Description
WithSecure Elements security events ingested via Microsoft Sentinel's Codeless Connector Framework (CCF) — a fully SaaS deployment with no Azure Function, Storage Account or Key Vault to manage.
The connector polls the [WithSecure Elements security-events API](https://connect.withsecure.com/api-reference/elements#post-/security-events/v1/security-events) and stores normalized events in the `WsSecurityEvents_CL` Log Analytics table.
- Declared author / publisher
- WithSecure
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Data types
Declared permissions
read and write permissions on the workspace are required.
Workspace
Workspace
WithSecure Elements API client credentials
Client credentials are required. See the [user guide](https://connect.withsecure.com/getting-started/elements#getting-client-credentials) for details.
Connector instructions
Content published in the repository. Refer to the original file for all parameters.
Create WithSecure Elements API credentials
Follow the [user guide](https://connect.withsecure.com/getting-started/elements#getting-client-credentials) to create Elements API credentials. Save the client id and client secret in a safe place.
Connect WithSecure Elements to Microsoft Sentinel
Provide the Elements API URL together with the client id and client secret you created in the previous step, then click **Connect** to start ingesting events.
Elements API URL
Engine (optional)
Engine Group (optional)
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
629d1d3↗- Source identifier
WithSecureElementsCCF
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC