↳ Source GitHubConnecteur

42Crunch API Protection (Push Connector via Codeless Connector Framework)

Description

Connects the 42Crunch API protection to Microsoft Sentinel via the Azure Monitor DCE/DCR REST API interface. The integration uses Docker containers (API Firewall and Log Forwarder) to forward API traffic logs to Microsoft Sentinel for threat detection and analysis.
Statut déclaré
1
Auteur / éditeur déclaré
Microsoft Corporation

Sources déclarées

Métadonnées du fichier source. Aucune dépendance déduite du KQL.

Types de données

Permissions déclarées

Read and Write permissions are required.
Workspace
Workspace
Microsoft.Insights/dataCollectionEndpoints
Data Collection Endpoint is required for the modern push connector to receive data from the external security system.
Microsoft.Insights/dataCollectionRules
Data Collection Rule is required to define the schema and transformations for incoming data.
Microsoft.Authorization/roleAssignments
Role assignment is required to grant the Entra application permissions to send data to the Data Collection Rule.
42Crunch API Firewall requirement
The 42Crunch API Firewall and Log Forwarder Docker containers must be deployed and running. Obtain your API Firewall token (42C_FIREWALL_TOKEN) and platform URL (42C_PLATFORM_URL) from the 42Crunch platform at https://platform.42crunch.com. Full deployment instructions are available at https://github.com/42Crunch/azure-sentinel-integration.

Instructions du connecteur

Contenu publié dans le dépôt. Consultez le fichier original pour l’ensemble des paramètres.

1. Create ARM Resources and Provide the Required Permissions
This connector receives data from external security systems that push logs to Microsoft Sentinel. The external system must be configured to send raw event data to the Microsoft Sentinel Ingestion API. Clicking on **Deploy** will trigger the creation of Log Analytics tables and a Data Collection Rule (DCR). It will then create an Entra application, link the DCR to it, and set the entered secret in the application. This setup enables data to be sent securely to the DCR using an Entra token. [Learn more about the connector setup process](https://review.learn.microsoft.com/azure/sentinel/create-push-codeless-connector)
Deploy 42Crunch API Protection connector resources
Tenant ID (Directory ID)
Entra App Registration Application ID
Entra App Registration Secret
Data Collection Endpoint Url
Data Collection Rule Immutable ID
Stream Name (FortyTwoCrunchAPIProtectionV2)
Keep these values secure. You will need them to configure your external security system.
2. Configure your external system to push logs
Use the following parameters to configure your external security system to send logs to the workspace. ### Configuration Steps 1. Access your external security system's configuration interface. 2. Navigate to the data forwarding, integration, or SIEM settings. 3. Select **Azure Monitor** or **Microsoft Sentinel** as the destination. 4. Select **Data Collection Endpoint** as the authentication method. 5. Configure the required fields using the values from the previous step: - **Tenant ID**: Copy from above - **Application (Client) ID**: Copy from above - **Client Secret**: Copy from above - **Data Collection Endpoint**: Copy from above - **Data Collection Rule Immutable ID**: Copy from above - **Stream Name**: Copy the appropriate stream name from above 6. Save the configuration and enable/start the forwarder. ### Validation > **Note**: Data will appear in the **FortyTwoCrunchAPIProtectionV2** table in your Log Analytics workspace within a few minutes. To verify data is being received, run the following query in your Log Analytics workspace: ```kusto FortyTwoCrunchAPIProtectionV2 | where TimeGenerated > ago(1h) | take 10 ``` ### Troubleshooting If data is not appearing: - Verify the configuration values are correct - Check that the forwarder/integration is enabled and running - Review logs in your external security system for any errors - Ensure network connectivity from your system to Azure - Verify the Entra application has the correct permissions
Uninstall connector
Follow these steps to disconnect and delete the connector instance.

Contenus associés

Liens établis à partir des identifiants déclarés et des manifests des solutions.

Traçabilité de la source

GitHub

Les valeurs affichées proviennent des fichiers du dépôt Azure/Azure-Sentinel. Elles décrivent le modèle publié, pas la configuration de votre workspace.

Identifiant source
FortyTwoCrunchAPIProtection
Autres fichiers source 2Solutions/42Crunch API Protection/Data Connectors/42Crunch_CCF/42CrunchAPIProtection_ConnectorDefinition.jsonsource ↗Solutions/42Crunch API Protection/Data/Solution_42CrunchAPIProtection.jsonsolution-membership ↗
GSTEP / SUIVI DU CATALOGUE

Ajouté au catalogue : 16 sept. 2026 · 05:49 UTC
Dernier changement observé : 16 sept. 2026 · 05:49 UTC

Dates de synchronisation GSTEP, distinctes des dates de publication du contenu source.