↳ Source GitHubConnecteur

Mimecast Security Events (via Codeless Connector Framework)

Description

Ingests Mimecast Secure Email Gateway, Targeted Threat Protection, DLP and Audit events into Microsoft Sentinel using Mimecast **Event Push** and the Codeless Connector Framework (Push). Mimecast posts events directly to the Azure Monitor Logs Ingestion API — no Mimecast credentials are stored in Sentinel.
Auteur / éditeur déclaré
Obrela

Sources déclarées

Métadonnées du fichier source. Aucune dépendance déduite du KQL.

Types de données

Permissions déclarées

Read and write permissions are required.
Workspace
Workspace
Mimecast Event Push
Access to the Mimecast Administration Console (Integrations Hub) to configure an Event Push integration with OAuth 2.0 client credentials.
Microsoft Entra ID
Permission to create an application registration (performed automatically by the Deploy button below).

Instructions du connecteur

Contenu publié dans le dépôt. Consultez le fichier original pour l’ensemble des paramètres.

1. Deploy the ingestion resources
This creates the Data Collection Endpoint, Data Collection Rule, custom table, and a Microsoft Entra application (with client secret) scoped to ingest into this connector's table only.
Deploy
2. Configure Mimecast Event Push
In the Mimecast Administration Console, open **Integrations Hub -> Event Push** and create a destination with format **JSON** and OAuth 2.0 client credentials. Enter the values below. - **Token endpoint**: the Microsoft Entra (v2.0) token endpoint for the Tenant ID below - the path is `/{Tenant ID}/oauth2/v2.0/token` on the Microsoft identity platform login endpoint ([documentation](https://learn.microsoft.com/entra/identity-platform/v2-oauth2-client-creds-grant-flow)) - **Scope**: https://monitor.azure.com/.default - **Destination URL**: {Data Collection Endpoint}/dataCollectionRules/{DCR Immutable ID}/streams/Custom-MimecastEvents_CL?api-version=2023-01-01
Tenant ID (Directory ID)
Client ID (Application ID)
Client secret
Data Collection Endpoint
DCR Immutable ID

Contenus associés

Liens établis à partir des identifiants déclarés et des manifests des solutions.

Traçabilité de la source

GitHub

Les valeurs affichées proviennent des fichiers du dépôt Azure/Azure-Sentinel. Elles décrivent le modèle publié, pas la configuration de votre workspace.

Identifiant source
MimecastEventsCCFDefinition
Autres fichiers source 2Solutions/MimecastEvents-CCF/Data Connectors/MimecastEvents_ccf/MimecastEvents_ConnectorDefinition.jsonsource ↗Solutions/MimecastEvents-CCF/Data/Solution_MimecastEvents-CCF.jsonsolution-membership ↗
GSTEP / SUIVI DU CATALOGUE

Ajouté au catalogue : 16 sept. 2026 · 05:49 UTC
Dernier changement observé : 16 sept. 2026 · 05:49 UTC

Dates de synchronisation GSTEP, distinctes des dates de publication du contenu source.