↳ GitHub sourceConnector

Infoblox SOC Insights (via Codeless Connector Framework)

Description

The [Infoblox SOC Insights](https://www.infoblox.com/products/bloxone-threat-defense/) data connector enables seamless integration of Infoblox BloxOne SOC Insight data with Microsoft Sentinel, allowing security teams to leverage advanced search, correlation, alerting, and threat intelligence enrichment capabilities. This connector provides comprehensive visibility into active security insights and threat detections, DNS security events with threat classifications, threat family and class categorizations, persistent and spreading threats across your network, and event blocking statistics. By aggregating Infoblox's advanced threat intelligence with Sentinel's powerful analytics, organizations can gain deeper insights into their security posture and respond more effectively to emerging threats. For detailed information about the underlying data sources and API capabilities, refer to the [Infoblox SOC Insights documentation](https://docs.infoblox.com/space/BloxOneThreatDefense/501514252/SOC+Insights).
Declared status
1
Declared author / publisher
Microsoft

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

Read and Write permissions are required.
Workspace
Workspace
Infoblox API access
**Infoblox API Key** is required to access the SOC Insights API

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

1. Connector Management
Manage your Infoblox SOC Insights connector instances
Add Connector
Add Infoblox SOC Insights Connector
Infoblox API Base URL
**API URL by Region:** - **US Region**: `https://csp.infoblox.com` - **EU Region**: `https://csp.eu.infoblox.com` - **Custom/On-Premises**: Contact your Infoblox administrator
API Key
Connector Friendly Name
The friendly name helps you identify this connector instance in the grid and in the collected data.
**Data Collection Schedule**: The connector will poll for new insights every 5 minutes.

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
InfobloxSOCInsightsConnector
Additional source files 2Solutions/Infoblox SOC Insights/Data Connectors/InfobloxSOCInsights_CCF/InfobloxSOCInsights_ConnectorDefinition.jsonsource ↗Solutions/Infoblox SOC Insights/Data/Solution_Infoblox_SOC_Insights.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.