↳ GitHub sourceConnector
Infoblox SOC Insights (via Codeless Connector Framework)
Description
The [Infoblox SOC Insights](https://www.infoblox.com/products/bloxone-threat-defense/) data connector enables seamless integration of Infoblox BloxOne SOC Insight data with Microsoft Sentinel, allowing security teams to leverage advanced search, correlation, alerting, and threat intelligence enrichment capabilities. This connector provides comprehensive visibility into active security insights and threat detections, DNS security events with threat classifications, threat family and class categorizations, persistent and spreading threats across your network, and event blocking statistics. By aggregating Infoblox's advanced threat intelligence with Sentinel's powerful analytics, organizations can gain deeper insights into their security posture and respond more effectively to emerging threats. For detailed information about the underlying data sources and API capabilities, refer to the [Infoblox SOC Insights documentation](https://docs.infoblox.com/space/BloxOneThreatDefense/501514252/SOC+Insights).
- Declared status
- 1
- Declared author / publisher
- Microsoft
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Data types
Declared permissions
Read and Write permissions are required.
Workspace
Workspace
Infoblox API access
**Infoblox API Key** is required to access the SOC Insights API
Connector instructions
Content published in the repository. Refer to the original file for all parameters.
1. Connector Management
Manage your Infoblox SOC Insights connector instances
Add Connector
Add Infoblox SOC Insights Connector
Infoblox API Base URL
**API URL by Region:**
- **US Region**: `https://csp.infoblox.com`
- **EU Region**: `https://csp.eu.infoblox.com`
- **Custom/On-Premises**: Contact your Infoblox administrator
API Key
Connector Friendly Name
The friendly name helps you identify this connector instance in the grid and in the collected data.
**Data Collection Schedule**: The connector will poll for new insights every 5 minutes.
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
9800e51↗- Source identifier
InfobloxSOCInsightsConnector
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC