- What are workbooks in Azure Sentinel?
- What is the difference between Azure Sentinel workbooks and notebooks?
- Which Microsoft Sentinel security role can Create workbooks?
What are workbooks in Azure Sentinel?
Azure Sentinel workbooks are a way to create and show customizable and interactive reports that can display graphs, charts, and tables. Information can be presented from Log Analytics workspaces using the same Kusto Query Language (KQL) queries that you already know how to use.
What is the difference between Azure Sentinel workbooks and notebooks?
Workbooks are provided for analysts and SOC managers to build interactive views and reports of the Sentinel data. Notebooks should be an integral part of the security team's daily processes, particularly those security teams using Microsoft Sentinel as their SIEM of choice.
Which Microsoft Sentinel security role can Create workbooks?
Security engineers
Create and edit workbooks, analytics rules, and other Microsoft Sentinel resources.