Description
The Incident Overview workbook is designed to assist in triaging and investigation by providing in-depth information about the incident, including:
* General information
* Entity data
* Triage time (time between incident creation and first response)
* Mitigation time (time between incident creation and closing)
* Comments
Customize this workbook by saving and editing it.
You can reach this workbook template from the incidents panel as well. Once you have customized it, the link from the incident panel will open the customized workbook instead of the template.
- Version
- 2.1.0
- Declared author / publisher
- Microsoft
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Data types
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
629d1d3↗- Source identifier
IncidentOverview
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 17:57 UTC