Skip to content

Commit af8d201

Browse files
Merge pull request #313953 from v-alje/AUTOGEN-Sentinel-connectors-Mon_Mar_30_2026-1405
[AUTOGEN] PR for Sentinel connectors
2 parents 2cba6d8 + 8a51c6e commit af8d201

3 files changed

Lines changed: 49 additions & 22 deletions

File tree

articles/sentinel/includes/connector-details.md

Lines changed: 15 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
author: EdB-MSFT
33
ms.author: edbaynash
44
ms.topic: include
5-
ms.date: 03/23/2026
5+
ms.date: 03/30/2026
66

77
# This file is auto-generated. Do not edit manually. Changes will be overwritten.
88
---
@@ -403,7 +403,7 @@ The [Atlassian Jira](https://www.atlassian.com/software/jira) Audit data connect
403403

404404
---
405405

406-
<a name="atlassian-jira-audit-using-rest-api"></a><details><summary>**Atlassian Jira Audit (using REST API)**</summary>
406+
<a name="atlassian-jira-audit-via-codeless-connector-framework"></a><details><summary>**Atlassian Jira Audit (via Codeless Connector Framework)**</summary>
407407

408408
**Supported by:** [Microsoft Corporation](https://support.microsoft.com/)
409409

@@ -446,7 +446,7 @@ The [Auth0 Access Management](https://auth0.com/access-management) data connecto
446446

447447
---
448448

449-
<a name="auth0-logs"></a><details><summary>**Auth0 Logs**</summary>
449+
<a name="auth0-logsvia-codeless-connector-framework"></a><details><summary>**Auth0 Logs(via Codeless Connector Framework)**</summary>
450450

451451
**Supported by:** [Microsoft Corporation](https://support.microsoft.com/)
452452

@@ -909,10 +909,10 @@ This connector uses Azure Functions to pull data from the BeyondTrust PM Cloud A
909909

910910
|Table|DCR support|Lake-only ingestion|
911911
|---|---|---|
912-
|`BeyondTrustPM_ActivityAudits_CL`|No|No|
913-
|`BeyondTrustPM_ClientEvents_CL`|No|No|
912+
|`BeyondTrustPM_ActivityAudits_CL`|Yes|Yes|
913+
|`BeyondTrustPM_ClientEvents_CL`|Yes|Yes|
914914

915-
**Data collection rule support:** Not currently supported
915+
**Data collection rule support:** [Workspace transform DCR](/azure/azure-monitor/logs/tutorial-workspace-transformations-portal)
916916

917917
**Prerequisites:**
918918

@@ -2131,7 +2131,7 @@ When critical systems fail or security incidents happen, SIGNL4 bridges the ‘l
21312131

21322132
<a name="digital-shadows-searchlight-using-azure-functions"></a><details><summary>**Digital Shadows Searchlight (using Azure Functions)**</summary>
21332133

2134-
**Supported by:** [Digital Shadows](https://reliaquest.com/solutions/digital-shadows/)
2134+
**Supported by:** [Digital Shadows](https://www.digitalshadows.com/contact-us/)
21352135

21362136
The Digital Shadows data connector provides ingestion of the incidents and alerts from Digital Shadows Searchlight into the Microsoft Sentinel using the REST API. The connector will provide the incidents and alerts information such that it helps to examine, diagnose and analyse the potential security risks and threats.
21372137

@@ -3328,11 +3328,13 @@ Use this data connector to integrate with InfoSec Crypto Analytics and get data
33283328

33293329
---
33303330

3331-
<a name="ionix-security-logs"></a><details><summary>**IONIX Security Logs**</summary>
3331+
<a name="ionix-security-logs-via-codeless-connector-framework"></a><details><summary>**IONIX Security Logs (via Codeless Connector Framework)**</summary>
3332+
3333+
**Supported by:** [IONIX](https://ionix.io/)
33323334

3333-
**Supported by:** [IONIX](https://cyberpion.com/)
3335+
The IONIX connector allows you to ingest action items from your IONIX Attack Surface Management platform into Microsoft Sentinel using the Codeless Connector Framework (CCF). Action items represent security findings and vulnerabilities that require remediation.
33343336

3335-
The IONIX Security Logs data connector, ingests logs from the IONIX system directly into Sentinel. The connector allows users to visualize their data, create alerts and incidents and improve security investigations.
3337+
**This connector automatically polls the IONIX API and writes data to the CyberpionActionItems_CL table.**
33363338

33373339
**Log Analytics table(s):**
33383340

@@ -3344,7 +3346,7 @@ The IONIX Security Logs data connector, ingests logs from the IONIX system direc
33443346

33453347
**Prerequisites:**
33463348

3347-
- **IONIX Subscription**: A subscription and account is required for IONIX logs. [One can be acquired here.](https://azuremarketplace.microsoft.com/en/marketplace/apps/cyberpion1597832716616.cyberpion)<br><br>
3349+
- **IONIX API Token**: An API token from IONIX Portal is required. Create one in **Settings > API** in your [IONIX Portal](https://portal.ionix.io/).<br><br>
33483350
</details>
33493351

33503352
---
@@ -6136,7 +6138,7 @@ The [Sophos Endpoint Protection](https://www.sophos.com/en-us/products/endpoint-
61366138

61376139
---
61386140

6139-
<a name="sophos-endpoint-protection-using-rest-api"></a><details><summary>**Sophos Endpoint Protection (using REST API)**</summary>
6141+
<a name="sophos-endpoint-protection-via-codeless-connector-platform"></a><details><summary>**Sophos Endpoint Protection (via Codeless Connector Framework)**</summary>
61406142

61416143
**Supported by:** [Microsoft Corporation](https://support.microsoft.com/)
61426144

@@ -6804,7 +6806,7 @@ The [VMware Carbon Black Cloud](https://www.broadcom.com/products/carbon-black/t
68046806

68056807
---
68066808

6807-
<a name="vmware-carbon-black-cloud-via-aws-s3"></a><details><summary>**VMware Carbon Black Cloud via AWS S3**</summary>
6809+
<a name="vmware-carbon-black-cloud-via-aws-s3-via-codeless-connector-framework"></a><details><summary>**VMware Carbon Black Cloud via AWS S3 (via Codeless Connector Framework)**</summary>
68086810

68096811
**Supported by:** [Microsoft](https://support.microsoft.com/)
68106812

articles/sentinel/includes/deprecated-connectors.md

Lines changed: 26 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
author: EdB-MSFT
33
ms.author: edbaynash
44
ms.topic: include
5-
ms.date: 03/17/2026
5+
ms.date: 03/30/2026
66

77
# This file is auto-generated. Do not edit manually. Changes will be overwritten.
88
---
@@ -56,6 +56,31 @@ This data connector ingests Infoblox SOC Insight CDC logs into your Log Analytic
5656

5757
---
5858

59+
<a name="deprecated-ionix-security-logs-push"></a><details><summary>**[Deprecated] IONIX Security Logs (Push)**</summary>
60+
61+
**Supported by:** [IONIX](https://ionix.io/)
62+
63+
⚠️ **This connector is deprecated and will be removed in June 2026.** Please use the new 'IONIX Security Logs (via Codeless Connector Framework)' connector instead, which provides automatic daily polling without requiring manual configuration in the IONIX portal.
64+
65+
---
66+
67+
The IONIX Security Logs data connector ingests logs from the IONIX system directly into Sentinel. The connector allows users to visualize their data, create alerts and incidents and improve security investigations.
68+
69+
**Log Analytics table(s):**
70+
71+
|Table|DCR support|Lake-only ingestion|
72+
|---|---|---|
73+
|`CyberpionActionItems_CL`|No|No|
74+
75+
**Data collection rule support:** Not currently supported
76+
77+
**Prerequisites:**
78+
79+
- **IONIX Subscription**: A subscription and account is required for IONIX logs. [One can be acquired here.](https://azuremarketplace.microsoft.com/en/marketplace/apps/cyberpion1597832716616.cyberpion)<br><br>
80+
</details>
81+
82+
---
83+
5984
<a name="deprecated-lookout"></a><details><summary>**[Deprecated] Lookout**</summary>
6085

6186
**Supported by:** [Lookout](https://www.lookout.com/support)

articles/sentinel/includes/sentinel-tables-connectors.md

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
author: EdB-MSFT
33
ms.author: edbaynash
44
ms.topic: include
5-
ms.date: 03/23/2026
5+
ms.date: 03/30/2026
66
# This file is auto-generated. Do not edit manually. Changes will be overwritten.
77
---
88

@@ -52,7 +52,7 @@ ms.date: 03/23/2026
5252
|[AuditLogs](/azure/azure-monitor/reference/tables/AuditLogs)|[Microsoft Entra ID](/azure/sentinel/data-connectors-reference#microsoft-entra-id)|Yes|Yes|
5353
|Audits_Data_CL|[Vectra XDR (using Azure Functions)](/azure/sentinel/data-connectors-reference#vectra-xdr-using-azure-functions)|Yes|Yes|
5454
|Auth0AM_CL|[Auth0 Access Management (using Azure Functions)](/azure/sentinel/data-connectors-reference#auth0-access-management-using-azure-functions)|No|No|
55-
|Auth0Logs_CL|[Auth0 Logs](/azure/sentinel/data-connectors-reference#auth0-logs)|Yes|Yes|
55+
|Auth0Logs_CL|[Auth0 Logs(via Codeless Connector Framework)](/azure/sentinel/data-connectors-reference#auth0-logsvia-codeless-connector-framework)|Yes|Yes|
5656
|Awareness_Performance_Details_CL|[Mimecast Awareness Training](/azure/sentinel/data-connectors-reference#mimecast-awareness-training)|Yes|Yes|
5757
|Awareness_SafeScore_Details_CL|[Mimecast Awareness Training](/azure/sentinel/data-connectors-reference#mimecast-awareness-training)|Yes|Yes|
5858
|Awareness_User_Data_CL|[Mimecast Awareness Training](/azure/sentinel/data-connectors-reference#mimecast-awareness-training)|Yes|Yes|
@@ -84,8 +84,8 @@ ms.date: 03/23/2026
8484
|BetterMTDDeviceLog_CL|[BETTER Mobile Threat Defense (MTD)](/azure/sentinel/data-connectors-reference#better-mobile-threat-defense-mtd)|No|No|
8585
|BetterMTDIncidentLog_CL|[BETTER Mobile Threat Defense (MTD)](/azure/sentinel/data-connectors-reference#better-mobile-threat-defense-mtd)|No|No|
8686
|BetterMTDNetflowLog_CL|[BETTER Mobile Threat Defense (MTD)](/azure/sentinel/data-connectors-reference#better-mobile-threat-defense-mtd)|No|No|
87-
|BeyondTrustPM_ActivityAudits_CL|[BeyondTrust PM Cloud](/azure/sentinel/data-connectors-reference#beyondtrust-pm-cloud)|No|No|
88-
|BeyondTrustPM_ClientEvents_CL|[BeyondTrust PM Cloud](/azure/sentinel/data-connectors-reference#beyondtrust-pm-cloud)|No|No|
87+
|BeyondTrustPM_ActivityAudits_CL|[BeyondTrust PM Cloud](/azure/sentinel/data-connectors-reference#beyondtrust-pm-cloud)|Yes|Yes|
88+
|BeyondTrustPM_ClientEvents_CL|[BeyondTrust PM Cloud](/azure/sentinel/data-connectors-reference#beyondtrust-pm-cloud)|Yes|Yes|
8989
|BigIDDSPMCatalog_CL|[BigID DSPM connector](/azure/sentinel/data-connectors-reference#bigid-dspm-connector)|Yes|Yes|
9090
|BitglassLogs_CL|[Bitglass (using Azure Functions)](/azure/sentinel/data-connectors-reference#bitglass-using-azure-functions)|No|No|
9191
|BitsightAlerts_data_CL|[Bitsight data connector (using Azure Functions)](/azure/sentinel/data-connectors-reference#bitsight-data-connector-using-azure-functions)|Yes|Yes|
@@ -102,7 +102,7 @@ ms.date: 03/23/2026
102102
|BitwardenEventLogs|[Bitwarden Event Logs](/azure/sentinel/data-connectors-reference#bitwarden-event-logs)|No|No|
103103
|BoxEvents_CL|[Box (using Azure Functions)](/azure/sentinel/data-connectors-reference#box-using-azure-functions)|No|No|
104104
|BoxEventsV2_CL|[Box Events (CCP)](/azure/sentinel/data-connectors-reference#box-events-ccp)|Yes|Yes|
105-
|CarbonBlack_Alerts_CL|[VMware Carbon Black Cloud via AWS S3](/azure/sentinel/data-connectors-reference#vmware-carbon-black-cloud-via-aws-s3)|No|No|
105+
|CarbonBlack_Alerts_CL|[VMware Carbon Black Cloud via AWS S3 (via Codeless Connector Framework)](/azure/sentinel/data-connectors-reference#vmware-carbon-black-cloud-via-aws-s3-via-codeless-connector-framework)|No|No|
106106
|CarbonBlackAuditLogs_CL|[VMware Carbon Black Cloud (using Azure Functions)](/azure/sentinel/data-connectors-reference#vmware-carbon-black-cloud-using-azure-functions)|No|No|
107107
|CarbonBlackEvents_CL|[VMware Carbon Black Cloud (using Azure Functions)](/azure/sentinel/data-connectors-reference#vmware-carbon-black-cloud-using-azure-functions)|No|No|
108108
|CarbonBlackNotifications_CL|[VMware Carbon Black Cloud (using Azure Functions)](/azure/sentinel/data-connectors-reference#vmware-carbon-black-cloud-using-azure-functions)|No|No|
@@ -145,7 +145,7 @@ ms.date: 03/23/2026
145145
|[CrowdStrikeAlerts](/azure/azure-monitor/reference/tables/CrowdStrikeAlerts)|[CrowdStrike API Data Connector (via Codeless Connector Framework)](/azure/sentinel/data-connectors-reference#crowdstrike-api-data-connector-via-codeless-connector-framework)|Yes|Yes|
146146
|CrowdStrikeReplicatorV2|[CrowdStrike Falcon Data Replicator (CrowdStrike Managed AWS-S3) (using Azure Functions)](/azure/sentinel/data-connectors-reference#crowdstrike-falcon-data-replicator-crowdstrike-managed-aws-s3-using-azure-functions)|No|No|
147147
|CyberArk_AuditEvents_CL|[CyberArk Audit](/azure/sentinel/data-connectors-reference#cyberark-audit)<br>[CyberArkAudit (using Azure Functions)](/azure/sentinel/data-connectors-reference#cyberarkaudit-using-azure-functions)|Yes|Yes|
148-
|CyberpionActionItems_CL|[IONIX Security Logs](/azure/sentinel/data-connectors-reference#ionix-security-logs)|No|No|
148+
|CyberpionActionItems_CL|[IONIX Security Logs (via Codeless Connector Framework)](/azure/sentinel/data-connectors-reference#ionix-security-logs-via-codeless-connector-framework)<br>[[DEPRECATED] IONIX Security Logs (Push)](/azure/sentinel/data-connectors-reference#deprecated-ionix-security-logs-push)|No|No|
149149
|CyberSixgill_Alerts_CL|[Cybersixgill Actionable Alerts (using Azure Functions)](/azure/sentinel/data-connectors-reference#cybersixgill-actionable-alerts-using-azure-functions)|No|No|
150150
|CybleVisionAlerts_CL|[Cyble Vision Alerts](/azure/sentinel/data-connectors-reference#cyble-vision-alerts)|No|No|
151151
|CyeraAssets_CL|[Cyera DSPM Microsoft Sentinel Data Connector](/azure/sentinel/data-connectors-reference#cyera-dspm-microsoft-sentinel-data-connector)|No|No|
@@ -328,7 +328,7 @@ ms.date: 03/23/2026
328328
|jamfprotectunifiedlogs_CL|[Jamf Protect Push Connector](/azure/sentinel/data-connectors-reference#jamf-protect-push-connector)|Yes|Yes|
329329
|JBossEvent_CL|[Custom logs via AMA](/azure/sentinel/data-connectors-reference#custom-logs-via-ama)|No|No|
330330
|Jira_Audit_CL|[Atlassian Jira Audit (using Azure Functions)](/azure/sentinel/data-connectors-reference#atlassian-jira-audit-using-azure-functions)|No|No|
331-
|Jira_Audit_v2_CL|[Atlassian Jira Audit (using REST API)](/azure/sentinel/data-connectors-reference#atlassian-jira-audit-using-rest-api)|Yes|Yes|
331+
|Jira_Audit_v2_CL|[Atlassian Jira Audit (via Codeless Connector Framework)](/azure/sentinel/data-connectors-reference#atlassian-jira-audit-via-codeless-connector-framework)|Yes|Yes|
332332
|JuniperIDP_CL|[Custom logs via AMA](/azure/sentinel/data-connectors-reference#custom-logs-via-ama)|Yes|Yes|
333333
|KeeperSecurityEventNewLogs_CL|[Keeper Security Push Connector](/azure/sentinel/data-connectors-reference#keeper-security-push-connector)|Yes|Yes|
334334
|LastPassNativePoller_CL|[LastPass Enterprise - Reporting (Polling CCP)](/azure/sentinel/data-connectors-reference#lastpass-enterprise---reporting-polling-ccp)|No|No|
@@ -451,7 +451,7 @@ ms.date: 03/23/2026
451451
|SOCPrimeAuditLogs_CL|[SOC Prime Platform Audit Logs Data Connector](/azure/sentinel/data-connectors-reference#soc-prime-platform-audit-logs-data-connector)|Yes|Yes|
452452
|Sonrai_Tickets_CL|[Sonrai Data Connector](/azure/sentinel/data-connectors-reference#sonrai-data-connector)|No|No|
453453
|SophosEP_CL|[Sophos Endpoint Protection (using Azure Functions)](/azure/sentinel/data-connectors-reference#sophos-endpoint-protection-using-azure-functions)|Yes|Yes|
454-
|SophosEPEvents_CL|[Sophos Endpoint Protection (using REST API)](/azure/sentinel/data-connectors-reference#sophos-endpoint-protection-using-rest-api)|Yes|Yes|
454+
|SophosEPEvents_CL|[Sophos Endpoint Protection (via Codeless Connector Platform)](/azure/sentinel/data-connectors-reference#sophos-endpoint-protection-via-codeless-connector-platform)|Yes|Yes|
455455
|SquidProxy_CL|[Custom logs via AMA](/azure/sentinel/data-connectors-reference#custom-logs-via-ama)|Yes|Yes|
456456
|[StorageBlobLogs](/azure/azure-monitor/reference/tables/StorageBlobLogs)|[Azure Storage Account](/azure/sentinel/data-connectors-reference#azure-storage-account)|Yes|Yes|
457457
|[StorageFileLogs](/azure/azure-monitor/reference/tables/StorageFileLogs)|[Azure Storage Account](/azure/sentinel/data-connectors-reference#azure-storage-account)|Yes|Yes|

0 commit comments

Comments
 (0)