↳ GitHub sourceConnector

Snowflake (via Codeless Connector Framework)

Description

The Snowflake data connector provides the capability to ingest Snowflake [Login History Logs](https://docs.snowflake.com/en/sql-reference/account-usage/login_history), [Query History Logs](https://docs.snowflake.com/en/sql-reference/account-usage/query_history), [User-Grant Logs](https://docs.snowflake.com/en/sql-reference/account-usage/grants_to_users), [Role-Grant Logs](https://docs.snowflake.com/en/sql-reference/account-usage/grants_to_roles), [Load History Logs](https://docs.snowflake.com/en/sql-reference/account-usage/load_history), [Materialized View Refresh History Logs](https://docs.snowflake.com/en/sql-reference/account-usage/materialized_view_refresh_history), [Roles Logs](https://docs.snowflake.com/en/sql-reference/account-usage/roles), [Tables Logs](https://docs.snowflake.com/en/sql-reference/account-usage/tables), [Table Storage Metrics Logs](https://docs.snowflake.com/en/sql-reference/account-usage/table_storage_metrics), [Users Logs](https://docs.snowflake.com/en/sql-reference/account-usage/users) into Microsoft Sentinel using the Snowflake SQL API. Refer to [Snowflake SQL API documentation](https://docs.snowflake.com/en/developer-guide/sql-api/reference) for more information.
Declared status
1
Declared author / publisher
Microsoft

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

Read and Write permissions are required.
Workspace
Workspace

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

Connect Snowflake to Microsoft Sentinel
**Notice:** Solution version 3.1.0 and later uses the SnowflakeV2 tables (e.g., SnowflakeQueryV2_CL, SnowflakeLoginV2_CL). The parsers have been updated accordingly.
Add Account
Add Account
Connection Alias
Enter a unique alias to identify this Snowflake connection. **Important**: Use different aliases for each account identifier. To update an existing connection, use the same alias or delete and create with the same alias. To replace a connection, delete the old one and create a new one with a new alias.
Data Types
Snowflake - Load data
Snowflake - Login data
Snowflake - Materialized View data
Snowflake - Query data
Snowflake - Role Grant data
Snowflake - Roles data
Snowflake - Tables data
Snowflake - Table Storage Metrics data
Snowflake - User Grant data
Snowflake - Users data
Snowflake Account Identifier
Snowflake PAT

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
SnowflakeConnector
Additional source files 2Solutions/Snowflake/Data Connectors/SnowflakeLogs_ccp/SnowflakeLogs_ConnectorDefinition.jsonsource ↗Solutions/Snowflake/Data/Solution_Snowflake.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.