Platform
Microsoft Sentinel
35 queries tagged with this platform.
-
Cost & Ingest / Billable Volume
90 Day Billable Cost Per Day Formatted
Daily billable GB and cost over 90 days, formatted as human-readable strings (`$X.XX / Day`, `XGB / Day`). Table-friendly, not chart-friendly.
-
Cost & Ingest / Billable Volume
90 Day Billable Cost Per Day
Daily billable GB and cost over 90 days with numeric `CostUSD`. The default cost-over-time view — plottable and aggregatable.
-
Cost & Ingest / Billable Volume
90 Day Billable Volume By Solution
Billable GB per day for the past 90 days, sliced by Solution, rendered as a column chart.
-
Cost & Ingest / Billable Volume
Efficiency Exercise
Teaching walkthrough of the "average daily ingest" question written four ways, from a slow `search *` to an efficient `Usage`-scoped version with cost. Read this before writing your own daily-average query.
-
Cost & Ingest / Billable Volume
GB Per Table
Ingest volume in GB for a single table (defaults to `SecurityEvent`, swap as needed).
-
Cost & Ingest / Cost By Eventid
Cost Of Eventid By Computer
Breaks the cost of a specific Event ID out by originating computer (defaults to `EventID == 4672`).
-
Cost & Ingest / Cost By Eventid
Cost Of Eventid
Estimated cost of a single Event ID over a time window, using your effective per-GB rate.
-
Cost & Ingest / Cost By Eventid
Cost Of Syslog Events By Severity
Cost of Syslog events grouped by severity level.
-
Cost & Ingest / Cost By Eventid
Eventid By Billedsize
Ingest volume in GB per Event ID from the `SecurityEvent` table.
-
Cost & Ingest / Cost By Eventid
Top 10 Eventids Windows Securityevents
Top 10 most expensive Event IDs from the `SecurityEvent` table over the last 90 days.
-
Cost & Ingest / Cost By Eventid
Top 10 Windowsevent Eventids
Top 10 most expensive Event IDs from the `WindowsEvent` table (AMA-shipped) over the last 90 days.
-
Cost & Ingest / Cost By Table
Cost Of A Table
Estimated dollar cost of a single table over a chosen window, given your effective per-GB rate.
-
Cost & Ingest / Cost By Table
Cost Of Workstations Logging Direct To Sentinel
Find workstations shipping logs directly to Sentinel and estimate what it's costing you.
-
Cost & Ingest / Cost By Table
How Loud Is A Table
Row-count-per-day graph for a given table (defaults to `Syslog`) — a quick "is this table getting louder?" check.
-
Cost & Ingest / Cost By Table
Top 10 Billable MDE Tables
Top 10 most expensive Microsoft Defender for Endpoint tables over the last 90 days.
-
Cost & Ingest / Cost By Table
Top 10 Common Security Logs By Reason With Cost Enhanced
Top `CommonSecurityLog` rows by `Reason` and `LogSeverity` (90d), ranked by event count, with an emoji cost-tier column. Filters out empty/`N/A` reasons.
-
Cost & Ingest / Cost By Table
Top 10 Common Security Logs By Severity With Cost
Top `CommonSecurityLog` groupings by `DeviceVendor`, `DeviceProduct`, and `LogSeverity` (30d), with numeric `CostUSD`.
-
Cost & Ingest / Cost By Table
Top 10 Log Sources With Cost Enhanced
Top log sources by `DataType` (30d) with an emoji cost-tier and formatted `$X.XX` string — table/dashboard friendly.
-
Cost & Ingest / Cost By Table
Top 10 Log Sources With Cost
Top log sources by `DataType` (30d) with numeric `CostUSD`. The chart-friendly default.
-
Cost & Ingest / Cost By Table
Top 10 Security Events With Cost Enhanced
Top `SecurityEvent` `EventID`s (30d) with GiB, emoji cost-tier, and formatted `$X.XX` string.
-
Cost & Ingest / Cost By Table
Top 10 Security Events With Cost
Top `SecurityEvent` `EventID`s with `Activity` (30d) and numeric `CostUSD`.
-
Cost & Ingest / Cost By Table
Top 10 Tables Exclude MDE
Top 10 most expensive log sources over 90 days, excluding MDE, via the fast `Usage` table.
-
Cost & Ingest / Ingest Trends
30 60 90 Day Common Security Log Ingest Trends
Compare `CommonSecurityLog` volume by `DeviceAction` across 30-, 60-, and 90-day periods to spot which actions are driving growth.
-
Cost & Ingest / Ingest Trends
30 60 90 Day Ingest Trends
Same three-window comparison against the `Usage` table for a workspace-wide view.
-
Cost & Ingest / Ingest Trends
Day By Day Change
Percent change in daily ingest volume vs the previous day over the last 31 days.
-
Cost & Ingest / Ingest Trends
Log Sources With Greatest Delta
Which data sources moved the most between the previous 30 days and the current 30 days — the "who suddenly got loud" query.
-
Health Checks
Analytics Rule Health
Analytics Rules that ran successfully in the last 90 days but never produced an alert — candidates for review or tuning.
-
Health Checks
Top 10 Alerts
Top 10 alert names over 90 days with percentage of total and color-coded impact level (High / Moderate / Low).
-
MITRE ATT&CK
Mitre Attack Tactics Observed
Events mapped against MITRE ATT&CK Tactics that have been observed in the environment, with percentage of total.
-
MITRE ATT&CK
Mitre Attack Techniques Observed
Events mapped against MITRE ATT&CK Techniques that have been observed in the environment, with percentage of total.
-
Pi-hole
Pihole Usage
Billable ingest volume for the Pi-hole custom log over the last 90 days.
-
Reference
Sort Function Result Comparison
Side-by-side of `sort by` vs `top` on a cost-per-EventID query, showing that both produce identical results in this case — a small worked example for anyone learning KQL sort semantics.
-
Reporting
Alert Trends
Alerts with significant increases vs the previous 90-day period, with severity categorized.
-
Reporting
Data Sources With Biggest Delta In Log Volume
Data sources with the biggest log-volume delta between comparison periods — configurable tunables at the top of the query.
-
Reporting
Report Queries
Grab-bag of reporting queries starting with MTTR against `SecurityIncident`.