↳ GitHub sourceConnector

Mimecast Security Events (via Codeless Connector Framework)

Description

Ingests Mimecast Secure Email Gateway, Targeted Threat Protection, DLP and Audit events into Microsoft Sentinel using Mimecast **Event Push** and the Codeless Connector Framework (Push). Mimecast posts events directly to the Azure Monitor Logs Ingestion API — no Mimecast credentials are stored in Sentinel.
Declared author / publisher
Obrela

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

Read and write permissions are required.
Workspace
Workspace
Mimecast Event Push
Access to the Mimecast Administration Console (Integrations Hub) to configure an Event Push integration with OAuth 2.0 client credentials.
Microsoft Entra ID
Permission to create an application registration (performed automatically by the Deploy button below).

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

1. Deploy the ingestion resources
This creates the Data Collection Endpoint, Data Collection Rule, custom table, and a Microsoft Entra application (with client secret) scoped to ingest into this connector's table only.
Deploy
2. Configure Mimecast Event Push
In the Mimecast Administration Console, open **Integrations Hub -> Event Push** and create a destination with format **JSON** and OAuth 2.0 client credentials. Enter the values below. - **Token endpoint**: the Microsoft Entra (v2.0) token endpoint for the Tenant ID below - the path is `/{Tenant ID}/oauth2/v2.0/token` on the Microsoft identity platform login endpoint ([documentation](https://learn.microsoft.com/entra/identity-platform/v2-oauth2-client-creds-grant-flow)) - **Scope**: https://monitor.azure.com/.default - **Destination URL**: {Data Collection Endpoint}/dataCollectionRules/{DCR Immutable ID}/streams/Custom-MimecastEvents_CL?api-version=2023-01-01
Tenant ID (Directory ID)
Client ID (Application ID)
Client secret
Data Collection Endpoint
DCR Immutable ID

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
MimecastEventsCCFDefinition
Additional source files 2Solutions/MimecastEvents-CCF/Data Connectors/MimecastEvents_ccf/MimecastEvents_ConnectorDefinition.jsonsource ↗Solutions/MimecastEvents-CCF/Data/Solution_MimecastEvents-CCF.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.