↳ GitHub sourceConnector
ESET Connect Data Connector (via Codeless Connector Framework)
Description
The ESET Connect data connector enables comprehensive security monitoring by ingesting threat detections and incident data from multiple ESET products through the ESET Connect REST API. All detections from ESET PROTECT, ESET Inspect, and ESET Cloud Office Security are unified into the Detections table, with ESET PROTECT and Inspect providing basic endpoint detections via the /v1/detections API, while ESET Cloud Office Security delivers enhanced email security detections through the /v2/detections API. Additionally, incident management data from ESET Inspect is collected into the Incidents table via the /v2/incidents endpoint, providing enhanced incident correlation and management capabilities. The connector uses ESET Connect API credentials with username and password authentication, requiring an API user account with appropriate permissions for your selected products. Before using this connector, ensure you have an ESET Connect API user account, access to your selected ESET products (EP/EI/ECOS), appropriate API permissions for data access, and note that ESET Cloud Office Security is not supported in the Japan region.
- Declared status
- 1
- Declared author / publisher
- ESET
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Data types
Declared permissions
Read and Write permissions are required.
Workspace
Workspace
ESET Connect API access
Access to ESET Connect API with appropriate permissions for selected products is required.
Connector instructions
Content published in the repository. Refer to the original file for all parameters.
1. Connector Management
Manage your ESET Connect connector instances
Add Connector
Add ESET Connect Connector
Deployment Mode
Cloud
On-Premise
ESET Product
ESET PROTECT (EP)
ESET Inspect (EI)
ESET Cloud Office Security (ECOS)
**Product Details:**
- **ESET PROTECT**: Endpoint detections via /v1/detections
- **ESET Inspect**: Detections via /v1/detections + Incidents via /v2/incidents
- **ESET Cloud Office Security**: Email security detections via /v2/detections (not available in Japan region)
Start From Detection ID (Optional)
ESET Connect API Base URL
**Important**: Enter the regional ESET Connect API base URL (not the portal URL). Common examples:
- United States: `https://us.incident-management.eset.systems`
- Europe: `https://eu.incident-management.eset.systems`
- Japan: `https://jpn.incident-management.eset.systems`
- On-Premise ESET Inspect: Enter your server URL (e.g., `https://your-server:8443`)
ESET Token Endpoint Base URL
**Token endpoint** (without /oauth/token):
- EU: `https://eu.business-account.iam.eset.systems`
- US: `https://us.business-account.iam.eset.systems`
- JP: `https://jpn.business-account.iam.eset.systems`
ESET API Username
ESET API Password
Client ID
Client Secret
**Client ID/Secret**: ESET ignores these. Enter any non-empty values.
**ECOS Requirement**: If using ESET Cloud Office Security, you must log into the ECOS instance with these API credentials at least once before data collection will work.
Connector Friendly Name
The friendly name helps you identify this connector instance in the grid and in the collected data.
**Data Collection Schedule**: The connector will poll for new data every 15 minutes per selected product.
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
629d1d3↗- Source identifier
ESETConnectConnector
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC