↳ GitHub sourceWorkbook

Windows Audit Checker

Description

Assess Windows Security auditing coverage in your Microsoft Sentinel workspace. The workbook highlights two core gaps: (1) important events not being collected due to disabled or insufficient audit subcategories, and (2) noisy over-collection where outcomes/subcategories aren't required or filtering is missing. It also detects duplicate Event ID collection introduced by overlapping Data Collection Rules (DCRs), helping you eliminate redundant ingestion.
Version
1.1.0
Declared author / publisher
Microsoft Sentinel community

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Connectors

Data types

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
WindowsAuditChecker
Additional source files 2Workbooks/WindowsAuditChecker.jsonsource ↗Workbooks/WorkbooksMetadata.jsonworkbook-metadata ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.