Description
The [Red Canary](https://www.redcanary.com/) solution for Microsoft Sentinel enables Red Canary to publish threat detections into a Microsoft Sentinel custom table for alerting and incident creation.
**Underlying Microsoft Technologies used:**
This solution takes a dependency on the following technologies, and some of these dependencies might result in additional ingestion or operational costs:
a. [Microsoft Sentinel Codeless Connector Framework](https://learn.microsoft.com/azure/sentinel/create-codeless-connector)
b. [Azure Monitor Logs Ingestion API](https://learn.microsoft.com/azure/azure-monitor/logs/logs-ingestion-api-overview)
c. [Data collection rules](https://learn.microsoft.com/azure/azure-monitor/essentials/data-collection-rule-overview)
- Version
- 3.0.0
- Declared author / publisher
- Red Canary - microsoft@redcanary.com
- Support tier
- Partner
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
9800e51↗- Source identifier
microsoft-sentinel-solution-redcanary
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC