Skip to content

Commit 56a3c69

Browse files
Merge pull request #249567 from cwatson-cat/sentinel-dc-refresh-8-28-23
Sentinel auto gen data connector refresh (August 2023)
2 parents 6861792 + 83d3e04 commit 56a3c69

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

41 files changed

+907
-518
lines changed

.openpublishing.redirection.sentinel.json

Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -179,6 +179,36 @@
179179
"source_path": "articles/sentinel/store-logs-in-azure-data-explorer.md",
180180
"redirect_url": "/azure/azure-monitor/logs/data-retention-archive",
181181
"redirect_document_id": true
182+
},
183+
{
184+
"source_path": "articles/sentinel/data-connectors/box-using-azure-function.md",
185+
"redirect_url": "/azure/sentinel/data-connectors/box-using-azure-functions",
186+
"redirect_document_id": true
187+
},
188+
{
189+
"source_path": "articles/sentinel/data-connectors/office-365.md",
190+
"redirect_url": "/azure/sentinel/data-connectors/microsoft-365",
191+
"redirect_document_id": true
192+
},
193+
{
194+
"source_path": "articles/sentinel/data-connectors/sophos-endpoint-protection-using-azure-function.md",
195+
"redirect_url": "/azure/sentinel/data-connectors/sophos-endpoint-protection-using-azure-functions",
196+
"redirect_document_id": true
197+
},
198+
{
199+
"source_path": "articles/sentinel/data-connectors/palo-alto-prisma-cloud-cspm-using-azure-function.md",
200+
"redirect_url": "/azure/sentinel/data-connectors/palo-alto-prisma-cloud-cspm-using-azure-functions",
201+
"redirect_document_id": true
202+
},
203+
{
204+
"source_path": "articles/sentinel/data-connectors/proofpoint-tap-using-azure-function.md",
205+
"redirect_url": "/azure/sentinel/data-connectors/proofpoint-tap-using-azure-functions",
206+
"redirect_document_id": true
207+
},
208+
{
209+
"source_path": "articles/sentinel/data-connectors/rubrik-security-cloud-data-connector-using-azure-function.md",
210+
"redirect_url": "/azure/sentinel/data-connectors/rubrik-security-cloud-data-connector-using-azure-functions",
211+
"redirect_document_id": true
182212
}
183213
]
184214
}

articles/sentinel/TOC.yml

Lines changed: 24 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -301,7 +301,7 @@
301301
href: data-connectors/alicloud-using-azure-functions.md
302302
- name: Amazon Web Services
303303
href: data-connectors/amazon-web-services.md
304-
- name: Amazon Web Services S3
304+
- name: Amazon Web Services S3 (preview)
305305
href: data-connectors/amazon-web-services-s3.md
306306
- name: Apache HTTP Server
307307
href: data-connectors/apache-http-server.md
@@ -339,7 +339,7 @@
339339
href: data-connectors/azure-data-lake-storage-gen1.md
340340
- name: Azure DDoS Protection
341341
href: data-connectors/azure-ddos-protection.md
342-
- name: Azure Event Hubs
342+
- name: Azure Event Hub
343343
href: data-connectors/azure-event-hub.md
344344
- name: Azure Firewall
345345
href: data-connectors/azure-firewall.md
@@ -364,7 +364,7 @@
364364
- name: Blackberry CylancePROTECT
365365
href: data-connectors/blackberry-cylanceprotect.md
366366
- name: Box (using Azure Functions)
367-
href: data-connectors/box-using-azure-function.md
367+
href: data-connectors/box-using-azure-functions.md
368368
- name: Broadcom Symantec DLP
369369
href: data-connectors/braodcom-symantec-dlp.md
370370
- name: Cisco Application Centric Infrastructure
@@ -375,7 +375,7 @@
375375
href: data-connectors/cisco-asa-ftd-via-ama.md
376376
- name: Cisco Duo Security (using Azure Functions)
377377
href: data-connectors/cisco-duo-security-using-azure-functions.md
378-
- name: Cisco Firepower eStreamer
378+
- name: Cisco Firepower eStreamer (preview)
379379
href: data-connectors/cisco-firepower-estreamer.md
380380
- name: Cisco Identity Services Engine
381381
href: data-connectors/cisco-identity-services-engine.md
@@ -385,11 +385,13 @@
385385
href: data-connectors/cisco-secure-email-gateway.md
386386
- name: Cisco Secure Endpoint (AMP) (using Azure Functions)
387387
href: data-connectors/cisco-secure-endpoint-amp-using-azure-functions.md
388+
- name: Cisco Software Defined WAN
389+
href: data-connectors/cisco-software-defined-wan.md
388390
- name: Cisco Stealthwatch
389391
href: data-connectors/cisco-stealthwatch.md
390392
- name: Cisco UCS
391393
href: data-connectors/cisco-ucs.md
392-
- name: Cisco Umbrella (using Azure Functions)
394+
- name: Cisco Umbrella (using Azure Function)
393395
href: data-connectors/cisco-umbrella-using-azure-function.md
394396
- name: Cisco Web Security Appliance
395397
href: data-connectors/cisco-web-security-appliance.md
@@ -415,6 +417,8 @@
415417
href: data-connectors/contrast-protect.md
416418
- name: Corelight
417419
href: data-connectors/corelight.md
420+
- name: Cortex XDR - Incidents
421+
href: data-connectors/cortex-xdr-incidents.md
418422
- name: Crowdstrike Falcon Data Replicator (using Azure Functions)
419423
href: data-connectors/crowdstrike-falcon-data-replicator-using-azure-functions.md
420424
- name: CrowdStrike Falcon Endpoint Protection
@@ -549,6 +553,8 @@
549553
href: data-connectors/mcafee-epolicy-orchestrator-epo.md
550554
- name: McAfee Network Security Platform
551555
href: data-connectors/mcafee-network-security-platform.md
556+
- name: Microsoft 365
557+
href: data-connectors/microsoft-365.md
552558
- name: Microsoft 365 Defender
553559
href: data-connectors/microsoft-365-defender.md
554560
- name: Microsoft 365 Insider Risk Management
@@ -563,26 +569,30 @@
563569
href: data-connectors/microsoft-defender-for-identity.md
564570
- name: Microsoft Defender for IoT
565571
href: data-connectors/microsoft-defender-for-iot.md
566-
- name: Microsoft Defender for Office 365
572+
- name: Microsoft Defender for Office 365 (preview)
567573
href: data-connectors/microsoft-defender-for-office-365.md
568574
- name: Microsoft Defender Threat Intelligence
569575
href: data-connectors/microsoft-defender-threat-intelligence.md
570-
- name: Microsoft Power BI
576+
- name: Microsoft Power BI (preview)
571577
href: data-connectors/microsoft-powerbi.md
572-
- name: Microsoft Project
578+
- name: Microsoft Project (preview)
573579
href: data-connectors/microsoft-project.md
574580
- name: Microsoft Purview (Preview)
575581
href: data-connectors/microsoft-purview.md
576582
- name: Microsoft Purview Information Protection
577583
href: data-connectors/microsoft-purview-information-protection.md
578584
- name: Microsoft Sysmon For Linux
579585
href: data-connectors/microsoft-sysmon-for-linux.md
586+
- name: MISP2Sentinel
587+
href: data-connectors/misp2sentinel.md
580588
- name: MongoDB Audit
581589
href: data-connectors/mongodb-audit.md
582590
- name: Morphisec UTPP
583591
href: data-connectors/morphisec-utpp.md
584592
- name: MuleSoft Cloudhub (using Azure Functions)
585593
href: data-connectors/mulesoft-cloudhub-using-azure-functions.md
594+
- name: Nasuni Edge Appliance
595+
href: data-connectors/nasuni-edge-appliance.md
586596
- name: NC Protect
587597
href: data-connectors/nc-protect.md
588598
- name: Netclean ProActive Incidents
@@ -607,8 +617,6 @@
607617
href: data-connectors/nxlog-dns-logs.md
608618
- name: NXLog LinuxAudit
609619
href: data-connectors/nxlog-linuxaudit.md
610-
- name: Office 365
611-
href: data-connectors/office-365.md
612620
- name: Okta Single Sign-On (using Azure Functions)
613621
href: data-connectors/okta-single-sign-on-using-azure-function.md
614622
- name: OneLogin IAM Platform (using Azure Functions)
@@ -630,7 +638,7 @@
630638
- name: Palo Alto Networks Cortex Data Lake (CDL)
631639
href: data-connectors/palo-alto-networks-cortex-data-lake-cdl.md
632640
- name: Palo Alto Prisma Cloud CSPM (using Azure Functions)
633-
href: data-connectors/palo-alto-prisma-cloud-cspm-using-azure-function.md
641+
href: data-connectors/palo-alto-prisma-cloud-cspm-using-azure-functions.md
634642
- name: Perimeter 81 Activity Logs
635643
href: data-connectors/perimeter-81-activity-logs.md
636644
- name: PingFederate
@@ -640,7 +648,7 @@
640648
- name: Proofpoint On Demand Email Security (using Azure Functions)
641649
href: data-connectors/proofpoint-on-demand-email-security-using-azure-functions.md
642650
- name: Proofpoint TAP (using Azure Functions)
643-
href: data-connectors/proofpoint-tap-using-azure-function.md
651+
href: data-connectors/proofpoint-tap-using-azure-functions.md
644652
- name: Pulse Connect Secure
645653
href: data-connectors/pulse-connect-secure.md
646654
- name: Qualys VM KnowledgeBase (using Azure Functions)
@@ -652,7 +660,7 @@
652660
- name: RSA® SecurID (Authentication Manager)
653661
href: data-connectors/rsa-securid-authentication-manager.md
654662
- name: Rubrik Security Cloud data connector (using Azure Functions)
655-
href: data-connectors/rubrik-security-cloud-data-connector-using-azure-function.md
663+
href: data-connectors/rubrik-security-cloud-data-connector-using-azure-functions.md
656664
- name: SailPoint IdentityNow (using Azure Functions)
657665
href: data-connectors/sailpoint-identitynow-using-azure-function.md
658666
- name: Salesforce Service Cloud (using Azure Functions)
@@ -676,7 +684,7 @@
676684
- name: Sophos Cloud Optix
677685
href: data-connectors/sophos-cloud-optix.md
678686
- name: Sophos Endpoint Protection (using Azure Functions)
679-
href: data-connectors/sophos-endpoint-protection-using-azure-function.md
687+
href: data-connectors/sophos-endpoint-protection-using-azure-functions.md
680688
- name: Sophos XG Firewall
681689
href: data-connectors/sophos-xg-firewall.md
682690
- name: Squid Proxy
@@ -719,6 +727,8 @@
719727
href: data-connectors/varmour-application-controller.md
720728
- name: Vectra AI Detect
721729
href: data-connectors/vectra-ai-detect.md
730+
- name: Vectra XDR (using Azure Functions)
731+
href: data-connectors/vectra-xdr-using-azure-functions.md
722732
- name: VMware Carbon Black Cloud (using Azure Functions)
723733
href: data-connectors/vmware-carbon-black-cloud-using-azure-functions.md
724734
- name: VMware ESXi

articles/sentinel/create-custom-connector.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -180,7 +180,7 @@ For examples of this method, see:
180180

181181
- [Connect your VMware Carbon Black Cloud Endpoint Standard to Microsoft Sentinel with Azure Function](./data-connectors/vmware-carbon-black-cloud-using-azure-functions.md)
182182
- [Connect your Okta Single Sign-On to Microsoft Sentinel with Azure Function](./data-connectors/okta-single-sign-on-using-azure-function.md)
183-
- [Connect your Proofpoint TAP to Microsoft Sentinel with Azure Function](./data-connectors/proofpoint-tap-using-azure-function.md)
183+
- [Connect your Proofpoint TAP to Microsoft Sentinel with Azure Function](./data-connectors/proofpoint-tap-using-azure-functions.md)
184184
- [Connect your Qualys VM to Microsoft Sentinel with Azure Function](data-connectors/qualys-vulnerability-management-using-azure-functions.md)
185185
- [Ingesting XML, CSV, or other formats of data](../azure-monitor/logs/create-pipeline-datacollector-api.md#ingesting-xml-csv-or-other-formats-of-data)
186186
- [Monitoring Zoom with Microsoft Sentinel](https://techcommunity.microsoft.com/t5/azure-sentinel/monitoring-zoom-with-azure-sentinel/ba-p/1341516) (blog)

articles/sentinel/data-connectors-reference.md

Lines changed: 18 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ title: Find your Microsoft Sentinel data connector | Microsoft Docs
33
description: Learn about specific configuration steps for Microsoft Sentinel data connectors.
44
author: cwatson-cat
55
ms.topic: reference
6-
ms.date: 07/26/2023
6+
ms.date: 08/28/2023
77
ms.author: cwatson
88
---
99

@@ -108,7 +108,7 @@ Data connectors are available as part of the following offerings:
108108

109109
## Box
110110

111-
- [Box (using Azure Function)](data-connectors/box-using-azure-function.md)
111+
- [Box (using Azure Functions)](data-connectors/box-using-azure-functions.md)
112112

113113
## Broadcom
114114

@@ -132,6 +132,7 @@ Data connectors are available as part of the following offerings:
132132
## Cisco Systems, Inc.
133133

134134
- [Cisco Firepower eStreamer](data-connectors/cisco-firepower-estreamer.md)
135+
- [Cisco Software Defined WAN](data-connectors/cisco-software-defined-wan.md)
135136

136137
## Citrix
137138

@@ -197,6 +198,10 @@ Data connectors are available as part of the following offerings:
197198
- [AI Analyst Darktrace](data-connectors/ai-analyst-darktrace.md)
198199
- [Darktrace Connector for Microsoft Sentinel REST API](data-connectors/darktrace-connector-for-microsoft-sentinel-rest-api.md)
199200

201+
## Defend Limited
202+
203+
- [Cortex XDR - Incidents](data-connectors/cortex-xdr-incidents.md)
204+
200205
## Delinea Inc.
201206

202207
- [Delinea Secret Server](data-connectors/delinea-secret-server.md)
@@ -372,6 +377,7 @@ Data connectors are available as part of the following offerings:
372377
- [Common Event Format (CEF) via AMA](data-connectors/common-event-format-cef-via-ama.md)
373378
- [DNS](data-connectors/dns.md)
374379
- [Fortinet FortiWeb Web Application Firewall](data-connectors/fortinet-fortiweb-web-application-firewall.md)
380+
- [Microsoft 365 (formerly, Office 365)](data-connectors/microsoft-365.md)
375381
- [Microsoft 365 Defender](data-connectors/microsoft-365-defender.md)
376382
- [Microsoft 365 Insider Risk Management](data-connectors/microsoft-365-insider-risk-management.md)
377383
- [Microsoft Defender for Cloud](data-connectors/microsoft-defender-for-cloud.md)
@@ -386,7 +392,6 @@ Data connectors are available as part of the following offerings:
386392
- [Microsoft Purview (Preview)](data-connectors/microsoft-purview.md)
387393
- [Microsoft Purview Information Protection](data-connectors/microsoft-purview-information-protection.md)
388394
- [Network Security Groups](data-connectors/network-security-groups.md)
389-
- [Office 365](data-connectors/office-365.md)
390395
- [Security Events via Legacy Agent](data-connectors/security-events-via-legacy-agent.md)
391396
- [Syslog](data-connectors/syslog.md)
392397
- [Threat intelligence - TAXII](data-connectors/threat-intelligence-taxii.md)
@@ -414,6 +419,7 @@ Data connectors are available as part of the following offerings:
414419
- [Forcepoint CSG](data-connectors/forcepoint-csg.md)
415420
- [Forcepoint DLP](data-connectors/forcepoint-dlp.md)
416421
- [Forcepoint NGFW](data-connectors/forcepoint-ngfw.md)
422+
- [MISP2Sentinel](data-connectors/misp2sentinel.md)
417423

418424
## MongoDB
419425

@@ -427,6 +433,10 @@ Data connectors are available as part of the following offerings:
427433

428434
- [MuleSoft Cloudhub (using Azure Functions)](data-connectors/mulesoft-cloudhub-using-azure-functions.md)
429435

436+
## Nasuni Corporation
437+
438+
- [Nasuni Edge Appliance](data-connectors/nasuni-edge-appliance.md)
439+
430440
## NetClean Technologies AB
431441

432442
- [Netclean ProActive Incidents](data-connectors/netclean-proactive-incidents.md)
@@ -488,7 +498,7 @@ Data connectors are available as part of the following offerings:
488498

489499
- [Palo Alto Networks (Firewall)](data-connectors/palo-alto-networks-firewall.md)
490500
- [Palo Alto Networks Cortex Data Lake (CDL)](data-connectors/palo-alto-networks-cortex-data-lake-cdl.md)
491-
- [Palo Alto Prisma Cloud CSPM (using Azure Functions)](data-connectors/palo-alto-prisma-cloud-cspm-using-azure-function.md)
501+
- [Palo Alto Prisma Cloud CSPM (using Azure Functions)](data-connectors/palo-alto-prisma-cloud-cspm-using-azure-functions.md)
492502

493503
## Perimeter 81
494504

@@ -505,7 +515,7 @@ Data connectors are available as part of the following offerings:
505515
## Proofpoint
506516

507517
- [Proofpoint On Demand Email Security (using Azure Functions)](data-connectors/proofpoint-on-demand-email-security-using-azure-functions.md)
508-
- [Proofpoint TAP (using Azure Functions)](data-connectors/proofpoint-tap-using-azure-function.md)
518+
- [Proofpoint TAP (using Azure Functions)](data-connectors/proofpoint-tap-using-azure-functions.md)
509519

510520
## Pulse Secure
511521

@@ -526,7 +536,7 @@ Data connectors are available as part of the following offerings:
526536

527537
## Rubrik, Inc.
528538

529-
- [Rubrik Security Cloud data connector (using Azure Functions)](data-connectors/rubrik-security-cloud-data-connector-using-azure-function.md)
539+
- [Rubrik Security Cloud data connector (using Azure Functions)](data-connectors/rubrik-security-cloud-data-connector-using-azure-functions.md)
530540

531541
## SailPoint
532542

@@ -571,7 +581,7 @@ Data connectors are available as part of the following offerings:
571581
## Sophos
572582

573583
- [Sophos Cloud Optix](data-connectors/sophos-cloud-optix.md)
574-
- [Sophos Endpoint Protection (using Azure Functions)](data-connectors/sophos-endpoint-protection-using-azure-function.md)
584+
- [Sophos Endpoint Protection (using Azure Functions)](data-connectors/sophos-endpoint-protection-using-azure-functions.md)
575585
- [Sophos XG Firewall](data-connectors/sophos-xg-firewall.md)
576586

577587
## Squid
@@ -627,6 +637,7 @@ Data connectors are available as part of the following offerings:
627637

628638
- [AI Vectra Stream](data-connectors/ai-vectra-stream.md)
629639
- [Vectra AI Detect](data-connectors/vectra-ai-detect.md)
640+
- [Vectra XDR (using Azure Functions)](data-connectors/vectra-xdr-using-azure-functions.md)
630641

631642
## VMware
632643

articles/sentinel/data-connectors/amazon-web-services-s3.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
---
2-
title: "Amazon Web Services S3 connector for Microsoft Sentinel"
2+
title: "Amazon Web Services S3 connector for Microsoft Sentinel (preview)"
33
description: "Learn how to install the connector Amazon Web Services S3 to connect your data source to Microsoft Sentinel."
44
author: cwatson-cat
55
ms.topic: how-to
@@ -8,7 +8,7 @@ ms.service: microsoft-sentinel
88
ms.author: cwatson
99
---
1010

11-
# Amazon Web Services S3 connector for Microsoft Sentinel
11+
# Amazon Web Services S3 connector for Microsoft Sentinel (preview)
1212

1313
This connector allows you to ingest AWS service logs, collected in AWS S3 buckets, to Microsoft Sentinel. The currently supported data types are:
1414
* AWS CloudTrail

0 commit comments

Comments
 (0)