Microsoft Sentinel
Cloud and workloads

Summary Rules

In brief

The article date and custom authoring metadata were updated, and its introductory sentence was revised from “This section” to “This article.”

What Defender admins need to know

No administrator action is required; the guidance topics described remain unchanged.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

#customer intent: As a SOC engineer, I want to create summary rules in Microsoft Sentinel to aggregate insights from incoming verbose log to optimize costs and query performance.

Microsoft Sentinel stores summary rule results in custom tables with the Analytics data plan. For more information on data plans and storage costs, see Log table plans.

This sectionarticle explains how to create summary rules, deploy pre-built templates, and review common usage scenarios in Microsoft Sentinel.