↳ GitHub sourceConnector

AzureStorageBlobConnector // modify to your title

Description

AzureStorageBlobConnector // Modify to your description
Declared status
1
Declared author / publisher
Microsoft // Modify to your user / company name

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

Read and Write permissions are required.
Workspace
Workspace
Read permissions to shared keys for the workspace are required. [See the documentation to learn more about workspace keys](https://docs.microsoft.com/azure/azure-monitor/platform/agent-windows#obtain-workspace-id-and-key)
Keys
Workspace
Subscription permissions
You need permissions to create the data flow resources: 
- storage queues (notification queue and dead-letter queue) 
- event grid topic and subscription (to send 'blob created event' notifications to the notification queue) 
- role assignments (to grant access for sentinel app to the blob container and the storage queues.)
Collecting data from __ to your blob container
Follow the steps in the [documentation](https://some-guide.net) for collecting data from __ to your blob container.

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

Connect Azure Storage Blob Logs to Microsoft Sentinel
To enable the Azure Storage Blob Logs for Microsoft Sentinel, provide the required information below and click on Connect. >
The blob container URL you want to collect data from
The blobs folder name in the container. Optional
The blob container's storage account location
The blob container's storage account resource group name
The blob container's storage account subscription id
The event grid topic name of the blob container's storage account if exist. else keep empty.
The data flow using event grid to send 'blob-created event' notifications. There could be only one event grid topic for each storage account. Go to your blob container's storage account and look in the 'Events' section. If you already have a topic, please provide it's name. Else, keep the text box empty.
toggle

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
AzureStorageBlobConnector
Additional source files 1DataConnectors/Templates/Connector_StorageBlob_CCF_template.jsonsource ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.