Use the Microsoft Sentinel Overview dashboard to view incidents, data, and analytics | Microsoft Sentinel
In brief
The article title and introductory content were revised to emphasize incidents, automation efficiency, data ingestion, and analytics. The automation time-saved formula was rephrased, and links to additional monitoring resources were added.
What Defender admins need to know
Administrators can more quickly identify the Overview dashboard’s coverage and find related monitoring guidance.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Visualize collected data on the Microsoft Sentinel Overview page
After connecting your data sources toUse the Microsoft Sentinel, use theSentinel Overview page to view, monitor, and analyze activities across your environment. This article describes the widgets and graphs available on Microsoft Sentinel's Overview dashboard, including insights into incidents, automation efficiency, data ingestion, and analytics rule status to help you quickly assess the security posture of your environment. Before you start, make sure you meet the prerequisites, including connecting your data sources to Microsoft Sentinel.
[!INCLUDE unified-soc-preview]
Start with a summary of the automation rules activity: Incidents closed by automation, the time the automation saved, and related playbooks health.
Microsoft Sentinel calculates the time saved by automation by finding the average time that a single automation saved, multiplied by the number of incidents resolved by automation.
TheMicrosoft Sentinel uses the following formulais as follows:to calculate time saved by automation:(avgWithout - avgWith) * resolvedByAutomation
Next steps
To continue exploring and monitoring your environment, use the following resources:
Use workbook templates to dive deeper into events generated across your environment. For more information, see Visualize and monitor your data by using workbooks in Microsoft Sentinel.
Turn on Log Analytics query logs to get all queries run from your workspace. For more information, see Audit Microsoft Sentinel queries and activities.
@@ -1,26 +1,26 @@ ----title: View aggregated data from the Overview | Microsoft Sentinel+title: Use the Microsoft Sentinel Overview dashboard to view incidents, data, and analytics | Microsoft Sentinel description: Learn how to quickly view and monitor what's happening across your environment by using Microsoft Sentinel. ms.author: guywild author: guywi-ms ms.reviewer: noak ms.topic: how-to-ms.date: 06/15/2026+ms.date: 07/02/2026 appliesto: - Microsoft Sentinel in the Microsoft Defender portal - Microsoft Sentinel in the Azure portal ms.collection: usx-security ai-usage: ai-assisted-ms.custom: msecd-doc-authoring-1014+ms.custom: msecd-doc-authoring-1016 #Customer intent: As a security analyst, I want to visualize and monitor data on a unified dashboard so that I can efficiently track incidents, automation, data records, and analytics in my environment. --- -# Visualize collected data on the Overview page+# Visualize collected data on the Microsoft Sentinel Overview page -After connecting your data sources to Microsoft Sentinel, use the **Overview** page to view, monitor, and analyze activities across your environment. This article describes the widgets and graphs available on Microsoft Sentinel's **Overview** dashboard, including insights into incidents, automation efficiency, data ingestion, and analytics rule status to help you quickly assess the security posture of your environment.+Use the Microsoft Sentinel **Overview** page to view, monitor, and analyze activities across your environment. This article describes the widgets and graphs available on Microsoft Sentinel's **Overview** dashboard, including insights into incidents, automation efficiency, data ingestion, and analytics rule status to help you quickly assess the security posture of your environment. Before you start, make sure you meet the [prerequisites](#prerequisites), including connecting your data sources to Microsoft Sentinel. [!INCLUDE [unified-soc-preview](includes/unified-soc-preview.md)] @@ -64,7 +64,7 @@ After deploying automation with Microsoft Sentinel, monitor your workspace's aut - Start with a summary of the automation rules activity: Incidents closed by automation, the time the automation saved, and related playbooks health. - Microsoft Sentinel calculates the time saved by automation by finding the average time that a single automation saved, multiplied by the number of incidents resolved by automation. The formula is as follows:+ Microsoft Sentinel calculates the time saved by automation by finding the average time that a single automation saved, multiplied by the number of incidents resolved by automation. Microsoft Sentinel uses the following formula to calculate time saved by automation: `(avgWithout - avgWith) * resolvedByAutomation` @@ -108,6 +108,8 @@ Select the **MITRE view** link to jump to the **MITRE ATT&CK**, where you can vi ## Next steps +To continue exploring and monitoring your environment, use the following resources:+ - Use workbook templates to dive deeper into events generated across your environment. For more information, see [Visualize and monitor your data by using workbooks in Microsoft Sentinel](monitor-your-data.md). - Turn on Log Analytics query logs to get all queries run from your workspace. For more information, see [Audit Microsoft Sentinel queries and activities](audit-sentinel-data.md). 