in the format of "<Name>Workbook" - not important what exactly is the name, just make sure it is unique and related to the workbook, for example PaloAltoOverviewWorkbook
    
     "logoFileName": "",//If you added logo - its name goes here
    
     "description": "description of the workbook.", // Will be displayed on the workbooks blade next to the logo and preview images
    
     "dataTypesDependencies": [ "Datatype" ],//The data type(s) that your workbook queries
    
     "dataConnectorsDependencies": [],//Relevant connectors
    
     "previewImagesFileNames": [ ],//The relative path of the preview images you saved under workbooks/images/previews
    
     "version": "1.0", // if this is a new workbook - this should be "1.0"
    
     "title": "Workbook title",//This should be the name of the workbook which will be displayed in the main workbooks blade - for example "Palo Alto overview"
    
     "templateRelativePath": "MyNewWorkbook.json",//The relative path of the JSON of the template (the gallery template you saved) 
    
     "subtitle": "",
    
     "provider": "Microsoft" //The provider of the workbook
     }
    
    

Here is an example of the JSON of Palo Alto workbook:

   {
  "workbookKey": "PaloAltoOverviewWorkbook",
  "logoFileName": "paloalto_logo.svg",
  "description": "Gain insights and comprehensive monitoring into Palo Alto firewalls by analyzing traffic and activities.\nThis workbook correlates all Palo Alto data with threat events to identify suspicious entities and relationships.\nYou can learn about trends across user and data traffic, and drill down into Palo Alto Wildfire and filter results.",
  "dataTypesDependencies": [ "CommonSecurityLog" ],
  "dataConnectorsDependencies": [ "PaloAlto" ],
  "previewImagesFileNames": [ "PaloAltoOverviewWhite1.png", "PaloAltoOverviewBlack1.png", "PaloAltoOverviewWhite2.png", "PaloAltoOverviewBlack2.png", "PaloAltoOverviewWhite3.png", "PaloAltoOverviewBlack3.png" ],
  "version": "1.1",
  "title": "Palo Alto overview",
  "templateRelativePath": "PaloAltoOverview.json",
  "subtitle": "",
  "provider": "Microsoft"
  },

After this PR is approved and completed, every 2 weeks the workbooks in Sentinel will be synced with the ones in github.

How to update an existing workbook

Just create a pull request to this repository in which you change the version of the relevant workbook in the WorkbooksMetadata.json file and change the relevant JSON of the workbook you would like to update. If needed, also update the preview images or the data types.

For any feedback on the instructions Open an issue