↳ Source GitHubConnecteur
Mimecast Security Events (via Codeless Connector Framework)
Description
Ingests Mimecast Secure Email Gateway, Targeted Threat Protection, DLP and Audit events into Microsoft Sentinel using Mimecast **Event Push** and the Codeless Connector Framework (Push). Mimecast posts events directly to the Azure Monitor Logs Ingestion API — no Mimecast credentials are stored in Sentinel.
- Auteur / éditeur déclaré
- Obrela
Sources déclarées
Métadonnées du fichier source. Aucune dépendance déduite du KQL.
Types de données
Permissions déclarées
Read and write permissions are required.
Workspace
Workspace
Mimecast Event Push
Access to the Mimecast Administration Console (Integrations Hub) to configure an Event Push integration with OAuth 2.0 client credentials.
Microsoft Entra ID
Permission to create an application registration (performed automatically by the Deploy button below).
Instructions du connecteur
Contenu publié dans le dépôt. Consultez le fichier original pour l’ensemble des paramètres.
1. Deploy the ingestion resources
This creates the Data Collection Endpoint, Data Collection Rule, custom table, and a Microsoft Entra application (with client secret) scoped to ingest into this connector's table only.
Deploy
2. Configure Mimecast Event Push
In the Mimecast Administration Console, open **Integrations Hub -> Event Push** and create a destination with format **JSON** and OAuth 2.0 client credentials. Enter the values below.
- **Token endpoint**: the Microsoft Entra (v2.0) token endpoint for the Tenant ID below - the path is `/{Tenant ID}/oauth2/v2.0/token` on the Microsoft identity platform login endpoint ([documentation](https://learn.microsoft.com/entra/identity-platform/v2-oauth2-client-creds-grant-flow))
- **Scope**: https://monitor.azure.com/.default
- **Destination URL**: {Data Collection Endpoint}/dataCollectionRules/{DCR Immutable ID}/streams/Custom-MimecastEvents_CL?api-version=2023-01-01
Tenant ID (Directory ID)
Client ID (Application ID)
Client secret
Data Collection Endpoint
DCR Immutable ID
Contenus associés
Liens établis à partir des identifiants déclarés et des manifests des solutions.
Traçabilité de la source
GitHubLes valeurs affichées proviennent des fichiers du dépôt Azure/Azure-Sentinel. Elles décrivent le modèle publié, pas la configuration de votre workspace.
- Commit
629d1d3↗- Identifiant source
MimecastEventsCCFDefinition
GSTEP / SUIVI DU CATALOGUE
Ajouté au catalogue : 16 sept. 2026 · 05:49 UTC
Dernier changement observé : 16 sept. 2026 · 05:49 UTC