↳ Source GitHubConnecteur

Darktrace Connector for Microsoft Sentinel REST API (Legacy)

Description

The Darktrace REST API connector pushes real-time events from Darktrace to Microsoft Sentinel and is designed to be used with the Darktrace Solution for Microsoft Sentinel. The connector writes logs to a custom log table titled "darktrace_model_alerts_CL"; Model Breaches, AI Analyst Incidents, System Alerts and Email Alerts can be ingested - additional filters can be set up on the Darktrace System Configuration page. Data is pushed to Microsoft Sentinel from Darktrace masters.
Statut déclaré
1
Auteur / éditeur déclaré
Darktrace

Sources déclarées

Métadonnées du fichier source. Aucune dépendance déduite du KQL.

Types de données

Permissions déclarées

read and write permissions are required.
Workspace
Workspace
read permissions to shared keys for the workspace are required. [See the documentation to learn more about workspace keys](https://docs.microsoft.com/azure/azure-monitor/platform/agent-windows#obtain-workspace-id-and-key).
Keys
Workspace
Darktrace Prerequisites
To use this Data Connector a Darktrace master running v5.2+ is required.
 Data is sent to the [Azure Monitor HTTP Data Collector API](https://docs.microsoft.com/azure/azure-monitor/logs/data-collector-api) over HTTPs from Darktrace masters, therefore outbound connectivity from the Darktrace master to Microsoft Sentinel REST API is required.
Filter Darktrace Data
During configuration it is possible to set up additional filtering on the Darktrace System Configuration page to constrain the amount or types of data sent.
Try the Darktrace Sentinel Solution
You can get the most out of this connector by installing the Darktrace Solution for Microsoft Sentinel. This will provide workbooks to visualise alert data and analytics rules to automatically create alerts and incidents from Darktrace Model Breaches and AI Analyst incidents.

Instructions du connecteur

Contenu publié dans le dépôt. Consultez le fichier original pour l’ensemble des paramètres.

1. Detailed setup instructions can be found on the Darktrace Customer Portal: https://customerportal.darktrace.com/product-guides/main/microsoft-sentinel-introduction 2. Take note of the Workspace ID and the Primary key. You will need to enter these details on your Darktrace System Configuration page.
Workspace ID
Primary Key
Darktrace Configuration
1. Perform the following steps on the Darktrace System Configuration page: 2. Navigate to the System Configuration Page (Main Menu > Admin > System Config) 3. Go into Modules configuration and click on the "Microsoft Sentinel" configuration card 4. Select "HTTPS (JSON)" and hit "New" 5. Fill in the required details and select appropriate filters 6. Click "Verify Alert Settings" to attempt authentication and send out a test alert 7. Run a "Look for Test Alerts" sample query to validate that the test alert has been received

Contenus associés

Liens établis à partir des identifiants déclarés et des manifests des solutions.

Traçabilité de la source

GitHub

Les valeurs affichées proviennent des fichiers du dépôt Azure/Azure-Sentinel. Elles décrivent le modèle publié, pas la configuration de votre workspace.

Identifiant source
DarktraceRESTConnector
Autres fichiers source 2Solutions/Darktrace/Data Connectors/DarktraceConnectorRESTAPI.jsonsource ↗Solutions/Darktrace/Data/Solution_DarktraceEnterpriseImmuneSystem.jsonsolution-membership ↗
GSTEP / SUIVI DU CATALOGUE

Ajouté au catalogue : 16 sept. 2026 · 05:49 UTC
Dernier changement observé : 16 sept. 2026 · 05:49 UTC

Dates de synchronisation GSTEP, distinctes des dates de publication du contenu source.