sentinel-ingestion-report

Analyze Microsoft Sentinel ingestion patterns, table volumes, and anomalies via PowerShell.

2|Updated Mar 4, 2026
One-click install
npx skills add https://github.com/msandbu/sentinelday --skill sentinel-ingestion-report
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: sentinel-ingestion-report
Source: https://github.com/msandbu/sentinelday/tree/main/.github/skills/sentinel-ingestion-report
Command: npx skills add https://github.com/msandbu/sentinelday --skill sentinel-ingestion-report

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires pypdf, pdfplumber, pdf2image, and includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill automates the analysis of Microsoft Sentinel ingestion patterns, helping you understand data volume, identify cost drivers, and optimize your data retention and security posture.

Core Features & Use Cases

  • Comprehensive Analysis: Generates detailed reports on table volumes, tier classifications, and ingestion anomalies.
  • Detection Coverage: Cross-references ingestion data with analytic rule coverage to identify gaps and optimization opportunities.
  • Cost Optimization: Provides actionable recommendations for tier migration, DCR filtering, and license benefit utilization.

Quick Start

Use the sentinel ingestion report skill to analyze Sentinel data volume for the last 30 days.

Frequently Asked Questions about sentinel-ingestion-report

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I analyze Microsoft Sentinel ingestion patterns and table volumes?

To analyze Microsoft Sentinel ingestion patterns and table volumes, you can automate the collection of data volume metrics and ingestion anomalies using a PowerShell pipeline with KQL queries and Graph API interactions.

What's the best way to optimize Sentinel log analytics costs and data retention?

The best way to optimize Sentinel log analytics costs is to analyze tier classifications, apply DCR filtering, and utilize license benefits to reduce data volume and adjust retention policies based on ingestion reports.

How does detection coverage analysis work with Sentinel ingestion data?

Detection coverage analysis works by cross-referencing Sentinel ingestion data with analytic rule coverage to identify security gaps and find optimization opportunities within your log analytics workspace.

Can I use PowerShell and KQL queries to identify Sentinel cost drivers and ingestion anomalies?

Yes, you can use PowerShell pipelines with automated KQL queries, REST API calls, and Graph API interactions to identify Sentinel cost drivers, ingestion anomalies, and table volume distributions.

Does this Sentinel ingestion analysis support tier migration and DCR filtering recommendations?

Yes, this Sentinel ingestion analysis supports tier migration and DCR filtering recommendations by evaluating table tier classifications and identifying actionable cost optimization opportunities across your workspace.