|
2 | 2 | author: EdB-MSFT |
3 | 3 | ms.author: edbaynash |
4 | 4 | ms.topic: include |
5 | | -ms.date: 04/06/2026 |
| 5 | +ms.date: 04/13/2026 |
6 | 6 |
|
7 | 7 | # This file is auto-generated. Do not edit manually. Changes will be overwritten. |
8 | 8 | --- |
@@ -2028,6 +2028,23 @@ Ingest IP reputation and malware URL indicators from Cyren using the Common Conn |
2028 | 2028 |
|
2029 | 2029 | --- |
2030 | 2030 |
|
| 2031 | +<a name="d3-smart-soar-incidents"></a><details><summary>**D3 Smart SOAR Incidents**</summary> |
| 2032 | + |
| 2033 | +**Supported by:** [D3 Security](https://d3security.com/company/contact/) |
| 2034 | + |
| 2035 | +The D3 Smart SOAR data connector pulls incidents from D3 Smart SOAR into Microsoft Sentinel using the D3 codeless REST API command endpoint. |
| 2036 | + |
| 2037 | +**Log Analytics table(s):** |
| 2038 | + |
| 2039 | +|Table|DCR support|Lake-only ingestion| |
| 2040 | +|---|---|---| |
| 2041 | +|`D3SOARIncidents_CL`|No|No| |
| 2042 | + |
| 2043 | +**Data collection rule support:** Not currently supported<br><br> |
| 2044 | +</details> |
| 2045 | + |
| 2046 | + --- |
| 2047 | + |
2031 | 2048 | <a name="darktrace-connector-for-microsoft-sentinel-rest-api"></a><details><summary>**Darktrace Connector for Microsoft Sentinel REST API**</summary> |
2032 | 2049 |
|
2033 | 2050 | **Supported by:** [Darktrace](https://darktrace.com/contact) |
@@ -5055,6 +5072,42 @@ The [Netskope](https://docs.netskope.com/en/netskope-help/admin-console/rest-api |
5055 | 5072 |
|
5056 | 5073 | --- |
5057 | 5074 |
|
| 5075 | +<a name="netskope-web-transaction-connector-via-blob-storage"></a><details><summary>**Netskope Web Transaction Connector (via Blob Storage)**</summary> |
| 5076 | + |
| 5077 | +**Supported by:** [Netskope](https://support.netskope.com/access/) |
| 5078 | + |
| 5079 | +The Netskope Web Transaction connector ingests web transaction logs from Netskope Log Streaming into Microsoft Sentinel via Azure Blob Storage using the Codeless Connector Framework (CCF). |
| 5080 | + |
| 5081 | +**Log Analytics table(s):** |
| 5082 | + |
| 5083 | +|Table|DCR support|Lake-only ingestion| |
| 5084 | +|---|---|---| |
| 5085 | +|`NetskopeWebTransactions_CL`|Yes|Yes| |
| 5086 | + |
| 5087 | +**Data collection rule support:** [Workspace transform DCR](/azure/azure-monitor/logs/tutorial-workspace-transformations-portal) |
| 5088 | + |
| 5089 | +**Prerequisites:** |
| 5090 | + |
| 5091 | +- **Subscription permissions**: You need permissions to create the data flow resources: |
| 5092 | +- storage queues (notification queue and dead-letter queue) |
| 5093 | +- event grid topic and subscription (to send 'blob created event' notifications to the notification queue) |
| 5094 | +- role assignments (to grant access for Microsoft Sentinel app to the blob container and the storage queues.) |
| 5095 | +- **Storage Account Network Configuration**: Network restrictions (firewall/IP rules) on the Azure Blob Storage account are **not supported** for this connector due to [Azure Storage firewall restrictions and limitations](/azure/storage/common/storage-network-security-limitations): |
| 5096 | +- IP network rules have**no effect**on requests originating from the same Azure region as the storage account. |
| 5097 | +- IP network rules**cannot restrict**access to Azure services deployed in the same region, as these services use private Azure IP addresses for communication. |
| 5098 | +- Virtual network service endpoint rules do not apply to clients in a paired region. |
| 5099 | + |
| 5100 | +Ensure the storage account's **Networking** blade is set to **Enabled from all networks**. |
| 5101 | +- **Storage Account Role Assignments**: The following Azure RBAC roles must be assigned to the Microsoft Sentinel enterprise application service principal (displayed below) on the **Storage Account** that contains your blob container: |
| 5102 | +- **Storage Blob Data Contributor** — required for reading blob data from the container. |
| 5103 | +- **Storage Queue Data Contributor** — required for managing notification and dead-letter queue messages. |
| 5104 | + |
| 5105 | +To assign these roles: navigate to the Storage Account → **Access Control (IAM)** → **Add role assignment**, search for the service principal ID shown below, and assign both roles. |
| 5106 | +- **Collecting data from Netskope to your blob container**: Follow the steps in the [Netskope Log Streaming documentation](https://docs.netskope.com/en/log-streaming.html) to configure Netskope to stream Web Transaction logs to your Azure Blob Storage container.<br><br> |
| 5107 | +</details> |
| 5108 | + |
| 5109 | + --- |
| 5110 | + |
5058 | 5111 | <a name="netskope-web-transactions-data-connector"></a><details><summary>**Netskope Web Transactions Data Connector**</summary> |
5059 | 5112 |
|
5060 | 5113 | **Supported by:** [Netskope](https://support.netskope.com/access/) |
@@ -5279,12 +5332,12 @@ The Open Systems Logs API Microsoft Sentinel Connector provides the capability t |
5279 | 5332 |
|
5280 | 5333 | |Table|DCR support|Lake-only ingestion| |
5281 | 5334 | |---|---|---| |
5282 | | -|`OpenSystemsZtnaLogs_CL`|No|No| |
| 5335 | +|`OpenSystemsZtnaLogs_CL`|Yes|Yes| |
5283 | 5336 | |`OpenSystemsFirewallLogs_CL`|No|No| |
5284 | 5337 | |`OpenSystemsAuthenticationLogs_CL`|No|No| |
5285 | 5338 | |`OpenSystemsProxyLogs_CL`|No|No| |
5286 | 5339 |
|
5287 | | -**Data collection rule support:** Not currently supported |
| 5340 | +**Data collection rule support:** [Workspace transform DCR](/azure/azure-monitor/logs/tutorial-workspace-transformations-portal) |
5288 | 5341 |
|
5289 | 5342 | **Prerequisites:** |
5290 | 5343 |
|
@@ -5652,6 +5705,27 @@ Ingest Qscout application events into Microsoft Sentinel |
5652 | 5705 |
|
5653 | 5706 | --- |
5654 | 5707 |
|
| 5708 | +<a name="qualys-knowledge-base-via-codeless-connector-framework"></a><details><summary>**Qualys Knowledge Base (via Codeless Connector Framework)**</summary> |
| 5709 | + |
| 5710 | +**Supported by:** [Microsoft Corporation](https://support.microsoft.com/) |
| 5711 | + |
| 5712 | +Ingest Qualys Knowledge Base Vulnerability Data into Microsoft Sentinel using version 2.0 of the Qualys API. |
| 5713 | + |
| 5714 | +**Log Analytics table(s):** |
| 5715 | + |
| 5716 | +|Table|DCR support|Lake-only ingestion| |
| 5717 | +|---|---|---| |
| 5718 | +|[`QualysKnowledgeBase`](/azure/azure-monitor/reference/tables/QualysKnowledgeBase)|Yes|Yes| |
| 5719 | + |
| 5720 | +**Data collection rule support:** [Workspace transform DCR](/azure/azure-monitor/logs/tutorial-workspace-transformations-portal) |
| 5721 | + |
| 5722 | +**Prerequisites:** |
| 5723 | + |
| 5724 | +- **Qualys API access**: Requires a Qualys User Account with read access to the Knowledge Base endpoints.<br><br> |
| 5725 | +</details> |
| 5726 | + |
| 5727 | + --- |
| 5728 | + |
5655 | 5729 | <a name="qualys-vm-knowledgebase-using-azure-functions"></a><details><summary>**Qualys VM KnowledgeBase (using Azure Functions)**</summary> |
5656 | 5730 |
|
5657 | 5731 | **Supported by:** [Microsoft Corporation](https://support.microsoft.com/) |
|
0 commit comments