Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
07Create detections and perform investigations using Microsoft Sentinel8 modules · 56 units · Analytics, automation, playbooks, incidents, UEBA, ASIM, workbooks, and content management0/56 units complete
Learning path 07 · Create detections and perform investigations using Microsoft Sentinel

8 modules · 56 units · Analytics, automation, playbooks, incidents, UEBA, ASIM, workbooks, and content management

0%

Study focus

Detection and response

Build analytics rules, automate triage, run playbooks, and manage security incidents.

Analytics and content

Apply UEBA, ASIM, KQL, workbooks, Content Hub solutions, and repository-based deployment.

8 modules · 56 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

07

Module 7

Query, visualize, and monitor data in Microsoft Sentinel

Focus: Logs, KQL, workbook templates, custom visualizations, and parameters.
0/8
01 / 08Introduction

Logs supports ad hoc analysis; workbooks turn KQL into reusable interactive views for monitoring, investigation, and reporting.

Official moduleQuery and visualization objectives
02 / 08Exercise - Query and visualize data with Microsoft Sentinel Workbooks

Deploy the Sentinel lab and Azure Activity connector. Confirm records in AzureActivity before building workbook elements.

Official exercisePrepare workbook data
03 / 08Monitor and visualize data

Workbooks combine text, parameters, KQL, metrics, links, tabs, and visualizations. Use charts for comparisons and trends, grids for exact records, and retain drill-down to underlying evidence.

Official lessonWorkbook capabilities
04 / 08Query data using Kusto Query Language

Start with the correct table and time range, filter early, project needed columns, derive fields, aggregate, and order results. Validate cost and meaning before embedding queries in content.

AzureActivity | where TimeGenerated > ago(24h) | summarize Operations=count() by Caller, ActivityStatusValue
Official lessonKQL in Logs
05 / 08Use default Microsoft Sentinel Workbooks

Content Hub solutions install workbook templates. Save a template, confirm required tables have data, and review parameters and queries before trusting its visuals. Saved copies are editable Azure resources.

Official lessonTemplate workbooks
06 / 08Create a new Microsoft Sentinel Workbook
  1. Define audience and question.
  2. Add time or selection parameters.
  3. Add KQL and suitable visuals.
  4. Reference parameters safely.
  5. Save with meaningful resource placement and access control.
Official lessonCustom workbooks
07 / 08Exercise - Visualize data using Microsoft Sentinel Workbooks

Explore Azure Activity logs, save its workbook template, use filters and tables, enter edit mode, and add a KQL-backed parameter to drive interactive analysis.

Official exerciseInteractive workbook view
08 / 08Summary

Reliable workbooks use validated KQL, relevant parameters, appropriate visual encoding, evidence drill-down, and Azure resource governance.

Official moduleSummary and assessment
End of learning pathCreate detections and perform investigations using Microsoft Sentinel