Microsoft Sentinel Documentation Statistics

This page provides comprehensive statistics across all Microsoft Sentinel solutions, connectors, tables, content items, and parsers.

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊


Table of Contents

Terminology

Term Description
Published Available in Microsoft Sentinel Content Hub for installation
Unpublished ⚠️ Present on GitHub but not available in Content Hub
Active Published and not deprecated
Deprecated 🚫 Marked as no longer maintained or replaced by newer solution
Discovered 🔍 Found in solution folders but not listed in Solution JSON definitions
In Solutions Listed in the Solution JSON definition file
📦 Solution Content that is part of a published Content Hub package
📄 Standalone GitHub content with metadata but not part of a Solution
🔗 GitHub Only GitHub content without formal metadata
Standalone Reference Tables Tables in Azure Monitor reference not used by any Sentinel solution
Support Tier Support level: Microsoft, Partner, or Community

Solutions

Availability

Metric Total Published Unpublished ⚠️
Solutions 564 463 101
With Connectors 373 301 72
With Content 445 373 72

Support Ownership

Support Tier Total Published Unpublished ⚠️
Microsoft 251 228 23
Partner 281 221 60
Community 14 11 3
Unknown 18 3 15
Total 564 463 101

Other Metrics

Metric Count
Unique Connectors 538
Tables Used 1052

Connectors

Note: The connector count Microsoft reports publicly is the number of active connectors published in solutions, plus 41 connectors (at the time of writing) that are not managed through this GitHub repository — including Logic App connectors and Sentinel data lake-only connectors.

Availability

Metric Total Active Deprecated 🚫 Unpublished ⚠️
In Solutions 538 446 45 47
Discovered 🔍 134 0 110 24
Total 672 446 155 71

Support Ownership

Support Tier Total Active Deprecated 🚫 Unpublished ⚠️
Microsoft 273 163 97 13
Partner 373 271 50 52
Community 22 10 8 4
Unknown 4 2 0 2
Total 672 446 155 71

Collection Methods

Collection Method Total Active Deprecated 🚫 Unpublished ⚠️
CCF 211 183 1 27
AMA 166 36 122 8
Azure Function 129 83 29 17
REST Pull API 53 39 1 13
CCF Push 46 44 0 2
Native 18 16 1 1
Azure Diagnostics 17 17 0 0
Unknown 15 15 0 0
Azure Function (TI Upload API) 15 11 1 3
Unknown (Custom Log) 1 1 0 0
MMA 1 1 0 0
Total 672 446 155 71

Collection Methods by Support Tier

Each cell shows: Active / Deprecated / Unpublished / Total

Collection Method Microsoft Partner Community Unknown
CCF 80 / 1 / 6 / 87 103 / 0 / 17 / 120 0 / 0 / 4 / 4 -
AMA 16 / 73 / 2 / 91 16 / 41 / 4 / 61 4 / 8 / 0 / 12 0 / 0 / 2 / 2
Azure Function 13 / 22 / 2 / 37 69 / 7 / 15 / 91 1 / 0 / 0 / 1 -
REST Pull API 2 / 0 / 2 / 4 31 / 1 / 11 / 43 4 / 0 / 0 / 4 2 / 0 / 0 / 2
CCF Push 2 / 0 / 0 / 2 42 / 0 / 2 / 44 - -
Native 16 / 1 / 1 / 18 - - -
Azure Diagnostics 17 / 0 / 0 / 17 - - -
Unknown 15 / 0 / 0 / 15 - - -
Azure Function (TI Upload API) 1 / 0 / 0 / 1 9 / 1 / 3 / 13 1 / 0 / 0 / 1 -
Unknown (Custom Log) - 1 / 0 / 0 / 1 - -
MMA 1 / 0 / 0 / 1 - - -
Total 163 / 97 / 13 / 273 271 / 50 / 52 / 373 10 / 8 / 4 / 22 2 / 0 / 2 / 4

CCF Capabilities

Metric Count
CCF Connectors (polling) 211
CCF Push Connectors 46
CCF Legacy Connectors 0
Total CCF 257
With config file 236
With capabilities detected 250

Connector Kind (non-default kinds; REST Pull API polling is the default):

Kind Count
REST Pull API Polling (default) 162
Push 46
GCP 16
AmazonWebServicesS3 14
StorageAccountBlobContainer 4
AliCloudSlsV1 2
EdgeGrid 1
None 1
PurviewAudit 1
OCI 1
Oracle 1
WebSocket 1

Authentication Methods:

Auth Type Count
APIKey 84
OAuth2 38
JwtToken 26
Basic 17
ServicePrincipal 4
(none detected) 81

Request Features:

Feature Count
Paging 135
POST 27
Nested 15
MvExpand 2

Ingestion API

API-based connectors use one of two APIs to send data to the workspace:

Ingestion API Total Active Deprecated 🚫 Unpublished ⚠️
Log Ingestion API 104 100 0 4
HTTP Data Collector API 123 69 30 24
Undetermined 3 1 0 2
Total 252 186 31 35

By Collection Method:

Collection Method Log Ingestion API HTTP Data Collector API Undetermined Total
Azure Function 47 71 3 121
REST Pull API 1 52 - 53
CCF Push 46 - - 46
Azure Function (TI Upload API) - - - 0
CCF 10 - - 10
Total 104 123 3 230

Custom Log V1 (CLv1) 🔶

Connectors that use at least one Custom Log V1 table (identified by type-suffixed columns or _CL suffix with compatible collection method).

Metric Count
CLv1 Connectors 144
Active 85
Deprecated 🚫 31
Unpublished ⚠️ 28

By Collection Method:

Collection Method CLv1 Connectors
Azure Function 64
REST Pull API 41
Azure Diagnostics 14
CCF 14
AMA 7
CCF Push 3
Azure Function (TI Upload API) 1
Total 144

By Ingestion API:

Ingestion API CLv1 Connectors
Log Ingestion API 4
HTTP Data Collector API 103
(no API) 34
Total 144

Tables

Overview

2130 tables documented across all discovery sources. 1884 tables have schema information.

Discovery Sources

Each table is assigned a single discovery source ("Discovered Via") by priority: Connector > Content > Docs > Schema. Within doc sources, priority is: Azure Monitor > Defender XDR > Sentinel Tables > Feature Support > Ingestion API. The "Total" column shows how many tables have each source regardless of priority, since a table can appear in multiple sources.

Discovery Source Discovered Via Total
Connector 1052 1052
Content 241 853
Azure Monitor Tables Reference 711 898
Defender XDR Advanced Hunting Schema 0 0
Sentinel Tables and Connectors Reference 13 540
Azure Monitor Tables Feature Support 49 761
Azure Monitor Logs Ingestion API 0 117
Schema 64 1884
Total 2130

Schema Sources

Tables with schema information, by schema source. A single table may have schemas from multiple sources.

Schema Source Tables
Azure Monitor docs 898
DCR 18
KQL validation 767
Connector definition 201
Total unique tables with schema 1884

Custom Log V1 (CLv1) 🔶

471 of 2130 tables are Custom Log V1 tables, identified by type-suffixed columns or _CL suffix with compatible collection method.

By Table Category:

Category CLv1 Tables
Uncategorized 444
Internal 21
GCP 5
Various 1
Total 471

Content

Content Items Summary

Metric Total 📦 In Solution 📦 Discovered 📦 Unpublished 📄 Standalone 🔗 GitHub Only
Content Items 6,990 5,125 98 510 489 1,278

Content Items by Type

Type Total 📦 In Solution 📦 Discovered 📦 Unpublished 📄 Standalone 🔗 GitHub Only
Analytic Rules 2,403 2,214 19 279 158 12
Hunting Queries 2,464 1,286 11 71 134 1,033
Playbooks 898 633 38 73 190 37
Workbooks 592 391 11 49 0 190
Parsers* 559 540 19 38 0 0
Watchlists 49 43 0 0 0 6
Summary Rules 25 18 0 0 7 0

\ Parsers from solution content. See Parsers section for all parsers including legacy.*

Playbook Logic App Connectors

Connectors and built-in actions referenced by playbooks. Managed/custom rows come from Microsoft.Web/connections resources; built-in rows come from walking definition.actions for Http, Function, Workflow, and ApiManagement types. Multiple connection or action instances of the same type within a playbook are aggregated.

Metric Count
Playbooks using Logic App connectors / built-ins 898
Total connector / built-in usages (rows) 2,384
Unique managed/custom connector types 148
  Managed (Microsoft-published) 96
  Custom 56
Unique built-in action types 3
Total built-in action invocations 1,325

Top managed connectors by playbook usage

Connector Playbooks
azuresentinel 698
keyvault 161
azuremonitorlogs 107
teams 104
azureloganalyticsdatacollector 103
office365 71
microsoftsentinel 34
azuread 29
wdatp 29
riskiqpassivetotal 27
hyasinsight 25
virustotal 16
azureblob 15
azuresentinel_1 14
recordedfuturev2 14

Built-in actions by playbook usage

Action type Playbooks Action invocations
http 398 1066
workflow 63 123
function 55 136

Parsers

Category Count
Legacy Parsers 35
Solution Parsers (in Solution JSON) 541
Discovered Parsers 🔍 21
Total Parsers 597
Solutions with Parsers 176

ASIM Parsers

Metric Count
Schemas 13
**Source Parser Pairs*** 97
**Union Parser Pairs*** 7
Empty Parsers 0

* Each parser pair consists of an ASim filtering parser and a vim parameter-based parser.

ASIM Products

Metric Count
Products 104
**Source Parser Pairs*** 97
Schemas Covered 12
Tables Used 91

* Each parser pair consists of an ASim filtering parser and a vim parameter-based parser.

Products per Schema

Schema Products
Authentication 33
NetworkSession 33
WebSession 19
AuditEvent 16
FileEvent 14
Dns 13
ProcessEvent 10
AlertEvent 9
RegistryEvent 7
UserManagement 7
DhcpEvent 2
AgentEvent 1
Total 104

Pre-requisites

Overview

Metric Total Explicit (required) ASIM (optional)
Dependency records 238 238 0
Solutions with dependencies 108 108 0
Unique dependency targets 40 40 0

Most Depended-Upon Solutions

Solution Depended On By
Common Event Format 47
Syslog 31
CustomLogsAma 14
Microsoft Entra ID 10
Microsoft Defender XDR 10
Microsoft 365 9
PaloAlto-PAN-OS 8
Amazon Web Services 8
CiscoASA 6
Azure Firewall 6
Check Point 6
Windows Server DNS 5
Azure Activity 5
Windows Security Events 5
Windows Forwarded Events 5

Generated by Solutions Analyzer - August 2026