↳ GitHub sourceConnector
Darktrace Connector for Microsoft Sentinel REST API (Legacy)
Description
The Darktrace REST API connector pushes real-time events from Darktrace to Microsoft Sentinel and is designed to be used with the Darktrace Solution for Microsoft Sentinel. The connector writes logs to a custom log table titled "darktrace_model_alerts_CL"; Model Breaches, AI Analyst Incidents, System Alerts and Email Alerts can be ingested - additional filters can be set up on the Darktrace System Configuration page. Data is pushed to Microsoft Sentinel from Darktrace masters.
- Declared status
- 1
- Declared author / publisher
- Darktrace
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Data types
Declared permissions
read and write permissions are required.
Workspace
Workspace
read permissions to shared keys for the workspace are required. [See the documentation to learn more about workspace keys](https://docs.microsoft.com/azure/azure-monitor/platform/agent-windows#obtain-workspace-id-and-key).
Keys
Workspace
Darktrace Prerequisites
To use this Data Connector a Darktrace master running v5.2+ is required. Data is sent to the [Azure Monitor HTTP Data Collector API](https://docs.microsoft.com/azure/azure-monitor/logs/data-collector-api) over HTTPs from Darktrace masters, therefore outbound connectivity from the Darktrace master to Microsoft Sentinel REST API is required.
Filter Darktrace Data
During configuration it is possible to set up additional filtering on the Darktrace System Configuration page to constrain the amount or types of data sent.
Try the Darktrace Sentinel Solution
You can get the most out of this connector by installing the Darktrace Solution for Microsoft Sentinel. This will provide workbooks to visualise alert data and analytics rules to automatically create alerts and incidents from Darktrace Model Breaches and AI Analyst incidents.
Connector instructions
Content published in the repository. Refer to the original file for all parameters.
1. Detailed setup instructions can be found on the Darktrace Customer Portal: https://customerportal.darktrace.com/product-guides/main/microsoft-sentinel-introduction
2. Take note of the Workspace ID and the Primary key. You will need to enter these details on your Darktrace System Configuration page.
Workspace ID
Primary Key
Darktrace Configuration
1. Perform the following steps on the Darktrace System Configuration page:
2. Navigate to the System Configuration Page (Main Menu > Admin > System Config)
3. Go into Modules configuration and click on the "Microsoft Sentinel" configuration card
4. Select "HTTPS (JSON)" and hit "New"
5. Fill in the required details and select appropriate filters
6. Click "Verify Alert Settings" to attempt authentication and send out a test alert
7. Run a "Look for Test Alerts" sample query to validate that the test alert has been received
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
9800e51↗- Source identifier
DarktraceRESTConnector
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC