Discover more from Rod’s Blog
KQL Queries Behind the Microsoft Sentinel Overview Page
How the sausage is made...Mmmmmm...
Customers and partners regularly ask about the KQL queries that are used to supply the data on the Overview page for Microsoft Sentinel that include overview information about Incidents, Automation, and Data.
If you want these queries for yourself to either a) learn more about KQL, or b) to tinker with creating your own data views in a Workbook, you can find these queries at the following location in my Microsoft Sentinel GitHub repo:
Microsoft Sentinel Overview Page queries: https://github.com/rod-trent/SentinelKQL/tree/master/Overview_Page
The repo is organized into the various Overview Page modules:
P.S. Some have asked why there are no queries supplied for the Analytics widget. The Analytics widget uses the API instead of a KQL query.
UPDATE:offers a great solution if you want to enhance the Automation query to show Playbooks in addition to Automation Rules for the ‘Time Saved’. See the comment: https://rodtrent.substack.com/p/kql-queries-behind-the-microsoft/comment/17384061
[Subscribe to the RSS feed for this blog]
[Subscribe to the Weekly Microsoft Sentinel Newsletter]
[Subscribe to the Weekly Microsoft Defender Newsletter]
[Learn KQL with the Must Learn KQL series and book]
Rod’s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.