↳ GitHub sourceConnector

WithSecure Elements (CCF)

Description

WithSecure Elements security events ingested via Microsoft Sentinel's Codeless Connector Framework (CCF) — a fully SaaS deployment with no Azure Function, Storage Account or Key Vault to manage. The connector polls the [WithSecure Elements security-events API](https://connect.withsecure.com/api-reference/elements#post-/security-events/v1/security-events) and stores normalized events in the `WsSecurityEvents_CL` Log Analytics table.
Declared author / publisher
WithSecure

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

read and write permissions on the workspace are required.
Workspace
Workspace
WithSecure Elements API client credentials
Client credentials are required. See the [user guide](https://connect.withsecure.com/getting-started/elements#getting-client-credentials) for details.

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

Create WithSecure Elements API credentials
Follow the [user guide](https://connect.withsecure.com/getting-started/elements#getting-client-credentials) to create Elements API credentials. Save the client id and client secret in a safe place.
Connect WithSecure Elements to Microsoft Sentinel
Provide the Elements API URL together with the client id and client secret you created in the previous step, then click **Connect** to start ingesting events.
Elements API URL
Engine (optional)
Engine Group (optional)

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
WithSecureElementsCCF
Additional source files 2Solutions/WithSecureElementsCCF/Data Connectors/WithSecureElementsCCP/WithSecureElements_ConnectorDefinition.jsonsource ↗Solutions/WithSecureElementsCCF/Data/Solution_WithSecureElementsCCF.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.