Skip to content

Update Sentinel Costs workbook - #14998

Draft
Dr Bill Mcilhargey (billmcilhargey) wants to merge 1 commit into
Azure:masterfrom
billmcilhargey:feat-sentinel-cost-wkb
Draft

Update Sentinel Costs workbook#14998
Dr Bill Mcilhargey (billmcilhargey) wants to merge 1 commit into
Azure:masterfrom
billmcilhargey:feat-sentinel-cost-wkb

Conversation

@billmcilhargey

Copy link
Copy Markdown

Summary

  • Refine ingestion, free-data, retention, Microsoft 365, and Defender for Servers Plan 2 cost views.
  • Add clearer source-table detail, grant comparisons, parameter validation, and missing-value behavior.
  • Document Data Lake billing boundaries and SOAR/Logic App cost estimation.

Validation

  • Workbooks/SentinelCosts.json parses successfully with ConvertFrom-Json.

Known runtime constraint

  • The SOAR summary uses AzureMetrics; it cannot run when that table is configured for Basic Logs in the selected workspace. An Analytics plan is required for that query.

@billmcilhargey

Copy link
Copy Markdown
Author

WIP - working on getting Data lake cost into here and fixing up SOAR (Playbooks - Logic Apps) and a few other things

Not ready for Review

@billmcilhargey

Copy link
Copy Markdown
Author

WIP - Not ready for review

This workbook continues to be a work in progress. It is still being drafted and tested and is not ready for review.

Summary of Changes

  • Release metadata was increased exactly once from 1.5.1 to 1.6.0 in WorkbooksMetadata.json. The workbook format remains Notebook/1.0.
  • Workbook items expanded from 20 to 53.
  • Added structured sections for ingestion, free Sentinel data, Microsoft 365 benefits, Defender for Servers Plan 2, retention, Data Lake, and SOAR.
  • Added and refined parameters for time range, workspace, ingestion price, retention price, Logic App execution cost, Microsoft 365 eligible seats, and Defender for Servers Plan 2 protected servers or nodes.
  • Added validation rules for positive license counts and non-negative pricing inputs.
  • Reworked ingestion summaries into average size, average cost, total size, and total cost tiles.
  • Added source-table ingestion detail and improved GB and currency formatting.
  • Added free-data summaries for total data, estimated savings, average daily savings, and selected-period savings.
  • Added a free-versus-billable daily ingestion visualization.
  • Added Microsoft 365 eligible-table detail and daily ingestion-versus-grant comparison.
  • Added Microsoft 365 grant and estimated savings calculations based on eligible seat counts.
  • Added Defender for Servers Plan 2 table detail, pooled trend analysis, node identification, daily grant, period grant, grant usage, and estimated savings.
  • Added DfSP2 daily ingestion-versus-grant visualization.
  • Added DfSP2 entitlement guidance and clarified that licensing, protection, and eligibility must be verified separately.
  • Added retention summary tiles for average daily and selected-period costs.
  • Added retained-data-by-source-table detail with data volume and cost columns.
  • Added Microsoft Sentinel Data Lake guidance and links to official cost-management documentation.
  • Added SOAR documentation covering Logic Apps, billable executions, execution pricing, and cost-management validation.
  • Added Logic App subscription, resource-group, and resource selectors.
  • Added an Azure Metrics-based automation cost summary.
  • Added Logic App execution metrics visualization and estimated automation cost tile.
  • Added no-data messages and consistent empty-state styling.
  • Added conditional visibility for optional sections when required inputs are unset.
  • Reorganized and repositioned existing workbook content around the new sections.
  • Expanded titles, section descriptions, assumptions, warnings, and documentation links.
  • Some legacy hidden items remain and still require cleanup, including a duplicate DfSP2 savings item.

Manual Testing

Testing has been performed manually in the Caldova demo tenant:

  1. Open https://security.microsoft.com.
  2. Go to Sentinel → Workbooks → Add workbook.
  3. Select Edit → Advanced Editor.
  4. Press Ctrl+A and remove the existing workbook content.
  5. Copy and paste the complete SentinelCosts.json into the Advanced Editor.
  6. Confirm that the editor reports no errors.
  7. Select Apply first.
  8. Select Done editing second.
  9. Test the workbook sections, parameters, queries, charts, tables, and cost calculations.

Testing is ongoing. The workbook remains in draft and is not ready for review.

Known Limitations

  • The SOAR summary requires the AzureMetrics table to use the Analytics plan. It cannot run when the table is configured for Basic Logs.
  • Data Lake costs are not calculated from the Log Analytics Usage table and must be validated through Microsoft Sentinel Cost Management or Azure Cost Management.
  • Retention, Microsoft 365, DfSP2, and SOAR values are estimates and should not be treated as invoices.

@v-atulyadav v-atulyadav added the Workbook Workbook specialty review needed label Aug 28, 2026
@v-atulyadav
v-atulyadav requested a lite review from Copilot August 28, 2026 04:36

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot was unable to run its full agentic suite in this review.

Updates the Sentinel Costs workbook metadata to reflect a new release version.

Changes:

  • Bump Sentinel Costs workbook metadata version from 1.5.1 to 1.6.0.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Workbook Workbook specialty review needed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants