Compare workbooks, playbooks, and notebooks
Workbooks, playbooks, and notebooks are key resources in Microsoft Sentinel that help you automate responses, visualize data, and analyze data, respectively. Sometimes it can be challenging to track which type of resource is right for your task.
This article helps to differentiate between workbooks, playbooks, and notebooks in Microsoft Sentinel:
- After you connect your data sources to Microsoft Sentinel, visualize and monitor the data using workbooks in Microsoft Sentinel. Microsoft Sentinel workbooks are based on Azure Monitor workbooks, and add tables and charts with analytics for your logs and queries to the tools already available in Azure.
- Jupyter notebooks in Microsoft Sentinel are a powerful tool for security investigations and hunting, providing full programmability with a huge collection of libraries for machine learning, visualization, and data analysis. While many common tasks can be carried out in the portal, Jupyter extends the scope of what you can do with this data.
- Use Microsoft Sentinel playbooks to run preconfigured sets of remediation actions to help automate and orchestrate your threat response.
Compare by persona
The following table compares Microsoft Sentinel playbooks, workbooks, and notebooks by the user persona:
Resource | Description |
---|---|
Workbooks |
|
Notebooks |
|
Playbooks |
|
Compare by use
The following table compares Microsoft Sentinel playbooks, workbooks, and notebooks by use case:
Resource | Description |
---|---|
Playbooks | Automation of simple, repeatable tasks:
|
Notebooks |
|
Workbooks |
|
Compare by advantages and challenges
The following table compares the advantages and disadvantages of playbooks, workbooks, and notebooks in Microsoft Sentinel:
Resource | Advantages | Challenges |
---|---|---|
Playbooks |
|
|
Notebooks |
|
|
Workbooks |
|
|