Skip to content

Commit c0ba909

Browse files
committed
[AUTOGEN] PR for Sentinel connectors
1 parent ef3e4f3 commit c0ba909

2 files changed

Lines changed: 96 additions & 60 deletions

File tree

articles/sentinel/includes/connector-details.md

Lines changed: 86 additions & 42 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
author: EdB-MSFT
33
ms.author: edbaynash
44
ms.topic: include
5-
ms.date: 03/30/2026
5+
ms.date: 04/06/2026
66

77
# This file is auto-generated. Do not edit manually. Changes will be overwritten.
88
---
@@ -58,6 +58,23 @@ This solution depends on the following technologies, and some of which may be in
5858

5959
---
6060

61+
<a name="a365-observability"></a><details><summary>**A365 Observability**</summary>
62+
63+
**Supported by:** [Microsoft Corporation](https://support.microsoft.com/)
64+
65+
A365 Observability data connector gives richer insights into AI agent activity by bringing AI agent telemetry from A365, AI Foundry, and Copilot in the Microsoft Sentinel data lake to investigate agent behavior, tool usage, and execution with hunting, graph, and MCP workflows. Data from this connector is used to investigate AI agent behavior, tool usage, and execution in Microsoft Sentinel. If you have enabled these workflows, deactivating this connector will prevent those investigations from being performed.
66+
67+
**Log Analytics table(s):**
68+
69+
|Table|DCR support|Lake-only ingestion|
70+
|---|---|---|
71+
72+
73+
**Data collection rule support:** Not currently supported<br><br>
74+
</details>
75+
76+
---
77+
6178
<a name="abnormalsecurity-using-azure-function"></a><details><summary>**AbnormalSecurity (using Azure Function)**</summary>
6279

6380
**Supported by:** [Abnormal Security](https://abnormalsecurity.com/contact)
@@ -123,6 +140,27 @@ The [Alibaba Cloud ActionTrail](https://www.alibabacloud.com/product/actiontrail
123140

124141
---
125142

143+
<a name="alibaba-cloud-networking-data-connector-via-codeless-connector-framework"></a><details><summary>**Alibaba Cloud Networking Data Connector (via Codeless Connector Framework)**</summary>
144+
145+
**Supported by:** [Microsoft Corporation](https://support.microsoft.com/)
146+
147+
The Alibaba Cloud Networking data connector provides the capability to ingest [Alibaba Cloud](https://www.alibabacloud.com/) networking data into Microsoft Sentinel through the Simple Log Service (SLS) REST API. Refer to [API documentation](https://www.alibabacloud.com/help/en/sls/developer-reference/api-sls-2020-12-30-endpoint) for more information. The connector provides the ability to get VPC Flow Logs, WAF Logs, and API Gateway Logs from Alibaba Cloud.
148+
149+
**Log Analytics table(s):**
150+
151+
|Table|DCR support|Lake-only ingestion|
152+
|---|---|---|
153+
|`AlibabaCloudVPCFlowLogs`|No|No|
154+
155+
**Data collection rule support:** Not currently supported
156+
157+
**Prerequisites:**
158+
159+
- **Alibaba Cloud SLS API access**: **Alibaba Cloud Simple Log Service** access is required for the SLS API.<br><br>
160+
</details>
161+
162+
---
163+
126164
<a name="alicloud-using-azure-functions"></a><details><summary>**AliCloud (using Azure Functions)**</summary>
127165

128166
**Supported by:** [Microsoft Corporation](https://support.microsoft.com/)
@@ -179,6 +217,27 @@ This data connector enables the integration of AWS CloudFront logs with Microsof
179217

180218
---
181219

220+
<a name="amazon-web-services-elastic-load-balancing-via-codeless-connector-framework"></a><details><summary>**Amazon Web Services Elastic Load Balancing (via Codeless Connector Framework)**</summary>
221+
222+
**Supported by:** [Microsoft Corporation](https://support.microsoft.com/)
223+
224+
The AWS Elastic Load Balancing (ELB) connector for Microsoft Sentinel allows you to ingest access logs and flow logs from AWS Application Load Balancers (ALB), Network Load Balancers (NLB), and Gateway Load Balancers (GLB) into Microsoft Sentinel. These logs provide detailed information about requests processed by your load balancers and VPC traffic flows, enabling security monitoring, threat detection, and traffic analysis.
225+
226+
**Log Analytics table(s):**
227+
228+
|Table|DCR support|Lake-only ingestion|
229+
|---|---|---|
230+
|`AWSALBAccessLogsData`|No|No|
231+
232+
**Data collection rule support:** Not currently supported
233+
234+
**Prerequisites:**
235+
236+
- **AWS IAM Role ARN and SQS Queue**: An **AWS IAM Role ARN** with cross-account access and an **SQS Queue URL** configured for S3 event notifications are required. See [AWS ELB connector documentation](/azure/sentinel/connect-aws) for setup instructions.<br><br>
237+
</details>
238+
239+
---
240+
182241
<a name="amazon-web-services-networkfirewall-via-codeless-connector-framework"></a><details><summary>**Amazon Web Services NetworkFirewall (via Codeless Connector Framework)**</summary>
183242

184243
**Supported by:** [Microsoft Corporation](https://support.microsoft.com/)
@@ -965,38 +1024,6 @@ The [Bitglass](https://www.forcepoint.com/bitglass) data connector provides the
9651024

9661025
---
9671026

968-
<a name="bitsight-data-connector-using-azure-functions"></a><details><summary>**Bitsight data connector (using Azure Functions)**</summary>
969-
970-
**Supported by:** [BitSight Support](https://help.bitsight.com/)
971-
972-
The [BitSight](https://www.BitSight.com/) Data Connector supports evidence-based cyber risk monitoring by bringing BitSight data in Microsoft Sentinel.
973-
974-
**Log Analytics table(s):**
975-
976-
|Table|DCR support|Lake-only ingestion|
977-
|---|---|---|
978-
|`BitsightAlerts_data_CL`|Yes|Yes|
979-
|`BitsightBreaches_data_CL`|Yes|Yes|
980-
|`BitsightCompany_details_CL`|Yes|Yes|
981-
|`BitsightCompany_rating_details_CL`|Yes|Yes|
982-
|`BitsightDiligence_historical_statistics_CL`|Yes|Yes|
983-
|`BitsightDiligence_statistics_CL`|Yes|Yes|
984-
|`BitsightFindings_data_CL`|Yes|Yes|
985-
|`BitsightFindings_summary_CL`|Yes|Yes|
986-
|`BitsightGraph_data_CL`|Yes|Yes|
987-
|`BitsightIndustrial_statistics_CL`|Yes|Yes|
988-
|`BitsightObservation_statistics_CL`|Yes|Yes|
989-
990-
**Data collection rule support:** [Workspace transform DCR](/azure/azure-monitor/logs/tutorial-workspace-transformations-portal)
991-
992-
**Prerequisites:**
993-
994-
- **Microsoft.Web/sites permissions**: Read and write permissions to Azure Functions to create a Function App is required. For more information, see [Azure Functions](/azure/azure-functions/).
995-
- **REST API Credentials/permissions**: BitSight API Token is required. See the documentation to [learn more](https://help.bitsighttech.com/hc/en-us/articles/115014888388-API-Token-Management) about API Token.<br><br>
996-
</details>
997-
998-
---
999-
10001027
<a name="bitwarden-event-logs"></a><details><summary>**Bitwarden Event Logs**</summary>
10011028

10021029
**Supported by:** [Bitwarden Inc](https://bitwarden.com/contact/)
@@ -3213,6 +3240,23 @@ The [Imperva Cloud WAF](https://www.imperva.com/resources/resource-library/datas
32133240

32143241
---
32153242

3243+
<a name="imperva-cloud-waf-via-codeless-connector-framework"></a><details><summary>**Imperva Cloud WAF (via Codeless Connector Framework)**</summary>
3244+
3245+
**Supported by:** [Microsoft Corporation](https://support.microsoft.com/)
3246+
3247+
The Imperva WAF Cloud data connector provides the capability to ingest logs into Microsoft Sentinel using the Imperva Log Integration via AWS S3 with SQS notifications. The connector parses CEF-formatted WAF events including access logs and security alerts for threat detection and investigation.Refer to [Imperva WAF Cloud Log Integration](https://docs.imperva.com/bundle/cloud-application-security/page/settings/log-integration.htm) for more information.
3248+
3249+
**Log Analytics table(s):**
3250+
3251+
|Table|DCR support|Lake-only ingestion|
3252+
|---|---|---|
3253+
|`ImpervaWAFCloud`|No|No|
3254+
3255+
**Data collection rule support:** Not currently supported<br><br>
3256+
</details>
3257+
3258+
---
3259+
32163260
<a name="infoblox-cloud-data-connector-via-ama"></a><details><summary>**Infoblox Cloud Data Connector via AMA**</summary>
32173261

32183262
**Supported by:** [Infoblox](https://support.infoblox.com/)
@@ -4072,7 +4116,7 @@ These alerts can be imported into Microsoft Sentinel with this connector, allowi
40724116

40734117
**Supported by:** [Microsoft](https://support.microsoft.com/)
40744118

4075-
The Microsoft Copilot logs connector in Microsoft Sentinel enables the seamless ingestion of Copilot-generated activity logs into Microsoft Sentinel for advanced threat detection, investigation, and response. It collects telemetry from Microsoft Copilot services - such as usage data, prompts and system responses - and ingests into Microsoft Sentinel, allowing security teams to monitor for misuse, detect anomalies, and maintain compliance with organizational policies.
4119+
The Microsoft Copilot logs connector in Microsoft Sentinel enables seamless ingestion of Copilot-generated activity logs from M365 Copilot and Security Copilot into Microsoft Sentinel for advanced threat detection, investigation and response. It collects telemetry from Microsoft Copilot services such as usage data and system responses and ingests into Microsoft Sentinel, allowing security teams to monitor for misuse, detect anomalies, and maintain compliance with organizational policies.
40764120

40774121
**Log Analytics table(s):**
40784122

@@ -6572,7 +6616,7 @@ The [Varonis Purview](https://www.varonis.com/) connector provides the capabilit
65726616

65736617
|Table|DCR support|Lake-only ingestion|
65746618
|---|---|---|
6575-
|`varonisresources_CL`|No|No|
6619+
|`VaronisResources_CL`|No|No|
65766620

65776621
**Data collection rule support:** Not currently supported
65786622

@@ -7071,12 +7115,12 @@ The [Zero Networks Segment](https://zeronetworks.com/) push connector allows Zer
70717115

70727116
|Table|DCR support|Lake-only ingestion|
70737117
|---|---|---|
7074-
|`ZNAudit_CL`|No|No|
7075-
|`ZNNetworkActivity_CL`|No|No|
7076-
|`ZNIdentityActivity_CL`|No|No|
7077-
|`ZNRPCActivity_CL`|No|No|
7118+
|`ZNAudit_CL`|Yes|Yes|
7119+
|`ZNNetworkActivity_CL`|Yes|Yes|
7120+
|`ZNIdentityActivity_CL`|Yes|Yes|
7121+
|`ZNRPCActivity_CL`|Yes|Yes|
70787122

7079-
**Data collection rule support:** Not currently supported
7123+
**Data collection rule support:** [Workspace transform DCR](/azure/azure-monitor/logs/tutorial-workspace-transformations-portal)
70807124

70817125
**Prerequisites:**
70827126

@@ -7096,9 +7140,9 @@ The [Zero Networks Segment](https://zeronetworks.com/) Audit data connector prov
70967140

70977141
|Table|DCR support|Lake-only ingestion|
70987142
|---|---|---|
7099-
|`ZNSegmentAuditNativePoller_CL`|No|No|
7143+
|`ZNSegmentAuditNativePoller_CL`|Yes|Yes|
71007144

7101-
**Data collection rule support:** Not currently supported
7145+
**Data collection rule support:** [Workspace transform DCR](/azure/azure-monitor/logs/tutorial-workspace-transformations-portal)
71027146

71037147
**Prerequisites:**
71047148

articles/sentinel/includes/sentinel-tables-connectors.md

Lines changed: 10 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
author: EdB-MSFT
33
ms.author: edbaynash
44
ms.topic: include
5-
ms.date: 03/30/2026
5+
ms.date: 04/06/2026
66
# This file is auto-generated. Do not edit manually. Changes will be overwritten.
77
---
88

@@ -35,6 +35,7 @@ ms.date: 03/30/2026
3535
|alertsremediationdata_CL|[Netskope Data Connector](/azure/sentinel/data-connectors-reference#netskope-data-connector)|No|No|
3636
|alertssecurityassessmentdata_CL|[Netskope Data Connector](/azure/sentinel/data-connectors-reference#netskope-data-connector)|No|No|
3737
|alertsubadata_CL|[Netskope Data Connector](/azure/sentinel/data-connectors-reference#netskope-data-connector)|No|No|
38+
|AlibabaCloudVPCFlowLogs|[Alibaba Cloud Networking Data Connector (via Codeless Connector Framework)](/azure/sentinel/data-connectors-reference#alibaba-cloud-networking-data-connector-via-codeless-connector-framework)|No|No|
3839
|AliCloud_CL|[AliCloud (using Azure Functions)](/azure/sentinel/data-connectors-reference#alicloud-using-azure-functions)|No|No|
3940
|AliCloudActionTrailLogs_CL|[Alibaba Cloud ActionTrail (via Codeless Connector Framework)](/azure/sentinel/data-connectors-reference#alibaba-cloud-actiontrail-via-codeless-connector-framework)|Yes|Yes|
4041
|Anvilogic_Alerts_CL|[Anvilogic](/azure/sentinel/data-connectors-reference#anvilogic)|No|No|
@@ -57,6 +58,7 @@ ms.date: 03/30/2026
5758
|Awareness_SafeScore_Details_CL|[Mimecast Awareness Training](/azure/sentinel/data-connectors-reference#mimecast-awareness-training)|Yes|Yes|
5859
|Awareness_User_Data_CL|[Mimecast Awareness Training](/azure/sentinel/data-connectors-reference#mimecast-awareness-training)|Yes|Yes|
5960
|Awareness_Watchlist_Details_CL|[Mimecast Awareness Training](/azure/sentinel/data-connectors-reference#mimecast-awareness-training)|Yes|Yes|
61+
|AWSALBAccessLogsData|[Amazon Web Services Elastic Load Balancing (via Codeless Connector Framework)](/azure/sentinel/data-connectors-reference#amazon-web-services-elastic-load-balancing-via-codeless-connector-framework)|No|No|
6062
|AWSCloudFront_AccessLog_CL|[Amazon Web Services CloudFront (via Codeless Connector Framework) (Preview)](/azure/sentinel/data-connectors-reference#amazon-web-services-cloudfront-via-codeless-connector-framework-preview)|Yes|Yes|
6163
|[AWSCloudTrail](/azure/azure-monitor/reference/tables/AWSCloudTrail)|[Amazon Web Services S3](/azure/sentinel/data-connectors-reference#amazon-web-services-s3)<br>[Amazon Web Services](/azure/sentinel/data-connectors-reference#amazon-web-services)|Yes|Yes|
6264
|[AWSCloudWatch](/azure/azure-monitor/reference/tables/AWSCloudWatch)|[Amazon Web Services S3](/azure/sentinel/data-connectors-reference#amazon-web-services-s3)|Yes|Yes|
@@ -88,17 +90,6 @@ ms.date: 03/30/2026
8890
|BeyondTrustPM_ClientEvents_CL|[BeyondTrust PM Cloud](/azure/sentinel/data-connectors-reference#beyondtrust-pm-cloud)|Yes|Yes|
8991
|BigIDDSPMCatalog_CL|[BigID DSPM connector](/azure/sentinel/data-connectors-reference#bigid-dspm-connector)|Yes|Yes|
9092
|BitglassLogs_CL|[Bitglass (using Azure Functions)](/azure/sentinel/data-connectors-reference#bitglass-using-azure-functions)|No|No|
91-
|BitsightAlerts_data_CL|[Bitsight data connector (using Azure Functions)](/azure/sentinel/data-connectors-reference#bitsight-data-connector-using-azure-functions)|Yes|Yes|
92-
|BitsightBreaches_data_CL|[Bitsight data connector (using Azure Functions)](/azure/sentinel/data-connectors-reference#bitsight-data-connector-using-azure-functions)|Yes|Yes|
93-
|BitsightCompany_details_CL|[Bitsight data connector (using Azure Functions)](/azure/sentinel/data-connectors-reference#bitsight-data-connector-using-azure-functions)|Yes|Yes|
94-
|BitsightCompany_rating_details_CL|[Bitsight data connector (using Azure Functions)](/azure/sentinel/data-connectors-reference#bitsight-data-connector-using-azure-functions)|Yes|Yes|
95-
|BitsightDiligence_historical_statistics_CL|[Bitsight data connector (using Azure Functions)](/azure/sentinel/data-connectors-reference#bitsight-data-connector-using-azure-functions)|Yes|Yes|
96-
|BitsightDiligence_statistics_CL|[Bitsight data connector (using Azure Functions)](/azure/sentinel/data-connectors-reference#bitsight-data-connector-using-azure-functions)|Yes|Yes|
97-
|BitsightFindings_data_CL|[Bitsight data connector (using Azure Functions)](/azure/sentinel/data-connectors-reference#bitsight-data-connector-using-azure-functions)|Yes|Yes|
98-
|BitsightFindings_summary_CL|[Bitsight data connector (using Azure Functions)](/azure/sentinel/data-connectors-reference#bitsight-data-connector-using-azure-functions)|Yes|Yes|
99-
|BitsightGraph_data_CL|[Bitsight data connector (using Azure Functions)](/azure/sentinel/data-connectors-reference#bitsight-data-connector-using-azure-functions)|Yes|Yes|
100-
|BitsightIndustrial_statistics_CL|[Bitsight data connector (using Azure Functions)](/azure/sentinel/data-connectors-reference#bitsight-data-connector-using-azure-functions)|Yes|Yes|
101-
|BitsightObservation_statistics_CL|[Bitsight data connector (using Azure Functions)](/azure/sentinel/data-connectors-reference#bitsight-data-connector-using-azure-functions)|Yes|Yes|
10293
|BitwardenEventLogs|[Bitwarden Event Logs](/azure/sentinel/data-connectors-reference#bitwarden-event-logs)|No|No|
10394
|BoxEvents_CL|[Box (using Azure Functions)](/azure/sentinel/data-connectors-reference#box-using-azure-functions)|No|No|
10495
|BoxEventsV2_CL|[Box Events (CCP)](/azure/sentinel/data-connectors-reference#box-events-ccp)|Yes|Yes|
@@ -294,6 +285,7 @@ ms.date: 03/30/2026
294285
|Illumio_Flow_Events_CL|[Illumio SaaS (using Azure Functions)](/azure/sentinel/data-connectors-reference#illumio-saas-using-azure-functions)|Yes|Yes|
295286
|IllumioInsightsSummary_CL|[Illumio Insights Summary](/azure/sentinel/data-connectors-reference#illumio-insights-summary)|No|No|
296287
|[IlumioInsights](/azure/azure-monitor/reference/tables/IlumioInsights)|[Illumio Insights](/azure/sentinel/data-connectors-reference#illumio-insights)|Yes|Yes|
288+
|ImpervaWAFCloud|[Imperva Cloud WAF (via Codeless Connector Framework)](/azure/sentinel/data-connectors-reference#imperva-cloud-waf-via-codeless-connector-framework)|No|No|
297289
|ImpervaWAFCloud_CL|[Imperva Cloud WAF (using Azure Functions)](/azure/sentinel/data-connectors-reference#imperva-cloud-waf-using-azure-functions)|Yes|Yes|
298290
|Infoblox_Failed_Indicators_CL|[Infoblox Data Connector via REST API](/azure/sentinel/data-connectors-reference#infoblox-data-connector-via-rest-api)|No|No|
299291
|InfobloxInsight_CL|[Infoblox SOC Insight Data Connector via REST API](/azure/sentinel/data-connectors-reference#infoblox-soc-insight-data-connector-via-rest-api)|No|No|
@@ -487,7 +479,7 @@ ms.date: 03/30/2026
487479
|union isfuzzy=true (WizVulnerabilities_CL),(WizVulnerabilitiesV2_CL)|[Wiz (using Azure Functions)](/azure/sentinel/data-connectors-reference#wiz-using-azure-functions)|No|No|
488480
|ValenceAlert_CL|[SaaS Security](/azure/sentinel/data-connectors-reference#saas-security)|No|No|
489481
|VaronisAlerts_CL|[Varonis SaaS](/azure/sentinel/data-connectors-reference#varonis-saas)|No|No|
490-
|varonisresources_CL|[Varonis Purview Push Connector](/azure/sentinel/data-connectors-reference#varonis-purview-push-connector)|No|No|
482+
|VaronisResources_CL|[Varonis Purview Push Connector](/azure/sentinel/data-connectors-reference#varonis-purview-push-connector)|No|No|
491483
|vcenter_CL|[Custom logs via AMA](/azure/sentinel/data-connectors-reference#custom-logs-via-ama)|Yes|Yes|
492484
|VectraStream_CL|[Custom logs via AMA](/azure/sentinel/data-connectors-reference#custom-logs-via-ama)|No|No|
493485
|VeeamAuthorizationEvents_CL|[Veeam Data Connector (using Azure Functions)](/azure/sentinel/data-connectors-reference#veeam-data-connector-using-azure-functions)|Yes|Yes|
@@ -528,11 +520,11 @@ ms.date: 03/30/2026
528520
|ZeroFox_CTI_vulnerabilities_CL|[ZeroFox CTI](/azure/sentinel/data-connectors-reference#zerofox-cti)|No|No|
529521
|ZeroFoxAlertPoller_CL|[ZeroFox Enterprise - Alerts (Polling CCF)](/azure/sentinel/data-connectors-reference#zerofox-enterprise---alerts-polling-ccf)|Yes|Yes|
530522
|ZimperiumThreatLog_CL|[Zimperium Mobile Threat Defense](/azure/sentinel/data-connectors-reference#zimperium-mobile-threat-defense)|No|No|
531-
|ZNAudit_CL|[Zero Networks Segment (Push)](/azure/sentinel/data-connectors-reference#zero-networks-segment-push)|No|No|
532-
|ZNIdentityActivity_CL|[Zero Networks Segment (Push)](/azure/sentinel/data-connectors-reference#zero-networks-segment-push)|No|No|
533-
|ZNNetworkActivity_CL|[Zero Networks Segment (Push)](/azure/sentinel/data-connectors-reference#zero-networks-segment-push)|No|No|
534-
|ZNRPCActivity_CL|[Zero Networks Segment (Push)](/azure/sentinel/data-connectors-reference#zero-networks-segment-push)|No|No|
535-
|ZNSegmentAuditNativePoller_CL|[Zero Networks Segment Audit](/azure/sentinel/data-connectors-reference#zero-networks-segment-audit)|No|No|
523+
|ZNAudit_CL|[Zero Networks Segment (Push)](/azure/sentinel/data-connectors-reference#zero-networks-segment-push)|Yes|Yes|
524+
|ZNIdentityActivity_CL|[Zero Networks Segment (Push)](/azure/sentinel/data-connectors-reference#zero-networks-segment-push)|Yes|Yes|
525+
|ZNNetworkActivity_CL|[Zero Networks Segment (Push)](/azure/sentinel/data-connectors-reference#zero-networks-segment-push)|Yes|Yes|
526+
|ZNRPCActivity_CL|[Zero Networks Segment (Push)](/azure/sentinel/data-connectors-reference#zero-networks-segment-push)|Yes|Yes|
527+
|ZNSegmentAuditNativePoller_CL|[Zero Networks Segment Audit](/azure/sentinel/data-connectors-reference#zero-networks-segment-audit)|Yes|Yes|
536528
|Zoom_CL|[Zoom Reports (using Azure Functions)](/azure/sentinel/data-connectors-reference#zoom-reports-using-azure-functions)|Yes|Yes|
537529
|ZoomV2_CL|[Zoom Reports Connector (via Codeless Connector Framework)](/azure/sentinel/data-connectors-reference#zoom-reports-connector-via-codeless-connector-framework)|No|No|
538530
|ZPA_CL|[Custom logs via AMA](/azure/sentinel/data-connectors-reference#custom-logs-via-ama)|Yes|Yes|

0 commit comments

Comments
 (0)