Microsoft Sentinel Detection Posture Report
Delivers a weekly report on Microsoft Sentinel table ingestion gaps, analytics rules that are failing, disabled, or blind, and anything in the workspace that needs an admin, from broken data connectors to the daily cap.
What this agent does
This read-only agent checks the health of a Microsoft Sentinel workspace every week. It finds tables and data connectors that stopped receiving data, agents that stopped sending heartbeats, and days when the workspace hit its daily cap. It finds analytics rules whose runs failed, rules that are disabled, and rules whose tables are silent. It summarizes the incidents created and closed since last week. It flags anything that needs an admin.
The challenge
An analytics rule fires only when its table receives data and its query runs. A data connector's app registration secret expires and a whole log source goes dark. A daily cap set to control cost silences the afternoon. A rule's query fails, and only SentinelHealth records it. The incident count drops, and the team takes it as a quiet week.
The solution
The agent checks ingestion, connector health, rule health, and incident activity in one pass each week and compares them with the previous week. It names the data that stopped, the rules that cannot fire, and the fix for each. Provides a weekly briefing a detection engineer can read in a few minutes.
Workflow
- 01
Check ingestion
Compare the latest record time per table and connector with the window, check agent heartbeats, and check the daily cap and ingestion volume.
- 02
Check rule health
Read each analytics rule's enabled state, its run results from the health table, and the tables its query depends on.
- 03
Check activity
Summarize incidents created, closed, and their classifications since last week, by rule.
- 04
Report
Publish what changed and what needs action, with the fix for each item.
Agent template
# Microsoft Sentinel Detection Posture Report
## Measurable outcomes
Every week, the detection engineer knows which data stopped arriving, which analytics rules cannot fire, and what needs action before a detection is missed. Track the silent tables, the unhealthy rules, and the open action items on every run.
## Procedure
Once a week, for the workspace I set, read the latest record time and the daily volume per table. Flag each table with no records in the last 24 hours, unless I set another window or mark it as expected to be quiet, and each table whose volume dropped by more than half against the previous week. Read each data connector's status and flag connectors that are disconnected or whose last data is outside the window. Flag agents and machines with no heartbeat in the window. Flag any day the workspace hit its daily cap. For each enabled analytics rule, read its run results from the health table and flag rules whose runs failed or were throttled in the window, with the reason. Report rule and connector health as not checked when health monitoring is off. Read the tables each rule's query depends on and flag a rule as blind when one of them is silent. List rules that were disabled or changed since last week, with who changed them, and rule templates with an available update. Flag automation rules that close incidents automatically, with their conditions. Summarize the incidents created and closed since the last report, by rule and by closing classification. Flag rules that created nothing in the last 30 days and at least one in the 90 days before. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Report a check it cannot run as not checked, never as fine.
## Requirements
It needs read-only access to the Sentinel workspace to query tables including the health and usage tables, and read-only access to analytics rules, automation rules, data connectors, and incidents, and nothing more. It never changes rules, connectors, workspace settings, or incidents. Related templates
-
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Resource Logging and Delivery
Identifies the AWS log sources in an account that are not enabled or not delivering logs.
Reporting and Compliance / Infrastructure Operations 1 tools -
AWS Security Hub CSPM Posture Report
Delivers a weekly report on Security Hub CSPM coverage across your accounts and regions, what changed in the findings, and anything in the configuration that needs an admin, from disabled controls to broken product integrations.
Reporting and Compliance / Vulnerability Management 2 tools -
Bitbucket Public Repository Posture Audit
Reports the public repositories in a Bitbucket workspace that fail its security policy, with each failing check.
Reporting and Compliance 1 tools