Skip to content

Add PowerQuery efficiency community dashboard - #106

Merged
marcorottigni-s1 merged 2 commits into
Sentinel-One:mainfrom
roarinpenguin:dashboards/powerquery-efficiency
Oct 2, 2026
Merged

marcorottigni-s1 merged 2 commits into
Sentinel-One:mainfrom
roarinpenguin:dashboards/powerquery-efficiency

Conversation

@roarinpenguin

Copy link
Copy Markdown
Contributor

Summary

  • Adds a new community dashboard (dashboards/community/PowerQuery-efficiency-latest/) that monitors per-query performance — execution time, CPU, bytes scanned, selectivity, and errors — using the data lake's own queryOutcome audit telemetry.
  • No connector or parser required: AI SIEM writes this telemetry into All Data itself.
  • Includes metadata.yaml, the dashboard .conf, and a README.md covering field reference, PowerQuery identification (lrqToken vs. marker-comment tracking), coverage caveats, and install steps.

Test plan

  • Import the .conf into a tenant console (Dashboards → New → Import) and confirm panels render against live queryOutcome data
  • Verify the pq_id parameter substitution works for both an lrqToken and a marker-comment value

Monitors per-query performance (time, CPU, bytes scanned, selectivity,
errors) from the data lake's own queryOutcome audit telemetry, with no
connector or parser required.
Split into About (standalone description/how-to-read), Overview (KPIs incl.
an error-rate gauge), Query Anatomy & Optimization (construct-usage and
selectivity-tier donuts, origin x time heatmap), and Troubleshooting & Errors.

Also fixes the purpose parameter, which had become a dead no-op filter during
an earlier quoting-bug fix, and moves the bytes-by-origin panel off the
undocumented "column" graphStyle onto the confirmed stacked_bar pattern.

@marcorottigni-s1 marcorottigni-s1 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved

@marcorottigni-s1
marcorottigni-s1 merged commit b442526 into Sentinel-One:main Oct 2, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants