Microsoft Sentinel
Cloud and workloads

Monitor the health and audit the integrity of your Microsoft Sentinel analytics rules

In brief

The page now describes health and audit logs, SentinelHealth queries, and notifications for analytics rule issues. It also clarifies when SentinelHealth is created, expands NRT terminology, and explains scheduled and Fusion audit rule types.

What Defender admins need to know

Administrators can use the clarified scope and terminology when monitoring analytics rule health; no action is specified.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


title: Monitor the health and audit the integrity of your Microsoft Sentinel analytics rules description: Use theMonitor analytics rule health and audit integrity in Microsoft Sentinel by using health and audit logs, querying SentinelHealth data table to keep track of your analytics rules' executiondata, and performance.setting notifications for rule issues. ms.author: guywild author: guywi-ms ms.reviewer: noak ms.topic: how-to ms.date: 06/15/07/02/2026 ms.custom: sfi-image-nochange, msecd-doc-authoring-10141016 ai-usage: ai-assisted

To get audit and health data from the SentinelHealth and SentinelAudit tables, you must first turn on the Microsoft Sentinel health feature for your workspace. For more information, see Turn on auditing and health monitoring for Microsoft Sentinel.

Once the health feature is turned on, the SentinelHealth data table is created at the first success or failure event generated for your automation rules and playbooks.analytics rules.

Understanding SentinelHealth and SentinelAudit table events

The SentinelHealth table logs the following types of analytics rule health events:

  • Scheduled analytics rule run.
  • NRTNear-real-time (NRT) analytics rule run.

For more information, see SentinelHealth table columns schema.

:::image type="content" source="media/monitor-analytics-rule-integrity/analytics-health-workbook-audit-tab.png" alt-text="Screenshot of selection of audit tab in analytics health workbook.":::

  • Filter the whole page data by audit rule type (scheduled/Fusion)(scheduled or Fusion, which are correlation-based rules that detect multistage attacks).
  • See the trends of audited activity on analytics rules over the selected time period. You can "time brush" the trend graph to see a subset of the original time range. :::image type="content" source="media/monitor-analytics-rule-integrity/audit-trending-by-activity.png" alt-text="Screenshot of trending audit activity in analytics health workbook.":::
  • See the numbers of audited events, broken down by activity and rule type.