Skip to content

Update Sentinel Costs workbook - #14998

Open
Dr Bill Mcilhargey (billmcilhargey) wants to merge 6 commits into
Azure:masterfrom
billmcilhargey:feat-sentinel-cost-wkb
Open

Update Sentinel Costs workbook#14998
Dr Bill Mcilhargey (billmcilhargey) wants to merge 6 commits into
Azure:masterfrom
billmcilhargey:feat-sentinel-cost-wkb

Conversation

@billmcilhargey

@billmcilhargey Dr Bill Mcilhargey (billmcilhargey) commented Aug 27, 2026

Copy link
Copy Markdown

Summary

  • Refine ingestion, free-data, retention, Microsoft 365, and Defender for Servers Plan 2 cost views.
  • Add clearer source-table detail, grant comparisons, parameter validation, and missing-value behavior.
  • Document Data Lake billing boundaries and SOAR/Logic App cost estimation.

Validation

  • Workbooks/SentinelCosts.json parses successfully with ConvertFrom-Json.

Known runtime constraint

  • The SOAR summary uses AzureMetrics; it cannot run when that table is configured for Basic Logs in the selected workspace. An Analytics plan is required for that query.

Included Summary From #15020

  • Update the SOC Handbook AzureSentinelCost workbook with reorganized cost sections and updated benefit guidance.
  • Expand the Defender for Servers Plan 2 eligible data-source description to mirror the Microsoft 365 benefit section style.
  • Add the SOC Handbook release note for the packaged workbook enhancements.

Scope

This update intentionally includes only:

  • Solutions/SOC Handbook/Workbooks/AzureSentinelCost.json
  • Solutions/SOC Handbook/ReleaseNotes.md

Other JSON changes from the source branch are excluded.

Validation

  • Parsed Solutions/SOC Handbook/Workbooks/AzureSentinelCost.json as JSON successfully.
  • Verified the branch diff against master contains only the two scoped files.
  • Ran git diff --check on the scoped files successfully.

@billmcilhargey

Copy link
Copy Markdown
Author

WIP - working on getting Data lake cost into here and fixing up SOAR (Playbooks - Logic Apps) and a few other things

Not ready for Review

@billmcilhargey

Copy link
Copy Markdown
Author

WIP - Not ready for review

This workbook continues to be a work in progress. It is still being drafted and tested and is not ready for review.

Summary of Changes

  • Release metadata was increased exactly once from 1.5.1 to 1.6.0 in WorkbooksMetadata.json. The workbook format remains Notebook/1.0.
  • Workbook items expanded from 20 to 53.
  • Added structured sections for ingestion, free Sentinel data, Microsoft 365 benefits, Defender for Servers Plan 2, retention, Data Lake, and SOAR.
  • Added and refined parameters for time range, workspace, ingestion price, retention price, Logic App execution cost, Microsoft 365 eligible seats, and Defender for Servers Plan 2 protected servers or nodes.
  • Added validation rules for positive license counts and non-negative pricing inputs.
  • Reworked ingestion summaries into average size, average cost, total size, and total cost tiles.
  • Added source-table ingestion detail and improved GB and currency formatting.
  • Added free-data summaries for total data, estimated savings, average daily savings, and selected-period savings.
  • Added a free-versus-billable daily ingestion visualization.
  • Added Microsoft 365 eligible-table detail and daily ingestion-versus-grant comparison.
  • Added Microsoft 365 grant and estimated savings calculations based on eligible seat counts.
  • Added Defender for Servers Plan 2 table detail, pooled trend analysis, node identification, daily grant, period grant, grant usage, and estimated savings.
  • Added DfSP2 daily ingestion-versus-grant visualization.
  • Added DfSP2 entitlement guidance and clarified that licensing, protection, and eligibility must be verified separately.
  • Added retention summary tiles for average daily and selected-period costs.
  • Added retained-data-by-source-table detail with data volume and cost columns.
  • Added Microsoft Sentinel Data Lake guidance and links to official cost-management documentation.
  • Added SOAR documentation covering Logic Apps, billable executions, execution pricing, and cost-management validation.
  • Added Logic App subscription, resource-group, and resource selectors.
  • Added an Azure Metrics-based automation cost summary.
  • Added Logic App execution metrics visualization and estimated automation cost tile.
  • Added no-data messages and consistent empty-state styling.
  • Added conditional visibility for optional sections when required inputs are unset.
  • Reorganized and repositioned existing workbook content around the new sections.
  • Expanded titles, section descriptions, assumptions, warnings, and documentation links.
  • Some legacy hidden items remain and still require cleanup, including a duplicate DfSP2 savings item.

Manual Testing

Testing has been performed manually in the Caldova demo tenant:

  1. Open https://security.microsoft.com.
  2. Go to Sentinel → Workbooks → Add workbook.
  3. Select Edit → Advanced Editor.
  4. Press Ctrl+A and remove the existing workbook content.
  5. Copy and paste the complete SentinelCosts.json into the Advanced Editor.
  6. Confirm that the editor reports no errors.
  7. Select Apply first.
  8. Select Done editing second.
  9. Test the workbook sections, parameters, queries, charts, tables, and cost calculations.

Testing is ongoing. The workbook remains in draft and is not ready for review.

Known Limitations

  • The SOAR summary requires the AzureMetrics table to use the Analytics plan. It cannot run when the table is configured for Basic Logs.
  • Data Lake costs are not calculated from the Log Analytics Usage table and must be validated through Microsoft Sentinel Cost Management or Azure Cost Management.
  • Retention, Microsoft 365, DfSP2, and SOAR values are estimates and should not be treated as invoices.

@v-atulyadav v-atulyadav added the Workbook Workbook specialty review needed label Aug 28, 2026
@v-atulyadav
v-atulyadav requested a lite review from Copilot August 28, 2026 04:36

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot was unable to run its full agentic suite in this review.

Updates the Sentinel Costs workbook metadata to reflect a new release version.

Changes:

  • Bump Sentinel Costs workbook metadata version from 1.5.1 to 1.6.0.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Reverts Workbooks/SentinelCosts.json and Workbooks/WorkbooksMetadata.json to master. All enhancements now live in the SOC Handbook solution workbook (AzureSentinelCost.json), bumped to 3.0.8.

Structure: reorganized into 7 collapsible groups - Costing, Free Sentinel Data, E5 Benefits, Defender for Cloud Plan 2, Retention, Commitment Tiers, Data Lake. Parameters scoped per section; TimeRange/Workspace/Price remain global. Removed 10 hidden legacy placeholder items.

New sections: Free Sentinel Data (documented free tables, savings), Retention (>90 day billable retention costs), Commitment Tiers (auto-detected current tier plus usage-based suggestion), Data Lake (per-table storage cost from mirrored volume at documented 6:1 compression, plus manual-entry table for ingestion/processing/query/insights meters that are not observable from the workspace).

Behavior fixes: charts now derive bin size from the selected TimeRange (5m to 30d) instead of fixed daily bins; E5 and Defender P2 grant lines are prorated per interval rather than compared against a full-day allowance; commitment tier recommendation is withheld with a days-remaining countdown until 31 days of billable history exist; Logic App selector now emits concrete resource IDs (selected = Rank <= 10) instead of the value::all sentinel, which prevented the Azure Monitor metrics control from resolving scope.

Defect fixes in the existing workbook: removed 85 invisible U+202F characters embedded in KQL; resolved duplicate item name 'EstimateMdcPlan2Discount - Copy'; corrected 'Defedner' typo; replaced hardcoded \ Defender P2 license price with a DfSP2LicensePrice parameter; scoped the licensing savings query to TimeRange instead of scanning all data; set fallbackResourceIds to [] per workbook guidance; stripped en-us locale codes from 11 Microsoft documentation URLs.

Not included: Package/ artifacts are still at 3.0.7 and require regeneration via build-and-validate.ps1, which needs PowerShell 7 (only 5.1 is available locally).
@billmcilhargey
Dr Bill Mcilhargey (billmcilhargey) marked this pull request as ready for review August 31, 2026 22:16
@billmcilhargey

Copy link
Copy Markdown
Author

Ready for Review and updated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

Copilot was unable to run its full agentic suite in this review.

Pull request overview

Copilot reviewed 2 out of 3 changed files in this pull request and generated 2 comments.

"Metadata": "SolutionMetadata.json",
"BasePath": "C:\\GitHub\\azure-sentinel\\Solutions\\SOC Handbook",
"Version": "3.0.7",
"Version": "3.0.8",
"Metadata": "SolutionMetadata.json",
"BasePath": "C:\\GitHub\\azure-sentinel\\Solutions\\SOC Handbook",
"Version": "3.0.7",
"Version": "3.0.8",
@v-rusraut

Copy link
Copy Markdown
Contributor

Hi Dr Bill Mcilhargey (@billmcilhargey)
After updating the workbook, please package the solution using the V3 tool - https://github.com/Azure/Azure-Sentinel/blob/master/Tools/Create-Azure-Sentinel-Solution/V3/README.md . Additionally, provide a screenshot demonstrating that the workbook is loading data successfully after deployment.

@v-rusraut

Copy link
Copy Markdown
Contributor

Hi Dr Bill Mcilhargey (@billmcilhargey)

Please create package of solution using the V3 tool - https://github.com/Azure/Azure-Sentinel/blob/master/Tools/Create-Azure-Sentinel-Solution/V3/README.md . Additionally, provide a screenshot demonstrating that the workbook is loading data successfully after deployment.

@v-rusraut

Copy link
Copy Markdown
Contributor

Hi Dr Bill Mcilhargey (@billmcilhargey) ,
Please create package of solution.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Workbook Workbook specialty review needed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants