0

Microsoft Sentinel Integration

I built a Microsoft Sentinel integration using a Codeless Connector Framework (CCF) connector, so there is no need for extra infrastructure such as a Function App or Logic App.

This connector supports multiple profiles, which can be defined as an array in the deployment template. That means a single connector can ingest data for multiple profiles.

 

 

In addition, I included several analytics rules for NextDNS, along with a parser aligned to the Microsoft ASIM DNS schema to return normalized DNS information.

 

 

If useful, I can also share a short deployment walkthrough and sample template structure for anyone who wants to test it quickly.

Reply

null

Content aside

  • yesterdayLast active
  • 22Views
  • 1 Following