↳ GitHub sourceConnector

Box Events (via Codeless Connector Framework)

Description

The Box data connector provides the capability to ingest [Box enterprise's events](https://developer.box.com/guides/events/#admin-events) into Microsoft Sentinel using the Box REST API. Refer to [Box documentation](https://developer.box.com/guides/events/enterprise-events/for-enterprise/) for more information.
Declared author / publisher
Microsoft

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

Read and Write permissions are required.
Workspace
Workspace
Box API credentials
Box API requires a Box App client ID and client secret to authenticate. [See the documentation to learn more about Client Credentials grant](https://developer.box.com/guides/authentication/client-credentials/client-credentials-setup/)
Box Enterprise ID
Box Enterprise ID is required to make the connection. See documentation to [find Enterprise ID](https://developer.box.com/platform/appendix/locating-values/)

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

>**NOTE:** This connector uses Codeless Connecor Platform (CCP) to connect to the Box REST API to pull logs into Microsoft Sentinel.
>**NOTE:** This connector depends on a parser based on Kusto Function to work as expected [**BoxEvents**](https://aka.ms/sentinel-BoxDataConnector-parser) which is deployed with the Microsoft Sentinel Solution.
**STEP 1 - Create Box Custom Application** See documentation to [setup client credentials authentication](https://developer.box.com/guides/authentication/client-credentials/client-credentials-setup/)
**STEP 2 - Grab Client ID and Client Secret values** You might need to setup 2FA to fetch the secret.
**STEP 3 - Grab Box Enterprise ID from Box Admin Console** See documentation to [find Enterprise ID](https://developer.box.com/platform/appendix/locating-values/)
Provide the required values below:
Box Enterprise ID
Connect to Box to start collecting event logs to Microsoft Sentinel

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
BoxEventsCCPDefinition
Additional source files 2Solutions/Box/Data Connectors/BoxEvents_ccp/BoxEvents_DataConnectorDefinition.jsonsource ↗Solutions/Box/Data/Solution_Box.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.