Microsoft Sentinel
Cloud and workloads

Sentinel Workbook Creation

In brief

The article now explains gallery template and WorkbooksMetadata.json attributes, including naming, paths, dependencies, versions, and schema requirements. It also warns that JSON syntax errors can cause build failures.

What Defender admins need to know

Administrators maintaining Sentinel workbook solutions can use the guidance to avoid metadata errors and pull request review findings.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

}

## Related content

- [Publish solutions to Microsoft Sentinel](/azure/sentinel/publish-sentinel-solutions)Workbook attributes

The following sections provide a detailed walkthrough of the gallery template properties and the `WorkbooksMetadata.json` entry attributes.

Template ID

The fromTemplateId attribute identifies the workbook template. It must start with sentinel- and be unique in the repository. It should match the workbookKey in WorkbooksMetadata.json minus the Workbook suffix. For example, workbookKey: "ContosoWorkbook" maps to fromTemplateId: "sentinel-Contoso".

Schema

The $schema attribute defines the workbook schema. Set it to https://github.com/Microsoft/Application-Insights-Workbooks/blob/master/schema/workbook.json.

Workbook key

The workbookKey attribute is the unique key for the workbook entry in WorkbooksMetadata.json. It must be unique among all entries and use the format <Name>Workbook.

Logo file name

The logoFileName attribute must match the logo file in your solution's Logos/ folder.

Description

The description attribute is a brief description shown on the Workbooks blade.

Data types dependencies

The dataTypesDependencies attribute lists the table names that your workbook queries.

Data connectors dependencies

The dataConnectorsDependencies attribute must match the id field in your connector JSON exactly. A mismatch is a common pull request (PR) review finding.

Preview image file names

The previewImagesFileNames attribute lists the preview image filenames only, without a folder path. Place the files in Solutions/<YourSolutionName>/Workbooks/Images/Preview/, named <WorkbookName>Black.png for the dark theme and <WorkbookName>White.png for the light theme. Add a number suffix for each additional tab, such as <WorkbookName>Black1.png and <WorkbookName>Black2.png.

Version

The version attribute is a string, not a number. Use "1.0" for a new workbook.

Title

The title attribute is the display name shown in the Workbooks gallery.

Template relative path

The templateRelativePath attribute is the workbook JSON filename only, without a folder path. For example, CiscoISE.json, not Workbooks/CiscoISE.json.

Provider

The provider attribute is your company name.

Related content