This app provides integration with Microsoft Sentinel
Supported Actions
- test connectivity: Validate the asset configuration for connectivity
- on poll: Callback action for the on_poll ingest functionality
- get incident: Gets a given incident
- get incident entities: Gets all entities for an incident
- get incident alerts: Gets all alerts for an incident
- list incidents: Gets all incidents
- update incident: Updates an existing incident
- add incident comment: Creates a new incident comment
- run query: Queries the Sentinel Log Analytics workspace for data using KQL