Microsoft Sentinel (v1.6.10)

Microsoft Sentinel is a cloud-native security information and event manager (SIEM) platform that uses built-in AI to help analyze large volumes of data across an enterprise.

Author
Cortex XSOAR
Support
xsoar
URL
https://www.paloaltonetworks.com/cortex
Categories
Analytics & SIEM

Incident fields (10)

Integrations (1)

Layouts (1)

Scripts (6)

README

Important Notice – Microsoft Sentinel Migration to Microsoft Defender Portal

Microsoft is migrating Microsoft Sentinel from the Azure portal to the Microsoft Defender portal:

  • From July 2025 – New customers have automatically been onboarded and redirected to the Defender portal.
  • Starting March 2027 – All customers using Microsoft Sentinel in the Azure portal will be redirected to the Defender portal.

This integration is not being deprecated at this time, as not all commands are supported in the Graph API. However, if you currently use Microsoft Sentinel in the Azure portal, Microsoft recommends planning your transition to the Defender portal now.

We strongly recommend transitioning to the following integrations for managing incidents and indicators:

Use the Azure Sentinel integration to get and manage incidents and get related entity information for incidents.

What does this pack do?