↳ GitHub sourceWorkbook

Incident overview

Description

The Incident Overview workbook is designed to assist in triaging and investigation by providing in-depth information about the incident, including: * General information * Entity data * Triage time (time between incident creation and first response) * Mitigation time (time between incident creation and closing) * Comments Customize this workbook by saving and editing it. You can reach this workbook template from the incidents panel as well. Once you have customized it, the link from the incident panel will open the customized workbook instead of the template.
Version
2.1.0
Declared author / publisher
Microsoft

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
IncidentOverview
Additional source files 3Solutions/SentinelSOARessentials/Workbooks/IncidentOverview.jsonsource ↗Workbooks/WorkbooksMetadata.jsonworkbook-metadata ↗Workbooks/IncidentOverview.jsonsource-occurrence ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 17:57 UTC

GSTEP sync dates, separate from the source content’s publication dates.