Skip to content

Commit b13d8df

Browse files
authored
Merge pull request #314658 from v-alje/AUTOGEN-Sentinel-connectors-Mon_Apr_13_2026-1302
[AUTOGEN] PR for Sentinel connectors
2 parents 2b9cb36 + a6398c2 commit b13d8df

2 files changed

Lines changed: 82 additions & 5 deletions

File tree

articles/sentinel/includes/connector-details.md

Lines changed: 77 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
author: EdB-MSFT
33
ms.author: edbaynash
44
ms.topic: include
5-
ms.date: 04/06/2026
5+
ms.date: 04/13/2026
66

77
# This file is auto-generated. Do not edit manually. Changes will be overwritten.
88
---
@@ -2028,6 +2028,23 @@ Ingest IP reputation and malware URL indicators from Cyren using the Common Conn
20282028

20292029
---
20302030

2031+
<a name="d3-smart-soar-incidents"></a><details><summary>**D3 Smart SOAR Incidents**</summary>
2032+
2033+
**Supported by:** [D3 Security](https://d3security.com/company/contact/)
2034+
2035+
The D3 Smart SOAR data connector pulls incidents from D3 Smart SOAR into Microsoft Sentinel using the D3 codeless REST API command endpoint.
2036+
2037+
**Log Analytics table(s):**
2038+
2039+
|Table|DCR support|Lake-only ingestion|
2040+
|---|---|---|
2041+
|`D3SOARIncidents_CL`|No|No|
2042+
2043+
**Data collection rule support:** Not currently supported<br><br>
2044+
</details>
2045+
2046+
---
2047+
20312048
<a name="darktrace-connector-for-microsoft-sentinel-rest-api"></a><details><summary>**Darktrace Connector for Microsoft Sentinel REST API**</summary>
20322049

20332050
**Supported by:** [Darktrace](https://darktrace.com/contact)
@@ -5055,6 +5072,42 @@ The [Netskope](https://docs.netskope.com/en/netskope-help/admin-console/rest-api
50555072

50565073
---
50575074

5075+
<a name="netskope-web-transaction-connector-via-blob-storage"></a><details><summary>**Netskope Web Transaction Connector (via Blob Storage)**</summary>
5076+
5077+
**Supported by:** [Netskope](https://support.netskope.com/access/)
5078+
5079+
The Netskope Web Transaction connector ingests web transaction logs from Netskope Log Streaming into Microsoft Sentinel via Azure Blob Storage using the Codeless Connector Framework (CCF).
5080+
5081+
**Log Analytics table(s):**
5082+
5083+
|Table|DCR support|Lake-only ingestion|
5084+
|---|---|---|
5085+
|`NetskopeWebTransactions_CL`|Yes|Yes|
5086+
5087+
**Data collection rule support:** [Workspace transform DCR](/azure/azure-monitor/logs/tutorial-workspace-transformations-portal)
5088+
5089+
**Prerequisites:**
5090+
5091+
- **Subscription permissions**: You need permissions to create the data flow resources:
5092+
- storage queues (notification queue and dead-letter queue)
5093+
- event grid topic and subscription (to send 'blob created event' notifications to the notification queue)
5094+
- role assignments (to grant access for Microsoft Sentinel app to the blob container and the storage queues.)
5095+
- **Storage Account Network Configuration**: Network restrictions (firewall/IP rules) on the Azure Blob Storage account are **not supported** for this connector due to [Azure Storage firewall restrictions and limitations](/azure/storage/common/storage-network-security-limitations):
5096+
- IP network rules have**no effect**on requests originating from the same Azure region as the storage account.
5097+
- IP network rules**cannot restrict**access to Azure services deployed in the same region, as these services use private Azure IP addresses for communication.
5098+
- Virtual network service endpoint rules do not apply to clients in a paired region.
5099+
5100+
Ensure the storage account's **Networking** blade is set to **Enabled from all networks**.
5101+
- **Storage Account Role Assignments**: The following Azure RBAC roles must be assigned to the Microsoft Sentinel enterprise application service principal (displayed below) on the **Storage Account** that contains your blob container:
5102+
- **Storage Blob Data Contributor** — required for reading blob data from the container.
5103+
- **Storage Queue Data Contributor** — required for managing notification and dead-letter queue messages.
5104+
5105+
To assign these roles: navigate to the Storage Account → **Access Control (IAM)****Add role assignment**, search for the service principal ID shown below, and assign both roles.
5106+
- **Collecting data from Netskope to your blob container**: Follow the steps in the [Netskope Log Streaming documentation](https://docs.netskope.com/en/log-streaming.html) to configure Netskope to stream Web Transaction logs to your Azure Blob Storage container.<br><br>
5107+
</details>
5108+
5109+
---
5110+
50585111
<a name="netskope-web-transactions-data-connector"></a><details><summary>**Netskope Web Transactions Data Connector**</summary>
50595112

50605113
**Supported by:** [Netskope](https://support.netskope.com/access/)
@@ -5279,12 +5332,12 @@ The Open Systems Logs API Microsoft Sentinel Connector provides the capability t
52795332

52805333
|Table|DCR support|Lake-only ingestion|
52815334
|---|---|---|
5282-
|`OpenSystemsZtnaLogs_CL`|No|No|
5335+
|`OpenSystemsZtnaLogs_CL`|Yes|Yes|
52835336
|`OpenSystemsFirewallLogs_CL`|No|No|
52845337
|`OpenSystemsAuthenticationLogs_CL`|No|No|
52855338
|`OpenSystemsProxyLogs_CL`|No|No|
52865339

5287-
**Data collection rule support:** Not currently supported
5340+
**Data collection rule support:** [Workspace transform DCR](/azure/azure-monitor/logs/tutorial-workspace-transformations-portal)
52885341

52895342
**Prerequisites:**
52905343

@@ -5652,6 +5705,27 @@ Ingest Qscout application events into Microsoft Sentinel
56525705

56535706
---
56545707

5708+
<a name="qualys-knowledge-base-via-codeless-connector-framework"></a><details><summary>**Qualys Knowledge Base (via Codeless Connector Framework)**</summary>
5709+
5710+
**Supported by:** [Microsoft Corporation](https://support.microsoft.com/)
5711+
5712+
Ingest Qualys Knowledge Base Vulnerability Data into Microsoft Sentinel using version 2.0 of the Qualys API.
5713+
5714+
**Log Analytics table(s):**
5715+
5716+
|Table|DCR support|Lake-only ingestion|
5717+
|---|---|---|
5718+
|[`QualysKnowledgeBase`](/azure/azure-monitor/reference/tables/QualysKnowledgeBase)|Yes|Yes|
5719+
5720+
**Data collection rule support:** [Workspace transform DCR](/azure/azure-monitor/logs/tutorial-workspace-transformations-portal)
5721+
5722+
**Prerequisites:**
5723+
5724+
- **Qualys API access**: Requires a Qualys User Account with read access to the Knowledge Base endpoints.<br><br>
5725+
</details>
5726+
5727+
---
5728+
56555729
<a name="qualys-vm-knowledgebase-using-azure-functions"></a><details><summary>**Qualys VM KnowledgeBase (using Azure Functions)**</summary>
56565730

56575731
**Supported by:** [Microsoft Corporation](https://support.microsoft.com/)

articles/sentinel/includes/sentinel-tables-connectors.md

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
author: EdB-MSFT
33
ms.author: edbaynash
44
ms.topic: include
5-
ms.date: 04/06/2026
5+
ms.date: 04/13/2026
66
# This file is auto-generated. Do not edit manually. Changes will be overwritten.
77
---
88

@@ -184,6 +184,7 @@ ms.date: 04/06/2026
184184
|Cymru_Scout_IP_Data_x509_CL|[Team Cymru Scout Data Connector (using Azure Functions)](/azure/sentinel/data-connectors-reference#team-cymru-scout-data-connector-using-azure-functions)|No|No|
185185
|CynerioEvent_CL|[Cynerio Security Events](/azure/sentinel/data-connectors-reference#cynerio-security-events)|No|No|
186186
|Cyren_Indicators_CL|[Cyren Threat Intelligence](/azure/sentinel/data-connectors-reference#cyren-threat-intelligence)|No|No|
187+
|D3SOARIncidents_CL|[D3 Smart SOAR Incidents](/azure/sentinel/data-connectors-reference#d3-smart-soar-incidents)|No|No|
187188
|darktrace_model_alerts_CL|[Darktrace Connector for Microsoft Sentinel REST API](/azure/sentinel/data-connectors-reference#darktrace-connector-for-microsoft-sentinel-rest-api)|Yes|Yes|
188189
|databahn_alerts_CL|[DataBahn](/azure/sentinel/data-connectors-reference#databahn)|No|No|
189190
|databahn_audit_logs_CL|[DataBahn](/azure/sentinel/data-connectors-reference#databahn)|No|No|
@@ -350,6 +351,7 @@ ms.date: 04/06/2026
350351
|net_assets_CL|[Holm Security Asset Data (using Azure Functions)](/azure/sentinel/data-connectors-reference#holm-security-asset-data-using-azure-functions)|No|No|
351352
|Netskope_WebTx_metrics_CL|[Netskope Data Connector](/azure/sentinel/data-connectors-reference#netskope-data-connector)|No|No|
352353
|NetskopeAlerts_CL|[Netskope Alerts and Events](/azure/sentinel/data-connectors-reference#netskope-alerts-and-events)|Yes|Yes|
354+
|NetskopeWebTransactions_CL|[Netskope Web Transaction Connector (via Blob Storage)](/azure/sentinel/data-connectors-reference#netskope-web-transaction-connector-via-blob-storage)|Yes|Yes|
353355
|NetskopeWebtxData_CL|[Netskope Web Transactions Data Connector](/azure/sentinel/data-connectors-reference#netskope-web-transactions-data-connector)|No|No|
354356
|NetskopeWebtxErrors_CL|[Netskope Web Transactions Data Connector](/azure/sentinel/data-connectors-reference#netskope-web-transactions-data-connector)|No|No|
355357
|[NetworkAccessTraffic](/azure/azure-monitor/reference/tables/NetworkAccessTraffic)|[Microsoft Entra ID](/azure/sentinel/data-connectors-reference#microsoft-entra-id)|Yes|Yes|
@@ -371,7 +373,7 @@ ms.date: 04/06/2026
371373
|OpenSystemsAuthenticationLogs_CL|[Open Systems Data Connector](/azure/sentinel/data-connectors-reference#open-systems-data-connector)|No|No|
372374
|OpenSystemsFirewallLogs_CL|[Open Systems Data Connector](/azure/sentinel/data-connectors-reference#open-systems-data-connector)|No|No|
373375
|OpenSystemsProxyLogs_CL|[Open Systems Data Connector](/azure/sentinel/data-connectors-reference#open-systems-data-connector)|No|No|
374-
|OpenSystemsZtnaLogs_CL|[Open Systems Data Connector](/azure/sentinel/data-connectors-reference#open-systems-data-connector)|No|No|
376+
|OpenSystemsZtnaLogs_CL|[Open Systems Data Connector](/azure/sentinel/data-connectors-reference#open-systems-data-connector)|Yes|Yes|
375377
|OracleWebLogicServer_CL|[Custom logs via AMA](/azure/sentinel/data-connectors-reference#custom-logs-via-ama)|Yes|Yes|
376378
|OrcaAlerts_CL|[Orca Security Alerts](/azure/sentinel/data-connectors-reference#orca-security-alerts)|Yes|Yes|
377379
|PaloAltoCortexXDR_Alerts_CL|[Palo Alto Cortex XDR](/azure/sentinel/data-connectors-reference#palo-alto-cortex-xdr)|Yes|Yes|
@@ -400,6 +402,7 @@ ms.date: 04/06/2026
400402
|QscoutAppEvents_CL|[QscoutAppEventsConnector (via Codeless Connector Framework)](/azure/sentinel/data-connectors-reference#qscoutappeventsconnector-via-codeless-connector-framework)|No|No|
401403
|QualysHostDetectionV3_CL|[Qualys Vulnerability Management (via Codeless Connector Framework)](/azure/sentinel/data-connectors-reference#qualys-vulnerability-management-via-codeless-connector-framework)|Yes|Yes|
402404
|QualysKB_CL|[Qualys VM KnowledgeBase (using Azure Functions)](/azure/sentinel/data-connectors-reference#qualys-vm-knowledgebase-using-azure-functions)|Yes|Yes|
405+
|[QualysKnowledgeBase](/azure/azure-monitor/reference/tables/QualysKnowledgeBase)|[Qualys Knowledge Base (via Codeless Connector Framework)](/azure/sentinel/data-connectors-reference#qualys-knowledge-base-via-codeless-connector-framework)|Yes|Yes|
403406
|RadiflowEvent|[Radiflow iSID via AMA](/azure/sentinel/data-connectors-reference#radiflow-isid-via-ama)|No|No|
404407
|RSAIDPlus_AdminLogs_CL|[RSA ID Plus Admin Logs Connector](/azure/sentinel/data-connectors-reference#rsa-id-plus-admin-logs-connector)|No|No|
405408
|Rubrik_Anomaly_Data_CL|[Rubrik Security Cloud data connector (using Azure Functions)](/azure/sentinel/data-connectors-reference#rubrik-security-cloud-data-connector-using-azure-functions)|Yes|Yes|

0 commit comments

Comments
 (0)