Microsoft Sentinel
Cloud and workloads

Use the Microsoft Sentinel Overview dashboard to view incidents, data, and analytics | Microsoft Sentinel

In brief

The article title and introductory content were revised to emphasize incidents, automation efficiency, data ingestion, and analytics. The automation time-saved formula was rephrased, and links to additional monitoring resources were added.

What Defender admins need to know

Administrators can more quickly identify the Overview dashboard’s coverage and find related monitoring guidance.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Visualize collected data on the Microsoft Sentinel Overview page

After connecting your data sources toUse the Microsoft Sentinel, use theSentinel Overview page to view, monitor, and analyze activities across your environment. This article describes the widgets and graphs available on Microsoft Sentinel's Overview dashboard, including insights into incidents, automation efficiency, data ingestion, and analytics rule status to help you quickly assess the security posture of your environment. Before you start, make sure you meet the prerequisites, including connecting your data sources to Microsoft Sentinel.

[!INCLUDE unified-soc-preview]

  • Start with a summary of the automation rules activity: Incidents closed by automation, the time the automation saved, and related playbooks health.

    Microsoft Sentinel calculates the time saved by automation by finding the average time that a single automation saved, multiplied by the number of incidents resolved by automation. TheMicrosoft Sentinel uses the following formula is as follows:to calculate time saved by automation:

    (avgWithout - avgWith) * resolvedByAutomation

Next steps

To continue exploring and monitoring your environment, use the following resources: