Skip to content
| Marketplace
Sign in
Visual Studio Code>Data Science>Microsoft SentinelNew to Visual Studio Code? Get it now.
Microsoft Sentinel

Microsoft Sentinel

Preview

Microsoft

microsoft.com
|
494 installs
| (0) | Free
Build solutions for Microsoft Security products
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

Microsoft Sentinel for Visual Studio Code (Preview)

This extension simplifies code development for Microsoft Security solutions. The initial release focuses on helping you explore data in the Microsoft Sentinel data lake and run security analytics over historical data. It provides a set of commands for interacting with data in the lake as well as creating and running notebooks using Microsoft-managed Spark compute.

Learn more about this extension

Features

  • Explore data in the lake, including tables and their schema
  • Create and execute notebooks
  • Schedule jobs and manage job lifecycles
  • Utilize Microsoft-managed Spark compute

Requirements

You need to install the Jupyter extension:

Jupyter Extension for Visual Studio Code

Getting started

Sign in to the extension with the account you use to access Microsoft Sentinel and Microsoft Defender.

To use data lake exploration capabilities, you must set up the Microsoft Sentinel data lake. You also need to ensure that you have the appropriate permissions.

  • Set up the data lake
  • Manage permissions to the data lake

Unlock data lake capabilities with notebooks

This extension enables you to utilize Jupyter notebooks for powerful analytics and visualization. You can interact with the data lake using Python and Spark to perform complex transformations, run machine learning models, and create visualizations directly within the notebook environment.

Understand data you have in the data lake by viewing the schema.

Explore lake tables and schema

Access and manipulate data by creating a Jupyter notebook. Get the GitHub Copilot extension to get AI help writing code that’s optimized for your data.

Create notebook using GitHub Copilot

Schedule your notebook to run regularly.

Schedule notebook as a job

Resources and next steps

Brush up on your Python skills by exploring examples and scenarios. View Jupyter notebook examples

Learn more about using the extension:

  • Use the Microsoft Sentinel Provider class
  • Pick a compute pool
  • Review limits
  • Troubleshoot errors

Data and telemetry

The Microsoft Sentinel Extension for Visual Studio Code collects usage data and sends it to Microsoft to help improve our products and services. Read our privacy statement to learn more. This extension respects the telemetry.telemetryLevel setting which you can learn more about at https://code.visualstudio.com/docs/supporting/faq#_how-to-disable-telemetry-reporting.

  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
© 2025 Microsoft