<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Microsoft Azure Sentinel integration with Splunk? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Azure-Sentinel-integration-with-Splunk/m-p/470613#M57822</link>
    <description>&lt;P&gt;Does anyone know if there is a way to integrate Microsoft Azure Sentinel with Splunk? &lt;/P&gt;

&lt;P&gt;I'm specifically looking for events of interest/alerts/indicators from Sentinel into Splunk. &lt;/P&gt;

&lt;P&gt;It appears that the Microsoft Azure Add-on for Splunk provides access to many aspects of Azure including Security Center but I don't see anything specifically for Sentinel. Presumably Sentinel would take these various feeds and apply the Microsoft secret sauce to them to provide insight. Rather than having to reverse-engineer or build new in Splunk it would be good if there was a way to integrate the curated information from Sentinel into Splunk.&lt;/P&gt;

&lt;P&gt;I can't seem to find any information on a Sentinel API. There are data connectors to get data into Sentinel but I can't seem to find anything on getting data out.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Feb 2020 19:08:49 GMT</pubDate>
    <dc:creator>isfleming</dc:creator>
    <dc:date>2020-02-11T19:08:49Z</dc:date>
    <item>
      <title>Microsoft Azure Sentinel integration with Splunk?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Azure-Sentinel-integration-with-Splunk/m-p/470613#M57822</link>
      <description>&lt;P&gt;Does anyone know if there is a way to integrate Microsoft Azure Sentinel with Splunk? &lt;/P&gt;

&lt;P&gt;I'm specifically looking for events of interest/alerts/indicators from Sentinel into Splunk. &lt;/P&gt;

&lt;P&gt;It appears that the Microsoft Azure Add-on for Splunk provides access to many aspects of Azure including Security Center but I don't see anything specifically for Sentinel. Presumably Sentinel would take these various feeds and apply the Microsoft secret sauce to them to provide insight. Rather than having to reverse-engineer or build new in Splunk it would be good if there was a way to integrate the curated information from Sentinel into Splunk.&lt;/P&gt;

&lt;P&gt;I can't seem to find any information on a Sentinel API. There are data connectors to get data into Sentinel but I can't seem to find anything on getting data out.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 19:08:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Azure-Sentinel-integration-with-Splunk/m-p/470613#M57822</guid>
      <dc:creator>isfleming</dc:creator>
      <dc:date>2020-02-11T19:08:49Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Azure Sentinel integration with Splunk?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Azure-Sentinel-integration-with-Splunk/m-p/470614#M57823</link>
      <description>&lt;P&gt;The Microsoft Graph Security API Add-On for Splunk can get these events.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/4564/"&gt;https://splunkbase.splunk.com/app/4564/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 19:24:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Azure-Sentinel-integration-with-Splunk/m-p/470614#M57823</guid>
      <dc:creator>jconger</dc:creator>
      <dc:date>2020-02-11T19:24:11Z</dc:date>
    </item>
  </channel>
</rss>

