↳ GitHub sourceConnector

ESET Connect Data Connector (via Codeless Connector Framework)

Description

The ESET Connect data connector enables comprehensive security monitoring by ingesting threat detections and incident data from multiple ESET products through the ESET Connect REST API. All detections from ESET PROTECT, ESET Inspect, and ESET Cloud Office Security are unified into the Detections table, with ESET PROTECT and Inspect providing basic endpoint detections via the /v1/detections API, while ESET Cloud Office Security delivers enhanced email security detections through the /v2/detections API. Additionally, incident management data from ESET Inspect is collected into the Incidents table via the /v2/incidents endpoint, providing enhanced incident correlation and management capabilities. The connector uses ESET Connect API credentials with username and password authentication, requiring an API user account with appropriate permissions for your selected products. Before using this connector, ensure you have an ESET Connect API user account, access to your selected ESET products (EP/EI/ECOS), appropriate API permissions for data access, and note that ESET Cloud Office Security is not supported in the Japan region.
Declared status
1
Declared author / publisher
ESET

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

Read and Write permissions are required.
Workspace
Workspace
ESET Connect API access
Access to ESET Connect API with appropriate permissions for selected products is required.

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

1. Connector Management
Manage your ESET Connect connector instances
Add Connector
Add ESET Connect Connector
Deployment Mode
Cloud
On-Premise
ESET Product
ESET PROTECT (EP)
ESET Inspect (EI)
ESET Cloud Office Security (ECOS)
**Product Details:** - **ESET PROTECT**: Endpoint detections via /v1/detections - **ESET Inspect**: Detections via /v1/detections + Incidents via /v2/incidents - **ESET Cloud Office Security**: Email security detections via /v2/detections (not available in Japan region)
Start From Detection ID (Optional)
ESET Connect API Base URL
**Important**: Enter the regional ESET Connect API base URL (not the portal URL). Common examples: - United States: `https://us.incident-management.eset.systems` - Europe: `https://eu.incident-management.eset.systems` - Japan: `https://jpn.incident-management.eset.systems` - On-Premise ESET Inspect: Enter your server URL (e.g., `https://your-server:8443`)
ESET Token Endpoint Base URL
**Token endpoint** (without /oauth/token): - EU: `https://eu.business-account.iam.eset.systems` - US: `https://us.business-account.iam.eset.systems` - JP: `https://jpn.business-account.iam.eset.systems`
ESET API Username
ESET API Password
Client ID
Client Secret
**Client ID/Secret**: ESET ignores these. Enter any non-empty values.
**ECOS Requirement**: If using ESET Cloud Office Security, you must log into the ECOS instance with these API credentials at least once before data collection will work.
Connector Friendly Name
The friendly name helps you identify this connector instance in the grid and in the collected data.
**Data Collection Schedule**: The connector will poll for new data every 15 minutes per selected product.

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
ESETConnectConnector
Additional source files 2Solutions/ESET Protect Platform/Data Connectors/ESETProtectPlatform_CCF/ESETProtectPlatform_ConnectorDefinition.jsonsource ↗Solutions/ESET Protect Platform/Data/Solution_ESETProtectPlatform.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.