Microsoft Sentinel KQL Analytics Workbench

Guided SIEM view for synthetic Windows SecurityEvent, Entra SigninLogs and AuditLogs correlations.

Synthetic lab only. No Azure tenant, Log Analytics workspace, credentials, tokens, production logs or live Sentinel calls.

For reviewers: 3-minute guided pathStart with SENT-006-POS to see Windows and Entra signals become one synthetic incident.
Analytics
Synthetic cases
Expected alerts
Tuning cases
Pass rate

TablesThresholdEntitiesMatched fieldsSeverity reasonPlaybook

Analyst narrative

KQL query

Incident timeline

TimeTableAccountIPHost/AppAction

Synthetic table rows

TimeGeneratedTablePrimary entityIPResult/EventDetails