Open Sentinel > and click on Workbooks located under the Threat management tab
Select Add Workbook
data:image/s3,"s3://crabby-images/8a297/8a29715ad589e1ba8da1bde3fc1733e43dd1c253" alt=""
Click on edit and use the Add dropdown menu to add items as per your requirements
data:image/s3,"s3://crabby-images/b5eed/b5eed3f7872b401d378d992e77ba289569575da5" alt=""
In this case we will use “Add text” to give our dashboard a name which will be SOC Dashboard
>## SOC Dashboard
Select Done editing to save
Now we will select “Add query” from from the Add dropdown menu
Select required parameters for your Workspace (Dashboard)
In my case I will be using the following:Data source: Logs
Resource Type: Log Analytics
Log Analytics workspace: (Select your Sentinel Workspace name)
Time Range: Last 24 hours
Visualization: Time chart
Size: Medium
We will use the following query which will summarize Sign in Logs by count in the last 24 hours
SigninLogs
| summarize count() by bin(TimeGenerated, 1d)
data:image/s3,"s3://crabby-images/2be11/2be11d1108ea33b0bd9cff2cd08d129f344e2557" alt=""
You can test query by clicking on “Run Query” button.
Once completed you can click “Done Editing” > and the “Save” button.
Make sure you pick the correct subscription, resource group, etc.
data:image/s3,"s3://crabby-images/7018a/7018ace665692fb7038b6f7a1184e6959d7a1812" alt=""
We can no go back to Sentinel Workbooks and verify that we now have added the new workbook we created:
data:image/s3,"s3://crabby-images/c7525/c7525f556585575ed1cda03a7f7351d3f83c68a0" alt=""