View aggregated data from the Overview (original) (raw)

After connecting your data sources to Microsoft Sentinel, use the Overview page to view, monitor, and analyze activities across your environment. This article describes the widgets and graphs available on Microsoft Sentinel's Overview dashboard.

Prerequisites

Access the Overview page

If your workspace is onboarded to the Microsoft Defender portal, select General > Overview. Otherwise, select Overview directly. For example:

Screenshot of the Microsoft Sentinel Overview dashboard.

Data for each section of the dashboard is precalculated, and the last refresh time is shown at the top of each section. Select Refresh at the top of the page to refresh the entire page.

View incident data

To help reduce noise and minimize the number of alerts you need to review and investigate, Microsoft Sentinel uses a fusion technique to correlate alerts into incidents. Incidents are actionable groups of related alerts for you to investigate and resolve.

The following image shows an example of the Incidents section on the Overview dashboard:

Screenshot of the Incidents section in the Microsoft Sentinel Overview page.

The Incidents section lists the following data:

Select Manage incidents to jump to the Microsoft Sentinel Incidents page for more details.

View automation data

After deploying automation with Microsoft Sentinel, monitor your workspace's automation in the Automation section of the Overview dashboard.

Screenshot of the Automation section in the Microsoft Sentinel Overview page.

Select the configure automation rules link to the jump the Automation page, where you can configure more automation.

View status of data records, data collectors, and threat intelligence

In the Data section of the Overview dashboard, track information on data records, data collectors, and threat intelligence.

Screenshot of the Data section in the Microsoft Sentinel Overview page.

View the following details:

Select Manage connectors to jump to the Data connectors page, where you can view and manage your data connectors.

View analytics data

Track data for your analytics rules in the Analytics section of the Overview dashboard.

Screenshot of the Analytics section in the Microsoft Sentinel Overview page.

The number of analytics rules in Microsoft Sentinel are shown by status, including enabled, disabled, and autodisabled.

Select the MITRE view link to jump to the MITRE ATT&CK, where you can view how your environment is protected against MITRE ATT&CK tactics and techniques. Select the manage analytics rules link to jump to the Analytics page, where you can view and manage the rules that configure how alerts are triggered.

Next steps